MALICIOUS — 60c6c5e8b8257da5848d4f7c5fda7c14372725649c975fac8ab413a7af3c8bd2
MALICIOUS — 60c6c5e8b8257da5848d4f7c5fda7c14372725649c975fac8ab413a7af3c8bd2 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
60c6c5e8b8257da5848d4f7c5fda7c14372725649c975fac8ab413a7af3c8bd2 - SHA-1:
0a6a8009f64b9bd4f4462536154ce5b4c21e9082 - MD5:
60409f70d0f7e21e06ba1c9fc1af843c - ssdeep:
1536:1Kj6sYI4iMz8znouPE5fTT5FhktHL/7z4jsHJkT4:cj6sYfuLjs5xMtHLjUjsHJ - TLSH:
T19037B0F32093EE8C7A86DF132DA7655D6589E38C5132DB5144886F3CC5BC3AE6E50940 - Submitted as: 60c6c5e8b8257da5848d4f7c5fda7c14372725649c975fac8ab413a7af3c8bd2
- File type: pdf · Size: 74508 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!60409F70D0F7
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://gedofulijul.weebly.com/uploads/1/3/0/7/130775434/3957515.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ponafet.ru/strik?utm_term=how+to+know+when+you%2527re+drinking+too+much+water, https://gedofulijul.weebly.com/uploads/1/3/0/7/130775434/3957515.pdf, http://prognoz-football.club/anamnese_terapia_holisticaeubui.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ponafet.ru/strik?utm_term=how+to+know+when+you%2527re+drinking+too+much+water
- https://gedofulijul.weebly.com/uploads/1/3/0/7/130775434/3957515.pdf
- http://prognoz-football.club/anamnese_terapia_holisticaeubui.pdf
- http://generalmassage.online/oscar_wilde_death_hotelbhc1c.pdf
- http://gogogoinst.xyz/59865928838k20sy.pdf
- https://s3.amazonaws.com/xepululejiwof/jenusiwewuxumir.pdf
- https://rofokaragi.weebly.com/uploads/1/3/2/8/132815015/1681981.pdf
- http://nubolats.xyz/2002_ford_explorer_sport_trac_fuse_box_diagramgb95k.pdf
- https://s3.amazonaws.com/zarelusipofox/85348361087.pdf
- https://bojurejid.weebly.com/uploads/1/3/4/8/134887271/6120009.pdf
- https://s3.amazonaws.com/gezejoputiwinu/86638306008.pdf
- http://thelandofbadideas.com/nuputalulfm3jd.pdf
- https://gefaturulabi.weebly.com/uploads/1/3/4/4/134487578/rosin.pdf
- https://pejejuwefosewa.weebly.com/uploads/1/3/4/0/134040570/jopesuzi-bebig-nowugop.pdf
- https://cdn-cms.f-static.net/uploads/4479691/normal_605f43e94b7e2.pdf
- https://s3.amazonaws.com/gudukupir/ropawemakapu.pdf
- http://present-mag.ru/resident_evil_3_safe_code_carloskbqgt.pdf
- https://s3.amazonaws.com/kewakuko/overseas_but_im_only_one_call_away_lyrics.pdf
- https://ziregorex.weebly.com/uploads/1/3/5/3/135351653/xiliber.pdf
- https://milonotupilo.weebly.com/uploads/1/3/5/3/135347339/kevajosekotol.pdf
- https://solezoxi.weebly.com/uploads/1/3/4/6/134654925/jipafasej-dalidaruz-pozavase-bezozitija.pdf
- http://domainlimax.xyz/nesewajoxus7879s.pdf
- http://cardioactiveuficiale.site/cartoon_cute_animalsw5aoq.pdf
- https://static.s123-cdn-static.com/uploads/4413866/normal_5fddb754ee42c.pdf
- http://jakor.pro/85742735548zc95c.pdf
Embedded domains
- ponafet.ru
- gedofulijul.weebly.com
- prognoz-football.club
- generalmassage.online
- gogogoinst.xyz
- s3.amazonaws.com
- rofokaragi.weebly.com
- nubolats.xyz
- bojurejid.weebly.com
- thelandofbadideas.com
- gefaturulabi.weebly.com
- pejejuwefosewa.weebly.com
- cdn-cms.f-static.net
- present-mag.ru
- ziregorex.weebly.com
- milonotupilo.weebly.com
- solezoxi.weebly.com
- domainlimax.xyz
- cardioactiveuficiale.site
- static.s123-cdn-static.com
- jakor.pro
- kaledawuvilef.weebly.com
- pressit.space
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report