MALICIOUS — 552f9ea88e877eb796db9f2acd85037f8ed770808ca18901e989b506070b262d
MALICIOUS — 552f9ea88e877eb796db9f2acd85037f8ed770808ca18901e989b506070b262d is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
552f9ea88e877eb796db9f2acd85037f8ed770808ca18901e989b506070b262d - SHA-1:
954b26158dbff1f675a281de3f181a7243801bc6 - MD5:
82a4f06144915307aa3d3ef251c8c974 - ssdeep:
1536:oyS1/6pm+CJgw9lyKQPJB0BgUkanAtZ2D3mhrb0U15SAEdBzBhrZCf/OL:WSpmWgMB0BsTn5SLBtZCfe - TLSH:
T1F53AE0F752D7DC8CB68B9F43FA5B296D698D838C653786500448A73CC4AC35EBE20A11 - Submitted as: 552f9ea88e877eb796db9f2acd85037f8ed770808ca18901e989b506070b262d
- File type: pdf · Size: 96806 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4495999/normal_5fe161f9838ad.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://kuzutuzo.ru/strik?utm_term=the+magicians+season+5+netflix+release, https://uploads.strikinglycdn.com/files/9f09975b-c727-4374-b3b6-fe355fe4e05f/christian_worship_supplement.pdf, https://deed868a-3c3f-4b0d-b3ae-f9ebe8a38c33.filesusr.com/ugd/95283b_6284bbae9d034ef898850ad0f526b49c.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://kuzutuzo.ru/strik?utm_term=the+magicians+season+5+netflix+release
- https://s3.amazonaws.com/xokebore/jabirovibemunakufobudubu.pdf
- https://uploads.strikinglycdn.com/files/9f09975b-c727-4374-b3b6-fe355fe4e05f/christian_worship_supplement.pdf
- https://s3.amazonaws.com/viboxikuz/manual_of_sensorless_brushless_motor_speed_controller.pdf
- https://deed868a-3c3f-4b0d-b3ae-f9ebe8a38c33.filesusr.com/ugd/95283b_6284bbae9d034ef898850ad0f526b49c.pdf?index=true
- https://kabugumaka.weebly.com/uploads/1/3/6/0/136099465/7255742.pdf
- https://cdn-cms.f-static.net/uploads/4379960/normal_6018f7862af3a.pdf
- https://kotezoxeruv.weebly.com/uploads/1/3/5/3/135345651/067b94e168e9dc.pdf
- https://uploads.strikinglycdn.com/files/b5929d40-854d-45e7-8383-1ba7bc96650c/the_dream_of_the_rood.pdf
- https://static.s123-cdn-static.com/uploads/4495999/normal_5fe161f9838ad.pdf
- https://2d130471-2a64-48ba-87cf-8f1e86c6acad.filesusr.com/ugd/9c43ec_7d824052cb55419c88c95eb8013d0d4b.pdf?index=true
- https://s3.amazonaws.com/labitajaxatufib/ministry_of_health_uganda_guidelines.pdf
- https://3abcc933-4059-444f-8e65-7077e95f005f.filesusr.com/ugd/44645f_2777a82ce9f14d59987a86237c7fd6b9.pdf?index=true
- https://53002a68-e35f-4167-ac88-1ab9777d7e72.filesusr.com/ugd/f5bc2a_9b61149dbd4745bca872e2b2cca84c29.pdf?index=true
- http://nonly.xyz/dasgupta_algorithms_solutions_manual8fok0.pdf
- https://s3.amazonaws.com/nademopor/daru_badnaam_kardi_song_raagsong.pdf
- https://8b7199fc-a029-4910-8138-caee300d1cbd.filesusr.com/ugd/da8f68_49f6b871d1bd454ba1ae475d30c996f9.pdf?index=true
- http://astrology-personal.online/39195658634w80q.pdf
- https://cdn-cms.f-static.net/uploads/4425728/normal_605d69f3522f5.pdf
- http://lovewaits.ru/ancient_civilization_persian_chart78a38.pdf
- https://xopilujipuwoka.weebly.com/uploads/1/3/4/8/134886601/960474.pdf
- https://static.s123-cdn-static.com/uploads/4369317/normal_5fc93162d2946.pdf
- https://uploads.strikinglycdn.com/files/8dba76d3-5bdb-4d4d-8621-6da470abb30b/what_is_cos_180_-_theta.pdf
- https://cdn-cms.f-static.net/uploads/4452595/normal_605439859e421.pdf
- https://uploads.strikinglycdn.com/files/3bcf7a3f-241c-4be2-b700-a7f06b4129f8/kexavujis.pdf
Embedded domains
- kuzutuzo.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- deed868a-3c3f-4b0d-b3ae-f9ebe8a38c33.filesusr.com
- kabugumaka.weebly.com
- cdn-cms.f-static.net
- kotezoxeruv.weebly.com
- static.s123-cdn-static.com
- 2d130471-2a64-48ba-87cf-8f1e86c6acad.filesusr.com
- 3abcc933-4059-444f-8e65-7077e95f005f.filesusr.com
- 53002a68-e35f-4167-ac88-1ab9777d7e72.filesusr.com
- nonly.xyz
- 8b7199fc-a029-4910-8138-caee300d1cbd.filesusr.com
- astrology-personal.online
- lovewaits.ru
- xopilujipuwoka.weebly.com
- sapilijufidukuw.weebly.com
- idealica-columbia.site
- tokio-2020.fun
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report