MALICIOUS — eb712c_c0fd3a29732b47ebb16dfdeab8a81b45.pdf
MALICIOUS — eb712c_c0fd3a29732b47ebb16dfdeab8a81b45.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
40fe23a850d03ba37e0694702b4221f353a2e6694964719fe146215029cbb8cf - SHA-1:
f8dbd4617e81b3d6d2dff55b1553df548e8b629f - MD5:
1fe3bfdada64539af440f0401a4311a3 - ssdeep:
1536:epcEHR1L1Oycz1kYRRg+JshGnx4gitZDBzZ1vpm8eOMpvptlee1h:Yx91O3Ji+JshGn83DB11vE8eFHe4 - TLSH:
T17438D1F36097ED4CFA9B5B03BEFB4199244AC3855223E7505048B72CC97C2AEBE20516 - Submitted as: eb712c_c0fd3a29732b47ebb16dfdeab8a81b45.pdf
- File type: pdf · Size: 78387 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!1FE3BFDADA64
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://bcd7deca-fd5d-492b-a220-d373ca515bc9.filesusr.com/ugd/12f4eb_98cb2d58ef524cb3b3a93a555ce6bcbb.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://nipisod.ru/wix?keyword=logic+pro+x+user+guide+download, https://bcd7deca-fd5d-492b-a220-d373ca515bc9.filesusr.com/ugd/12f4eb_98cb2d58ef524cb3b3a93a555ce6bcbb.pdf?index=true, http://mirror-x.org/19706096168dbl6a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nipisod.ru/wix?keyword=logic+pro+x+user+guide+download
- https://bcd7deca-fd5d-492b-a220-d373ca515bc9.filesusr.com/ugd/12f4eb_98cb2d58ef524cb3b3a93a555ce6bcbb.pdf?index=true
- http://mirror-x.org/19706096168dbl6a.pdf
- https://cdn-cms.f-static.net/uploads/4481155/normal_602f0d3321eee.pdf
- https://b6f97e74-198a-461d-a312-d71b9712332b.filesusr.com/ugd/a2d007_557db268356048cdb48169e6f46ee34f.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4417033/normal_6031c45beb370.pdf
- http://dinilemave.epizy.com/nejisafesuporuvopizaz.pdf
- https://0ef2f354-78a3-4528-990c-72f69c86fc6a.filesusr.com/ugd/6a0da6_00b72fe8ee9e479fac01e64aaadc15ec.pdf?index=true
- http://lnstagramverifiedsbadgesforms.com/education_galaxy_the_gamemnn7r.pdf
- https://cdn-cms.f-static.net/uploads/4448137/normal_6032177aca7ce.pdf
- https://0e733887-fd72-4d21-8b10-0a39cafbc931.filesusr.com/ugd/1e4d10_9c8336acfc974da88e14f7e240e8a491.pdf?index=true
- https://bb491b24-4c81-4ccc-8daa-bf1baeb171c2.filesusr.com/ugd/93c935_f5bddd1db8da434091605c28815a1eb6.pdf?index=true
- https://uploads.strikinglycdn.com/files/5c0b379c-6abe-4643-b2b6-9ebbed1b4aea/can_you_work_at_rue21_at_14.pdf
- https://uploads.strikinglycdn.com/files/c0110d94-04a5-4aa2-b3ac-126e3577db3e/crossfit_workouts_at_home_without_equipment_for_beginners.pdf
- https://uploads.strikinglycdn.com/files/371fd794-f6da-446c-99b1-c2e63257f7e8/bowama.pdf
- http://zazaluvuzusu.rf.gd/xexoxabe.pdf
- http://filmera.ru/asge_guidelines_surveillance_colonoscopy7b1y9.pdf
- http://pumonufagatoteb.epizy.com/bounce_fabric_sheets_and_mice.pdf
- http://the-glow.ru/nikon_sb-800_speedlight_flashyqve0.pdf
- http://dadojusox.epizy.com/ayyappa_harivarasanam_ringtones_free.pdf
- http://vexorulutukozov.rf.gd/how_to_enter_commands_in_autocad.pdf
- https://uploads.strikinglycdn.com/files/2cb5074d-9ea3-4559-8a83-a646972abfa5/57225358035.pdf
- https://cdn-cms.f-static.net/uploads/4389571/normal_60358ada520ad.pdf
- http://albl.ru/87582786116afaz1.pdf
- http://espacecmb.xyz/is_new_verizon_router_worth_itt0xzp.pdf
Embedded domains
- nipisod.ru
- bcd7deca-fd5d-492b-a220-d373ca515bc9.filesusr.com
- mirror-x.org
- cdn-cms.f-static.net
- b6f97e74-198a-461d-a312-d71b9712332b.filesusr.com
- dinilemave.epizy.com
- 0ef2f354-78a3-4528-990c-72f69c86fc6a.filesusr.com
- lnstagramverifiedsbadgesforms.com
- 0e733887-fd72-4d21-8b10-0a39cafbc931.filesusr.com
- bb491b24-4c81-4ccc-8daa-bf1baeb171c2.filesusr.com
- uploads.strikinglycdn.com
- filmera.ru
- pumonufagatoteb.epizy.com
- the-glow.ru
- dadojusox.epizy.com
- albl.ru
- espacecmb.xyz
- parralax.net
- www.w3.org
- purl.org
- ns.adobe.com
- zazaluvuzusu.rf.gd
- vexorulutukozov.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report