MALICIOUS — dusume-vexukof.pdf
MALICIOUS — dusume-vexukof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5fa7ab60e3bead52f8b6538849e4b9732f90dacde4953b4f972471f37ce20b23 - SHA-1:
75fdf984564cc5b28480a349bb65474ffec499cf - MD5:
f89865466acf86c280dc81b10db88575 - ssdeep:
3072:RS873Fs9siGmuYu+klfKyx925BQ5DMUXlZqsSD82:U871AH3uY9lk9mcD5qsE - TLSH:
T1E43CF1F31283DC9DBA899F436EB310DC2889C788753296A1494CB72C85B87ED6D52D21 - Submitted as: dusume-vexukof.pdf
- File type: pdf · Size: 121721 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4472488/normal_6002a686c1f5f.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://crophysi.ru/wb?keyword=what%20is%20my%20native%20american%20zodiac%20sign, https://uploads.strikinglycdn.com/files/236b0040-7eab-447b-bc68-20e55eb34e35/verbos_regulares_e_irregulares_en_pasado_simple_ingles.pdf, https://uploads.strikinglycdn.com/files/223faf1f-8bae-4a28-8e8a-189d2a5f8e33/liwoso.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crophysi.ru/wb?keyword=what%20is%20my%20native%20american%20zodiac%20sign
- https://uploads.strikinglycdn.com/files/236b0040-7eab-447b-bc68-20e55eb34e35/verbos_regulares_e_irregulares_en_pasado_simple_ingles.pdf
- https://uploads.strikinglycdn.com/files/223faf1f-8bae-4a28-8e8a-189d2a5f8e33/liwoso.pdf
- https://cdn-cms.f-static.net/uploads/4414174/normal_6069dfb5993c6.pdf
- https://cdn-cms.f-static.net/uploads/4469378/normal_603ffb4f53a23.pdf
- https://tuwijojax.weebly.com/uploads/1/3/4/4/134477229/dozonofopatenez.pdf
- https://cdn-cms.f-static.net/uploads/4463803/normal_60412d1bbd125.pdf
- https://sarodinejafa.weebly.com/uploads/1/3/4/7/134762654/gujax_wuvevogi.pdf
- https://pevetogebika.weebly.com/uploads/1/3/5/3/135335423/piwunupelufabi.pdf
- https://static.s123-cdn-static.com/uploads/4472488/normal_6002a686c1f5f.pdf
- https://uploads.strikinglycdn.com/files/25b7c138-3056-42a3-9880-293f4f278419/lonupaxedujadav.pdf
- https://uploads.strikinglycdn.com/files/9505147e-f51c-4dd2-be76-ec98e5fbfaee/89983287810.pdf
- https://cdn-cms.f-static.net/uploads/4474734/normal_602586023c75a.pdf
- https://cdn-cms.f-static.net/uploads/4476758/normal_60485c05c21bc.pdf
- https://static.s123-cdn-static.com/uploads/4406228/normal_5fc758e086380.pdf
- https://getawotenag.weebly.com/uploads/1/3/4/4/134443600/2227182.pdf
- https://static.s123-cdn-static.com/uploads/4373788/normal_5fc7a560a0cad.pdf
- https://uploads.strikinglycdn.com/files/8dfc54ce-d4b2-48d3-b900-a06950a8a49a/73594565589.pdf
- https://rojomitalo.weebly.com/uploads/1/3/4/4/134485393/bamukotokawan-feperufidaxe-minegogejo.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_6040c02e7050f.pdf
- https://lurovexizapup.weebly.com/uploads/1/3/4/4/134402553/3360457.pdf
- https://uploads.strikinglycdn.com/files/4fbaf980-48f8-494d-8c54-519bcea4706d/fazibifofajaxamoxijexuto.pdf
- https://uploads.strikinglycdn.com/files/2574c84c-e1e8-4b7b-bb71-a3cedea23545/physics_classroom_worksheet_answer_key.pdf
- https://cdn-cms.f-static.net/uploads/4462730/normal_5fd3410a06b86.pdf
- https://uploads.strikinglycdn.com/files/1549fcf6-ce0f-4940-b76d-bcb2ea0d8a54/rovudidofusis.pdf
Embedded domains
- crophysi.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- tuwijojax.weebly.com
- sarodinejafa.weebly.com
- pevetogebika.weebly.com
- static.s123-cdn-static.com
- getawotenag.weebly.com
- rojomitalo.weebly.com
- lurovexizapup.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report