MALICIOUS — mubesinomur.pdf
MALICIOUS — mubesinomur.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3737846ce35d9e49f510d2fab07a380b69ff964af1b0ab979b4d78c661f380fc - SHA-1:
0c6c480b5767b8a049c738de594753542e555ccc - MD5:
6e7eb75c174133668d92fb97e298c3bf - ssdeep:
1536:9IHt9Y983BtdcNz/zd3U98sd8kv3FMULoL2sU90:WfYyXdezLi9zdx3FMULoCs7 - TLSH:
T15F37D0F3A2D7DC8CABC77B93B9D6116C7045A2486123DB614488A76CC57C2DE7E21E02 - Submitted as: mubesinomur.pdf
- File type: pdf · Size: 73552 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!6E7EB75C1741
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4444655/normal_5fcef5af4580b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://jacksth.ru/wb?keyword=garmin%20forerunner%20410%20replacement%20strap, https://cdn.sqhk.co/loxinesupiva/iyigEjc/space_wars_movie_netflix.pdf, https://cdn.sqhk.co/wofazexej/ggigvbc/free_printable_shopping_list_for_keto_diet.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/wb?keyword=garmin%20forerunner%20410%20replacement%20strap
- https://cdn.sqhk.co/loxinesupiva/iyigEjc/space_wars_movie_netflix.pdf
- https://cdn.sqhk.co/wofazexej/ggigvbc/free_printable_shopping_list_for_keto_diet.pdf
- https://cdn.sqhk.co/vigesiji/gdHjiUJ/30406155192.pdf
- https://cdn.sqhk.co/xoxamomajil/MgiujjI/cheat_code_sims_4_xbox_one_money.pdf
- http://rakadan.sportsontheweb.net/nordictrack_commercial_1750_assembly_cost.pdf
- https://cdn-cms.f-static.net/uploads/4471085/normal_5fdbbd4d46e64.pdf
- https://065b66ee-25d8-4381-b309-094abc4d823c.filesusr.com/ugd/2703e6_0f2a94f2476e4210a447c2ae268b5f1e.pdf?index=true
- http://winoxolupuvil.getenjoyment.net/gsm_smart_alarm_system_android_app.pdf
- https://static.s123-cdn-static.com/uploads/4444655/normal_5fcef5af4580b.pdf
- https://cdn.sqhk.co/totimujid/3jeUjgv/32236908342.pdf
- https://76b44699-1094-4fd8-8d4a-70b7be8159c3.filesusr.com/ugd/c450b2_7b5b405449d549d99a9f18b70b396447.pdf?index=true
- https://5a2ada08-5b6c-402a-b0df-3636415b461e.filesusr.com/ugd/434ae6_0c67a0fb984d48e8b67f33e65df41fd2.pdf?index=true
- http://jalebuvubo.myartsonline.com/coleman_mach_rv_air_conditioner_installation.pdf
- https://cdn.sqhk.co/nulegudup/tPx3Wji/truck_simulator_offroad_mod_apk_android_1.pdf
- https://cdn.sqhk.co/fuwasokeg/idZgchj/57940108119.pdf
- https://c4e42e93-254c-4ba8-b495-737f84002742.filesusr.com/ugd/ddb60a_135358f895e9417ab72712ba0e3ac330.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- jacksth.ru
- cdn.sqhk.co
- rakadan.sportsontheweb.net
- cdn-cms.f-static.net
- 065b66ee-25d8-4381-b309-094abc4d823c.filesusr.com
- winoxolupuvil.getenjoyment.net
- static.s123-cdn-static.com
- 76b44699-1094-4fd8-8d4a-70b7be8159c3.filesusr.com
- 5a2ada08-5b6c-402a-b0df-3636415b461e.filesusr.com
- jalebuvubo.myartsonline.com
- c4e42e93-254c-4ba8-b495-737f84002742.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report