MALICIOUS — dav_maths_book_class_8_solutions.pdf
MALICIOUS — dav_maths_book_class_8_solutions.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3b8af215f093d17e4fa68af424cf7fa1698b30a80497f9a47d6e238360fc131d - SHA-1:
0dd18f8edfff83905834b0cf49df206d70a1c0fb - MD5:
c7b975075b108c609d412c3e95aea47c - ssdeep:
1536:kAqwF87eKRNWW+HsgpxaZj6QEoy/kxUUuMzriB93yWVvmlxZuNNU30F7um1:PLzTjnU5dx1uMzrGvmlx4TUu1 - TLSH:
T10939D0F3B157DD8C3A8F2F17A9E7157C6486DB8C71329B8085887B2CC8AC66D2D24650 - Submitted as: dav_maths_book_class_8_solutions.pdf
- File type: pdf · Size: 89174 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!C7B975075B10
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4484364/normal_5ff37e8a00403.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://xajibur.ru/strik?utm_term=dav+maths+book+class+8+solutions+pdf, https://cdn.sqhk.co/dedomafub/jiha9Zq/rezinuregufuk.pdf, https://9a4b5e96-23fe-4021-9525-787506808755.filesusr.com/ugd/b3318b_035392f8d26c4a17b214ae41ce05f539.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://xajibur.ru/strik?utm_term=dav+maths+book+class+8+solutions+pdf
- https://cdn.sqhk.co/dedomafub/jiha9Zq/rezinuregufuk.pdf
- https://9a4b5e96-23fe-4021-9525-787506808755.filesusr.com/ugd/b3318b_035392f8d26c4a17b214ae41ce05f539.pdf?index=true
- https://cdn.sqhk.co/mavixuwaloz/5tAk9R1/24849970150.pdf
- https://01dc7cc6-b8ed-446e-8cc8-1ad78882ed38.filesusr.com/ugd/e23fbb_147a44e9e867486c8653482becc16446.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4484364/normal_5ff37e8a00403.pdf
- https://s3.amazonaws.com/viregujipowuru/miwuzufowuwivukebarevifo.pdf
- https://5057b38b-f250-4925-a5fd-2dbc054a2c1f.filesusr.com/ugd/25ee37_eea10b516b174855a77fa3421659a35d.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4379482/normal_6056d62e3badb.pdf
- https://s3.amazonaws.com/jajoxulabojaso/bobby_womack_harry_hippie.pdf
- https://cdn.sqhk.co/waxubisolo/9IEgeii/61709890073.pdf
- https://cdn-cms.f-static.net/uploads/4404293/normal_5fd27ddf2b29a.pdf
- https://s3.amazonaws.com/lewuli/ferovalonilujutudakujaku.pdf
- https://cdn.sqhk.co/fojevimexu/Wjcijjg/sifakinuvuga.pdf
- https://s3.amazonaws.com/nabifovu/17963285187.pdf
- https://e192e36c-395d-4660-9df6-aa7aed00c30a.filesusr.com/ugd/3aee12_f53e2c4e30c240008a321c55102328b9.pdf?index=true
- https://s3.amazonaws.com/nawosineromigi/invoice_audit_template.pdf
- https://cdn.sqhk.co/gubusase/ibHTggV/68036727314.pdf
- https://s3.amazonaws.com/paropabaru/58061950872.pdf
- https://cdn.sqhk.co/kogeledewafo/egcifmu/spotlight_room_escape_losung_kapitel_2_level_1.pdf
- https://cdn.sqhk.co/foxidagon/iQpgfSC/my_airtel_mobile_number_offer_check.pdf
- https://cdn.sqhk.co/nujoxodove/XhfYkqJ/3503_east_frontage_road_tampa_fl.pdf
- https://s3.amazonaws.com/xopugup/11421725148.pdf
- https://s3.amazonaws.com/serogajugomiji/keponumaxug.pdf
- https://cdn-cms.f-static.net/uploads/4471703/normal_606e30255e8c0.pdf
Embedded domains
- xajibur.ru
- cdn.sqhk.co
- 9a4b5e96-23fe-4021-9525-787506808755.filesusr.com
- 01dc7cc6-b8ed-446e-8cc8-1ad78882ed38.filesusr.com
- static.s123-cdn-static.com
- s3.amazonaws.com
- 5057b38b-f250-4925-a5fd-2dbc054a2c1f.filesusr.com
- cdn-cms.f-static.net
- e192e36c-395d-4660-9df6-aa7aed00c30a.filesusr.com
- 21d44941-995c-48b9-956b-8145330e20d5.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report