MALICIOUS — 3da3f07406f3cdd42b012222df9c662e382f47c504f8a70f59afdb67cdb19794
MALICIOUS — 3da3f07406f3cdd42b012222df9c662e382f47c504f8a70f59afdb67cdb19794 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3da3f07406f3cdd42b012222df9c662e382f47c504f8a70f59afdb67cdb19794 - SHA-1:
59f92c7042361098cd3b1e807db82d7f16672217 - MD5:
b053c019f35a4b8d0790ef00948b8d4c - ssdeep:
1536:1LpQ1wUeON76nBqdg5d/pWsXu2TfETVH1PdBJkO1LTLDHXv0dwVG:nQz5x64wIsBTwVHjBCOHXv0db - TLSH:
T12438D0F38197EC8CBA578B83AEF70469940AC7C85137AB2055887A3DC67C2AE7F10551 - Submitted as: 3da3f07406f3cdd42b012222df9c662e382f47c504f8a70f59afdb67cdb19794
- File type: pdf · Size: 77355 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!B053C019F35A
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://tojaluteder.weebly.com/uploads/1/3/4/3/134384479/3562fe2adfe4e.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://jottigo.ru/strik?utm_term=dmv+audio+driving+test+appointment, https://tojaluteder.weebly.com/uploads/1/3/4/3/134384479/3562fe2adfe4e.pdf, http://fresh-ita.fun/955197621077zi19.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jottigo.ru/strik?utm_term=dmv+audio+driving+test+appointment
- https://tojaluteder.weebly.com/uploads/1/3/4/3/134384479/3562fe2adfe4e.pdf
- http://fresh-ita.fun/955197621077zi19.pdf
- https://uploads.strikinglycdn.com/files/d019deba-48d0-4961-af38-1386826b2f04/wejodoxufulopodiwubis.pdf
- http://parubexe.iblogger.org/legesinesosokufusatozum.pdf
- http://tryici.xyz/mht_cet_question_papers_with_answers_free_download_biology6jyo0.pdf
- https://58fabbca-0322-4868-a582-948aa19840f9.filesusr.com/ugd/93748c_b5ba9128f8ab4c0c875828763912f947.pdf?index=true
- https://fejajeger.weebly.com/uploads/1/3/4/6/134614243/67b7501.pdf
- http://tagugatukosag.epizy.com/bavomifofesalon.pdf
- https://uploads.strikinglycdn.com/files/13528be2-b6a0-4a5d-9632-76effae1d673/xipajigukerosemuvewajujep.pdf
- https://uploads.strikinglycdn.com/files/adfa2d1b-175f-482f-aaf2-4fd8999898cb/dcs_world_mission_editor_tutorial.pdf
- https://uploads.strikinglycdn.com/files/90dd1c03-4295-408f-a530-ed412fe7e293/how_to_set_time_in_casio_edifice_era_600.pdf
- https://rofaxebawo.weebly.com/uploads/1/3/4/7/134750080/b109160d5ce96.pdf
- http://daliadiago.com/schwinn_bike_seat_installation_instructionskae7f.pdf
- https://finepeva.weebly.com/uploads/1/3/5/3/135347337/6c2bedf80f48.pdf
- https://nasaxedinevizuv.weebly.com/uploads/1/3/4/7/134759800/909610.pdf
- http://xujijanuzovaziv.rf.gd/brush_pen_fonts_free.pdf
- http://gejevebo.epizy.com/newuw.pdf
- https://uploads.strikinglycdn.com/files/10e79003-4e0c-4df8-af61-4876a3a1e7fa/xowavabe.pdf
- https://5b5cf7c4-d983-4e27-bd54-44d52fc9074e.filesusr.com/ugd/2f9450_58de1eb02e7942c199bdc51ba04dae52.pdf?index=true
- https://uploads.strikinglycdn.com/files/44432fd2-11cb-4b46-a2e5-7caab329ed6d/zubatis.pdf
- http://lujadexezusunam.22web.org/85428358399.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- jottigo.ru
- tojaluteder.weebly.com
- fresh-ita.fun
- uploads.strikinglycdn.com
- parubexe.iblogger.org
- tryici.xyz
- 58fabbca-0322-4868-a582-948aa19840f9.filesusr.com
- fejajeger.weebly.com
- tagugatukosag.epizy.com
- rofaxebawo.weebly.com
- daliadiago.com
- finepeva.weebly.com
- nasaxedinevizuv.weebly.com
- gejevebo.epizy.com
- 5b5cf7c4-d983-4e27-bd54-44d52fc9074e.filesusr.com
- lujadexezusunam.22web.org
- www.w3.org
- purl.org
- ns.adobe.com
- xujijanuzovaziv.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report