MALICIOUS — ecd213_cc97d6c618d04fe9a5727197c4cd514d.pdf
MALICIOUS — ecd213_cc97d6c618d04fe9a5727197c4cd514d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
36bab181d1447e804b737836730af07596c3c6b1bc3281a143e1eb78ce4e10c6 - SHA-1:
7035c8fb48a33a836b500713ff72ef263537ce07 - MD5:
53d6f75b0f4d97e9577196c38839f39f - ssdeep:
1536:sck59CNvBRIeFwNcYlwWA7iRdsr3lgy2Zopi6yrYxrTQ4:XvAeFWiP7Fiy2CL3pz - TLSH:
T19A38B0F310A7ED4C7A8F9B47BDB7165CA099E35D60718B60109CB26CC4BC2AE7E50A50 - Submitted as: ecd213_cc97d6c618d04fe9a5727197c4cd514d.pdf
- File type: pdf · Size: 77145 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!53D6F75B0F4D
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://ad843f61-c544-48d7-8cfb-3c048b9edb46.filesusr.com/ugd/0dd9ed_c77bcf334089423eb80db53122172be1.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://zajinet.ru/wix?keyword=17.4+similarity+in+right+triangles+worksheet+answers, https://0e627107-309b-4451-a84d-e7064c41fccd.filesusr.com/ugd/04c368_d0299fa2cc2d4a9a8424f3d446de6185.pdf?index=true, https://uploads.strikinglycdn.com/files/c54ce8db-3de9-435f-b7a0-47c54013df45/diwedoguremowix.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://zajinet.ru/wix?keyword=17.4+similarity+in+right+triangles+worksheet+answers
- https://0e627107-309b-4451-a84d-e7064c41fccd.filesusr.com/ugd/04c368_d0299fa2cc2d4a9a8424f3d446de6185.pdf?index=true
- https://uploads.strikinglycdn.com/files/c54ce8db-3de9-435f-b7a0-47c54013df45/diwedoguremowix.pdf
- https://ad843f61-c544-48d7-8cfb-3c048b9edb46.filesusr.com/ugd/0dd9ed_c77bcf334089423eb80db53122172be1.pdf?index=true
- https://83d12552-0bc1-4415-b221-1da25caacb9b.filesusr.com/ugd/1e11d0_97d1989148134dea9786250db3819a90.pdf?index=true
- https://uploads.strikinglycdn.com/files/77e0b988-c6c3-44e8-b849-3c477fc59a48/tabla_de_conversion_de_medidas_pulgadas_a_milimetros.pdf
- https://s3.amazonaws.com/jixerubowi/2015_chevy_trax_user_manual.pdf
- https://6c71f620-b6e5-46cc-9e58-526c5f0a7a41.filesusr.com/ugd/1c90dc_9b958ee8cea943918c5932b02dd5346c.pdf?index=true
- https://s3.amazonaws.com/sazomo/shareholder_loan_agreement_template_hong_kong.pdf
- https://s3.amazonaws.com/fefurorobumi/will_evening_primrose_oil_induce_labor.pdf
- https://s3.amazonaws.com/kiguteperilodu/27613895407.pdf
- https://gatokoliza.weebly.com/uploads/1/3/0/7/130739470/wigana-nujeduwikomeji-pulizej-divegimaj.pdf
- http://beverunogi.rf.gd/vupasagesokixemavaxe.pdf
- https://8772a198-af03-49ef-8724-5feb7546cb8a.filesusr.com/ugd/436f04_d89df15e44404f10847e5a7d7cd833ac.pdf?index=true
- https://s3.amazonaws.com/gidibesuxi/space_place_and_gender_identities_develop_pre-600_bce.pdf
- https://s3.amazonaws.com/betefowubevat/19332251346.pdf
- https://s3.amazonaws.com/nodetuxapabara/seagate_barracuda_1tb_st1000dm010_manual.pdf
- https://dowusezawidi.weebly.com/uploads/1/3/3/9/133997386/talerom-tafokise-lebozo.pdf
- https://kawuzuke.weebly.com/uploads/1/3/1/6/131606938/xinowarajawilu-duroripo-tewezunid-momejugobepo.pdf
- https://s3.amazonaws.com/kiremefegonar/sekopunedatugut.pdf
- https://s3.amazonaws.com/tevomenil/8642489990.pdf
- http://xabogubumux.rf.gd/tuxokib.pdf
- https://s3.amazonaws.com/verirejon/http_tinyurl._com.pdf
- http://bunewasebawaxig.iblogger.org/sony_bdp-bx59_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- zajinet.ru
- 0e627107-309b-4451-a84d-e7064c41fccd.filesusr.com
- uploads.strikinglycdn.com
- ad843f61-c544-48d7-8cfb-3c048b9edb46.filesusr.com
- 83d12552-0bc1-4415-b221-1da25caacb9b.filesusr.com
- s3.amazonaws.com
- 6c71f620-b6e5-46cc-9e58-526c5f0a7a41.filesusr.com
- gatokoliza.weebly.com
- 8772a198-af03-49ef-8724-5feb7546cb8a.filesusr.com
- dowusezawidi.weebly.com
- kawuzuke.weebly.com
- bunewasebawaxig.iblogger.org
- www.w3.org
- purl.org
- ns.adobe.com
- beverunogi.rf.gd
- xabogubumux.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report