MALICIOUS — 3cb6cb_d20ce6d0df9d4ed49dd8c5498866d107.pdf
MALICIOUS — 3cb6cb_d20ce6d0df9d4ed49dd8c5498866d107.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6b6065df333f110922ca5566db845a3cecb1ae5f00dfb628eb27e1d15bca580b - SHA-1:
6f9a264176e39a03fb2ed0bfeb4d5946efdd4e0a - MD5:
b4e6ae7db3fbb38b63e0186ea1febc35 - ssdeep:
1536:cdqbsB5W59m0CeicRDvPR1N6YnfG8DJO1g2kEOdfSh1gl9I5GM3bI6XJsWOhjzWR:KWbUGbP3IyfZ5xEL4leLbrJ6jzTFE - TLSH:
T16C3CD0F361DBDCCE734B5BC37DEB1918708AD6A521368B90A4CC662C893D2BCAD14581 - Submitted as: 3cb6cb_d20ce6d0df9d4ed49dd8c5498866d107.pdf
- File type: pdf · Size: 122543 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://0e627107-309b-4451-a84d-e7064c41fccd.filesusr.com/ugd/04c368_4eff5670be8349d5b524db8b5657d9e9.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://fokemale.ru/wix?keyword=%25D8%25A8%25DB%258C%25D8%25A7+%25D8%25AA%25D9%2588+%25DA%25A9%25D8%25B1%25D9%2587+%25D9%2587%25D8%25AA%25D9%2584+%25D8%25AF%25D9%2584+%25D9%2584%25D9%2588%25D9%2586%25D8%25A7, https://cdn.sqhk.co/butofelo/odVhgoP/sumo_logic_stock_ipo_date.pdf, https://cdn.sqhk.co/sunomedude/jahjUgh/demolition_derby_crash_racing_mod_apk_unlimited_money.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://fokemale.ru/wix?keyword=%25D8%25A8%25DB%258C%25D8%25A7+%25D8%25AA%25D9%2588+%25DA%25A9%25D8%25B1%25D9%2587+%25D9%2587%25D8%25AA%25D9%2584+%25D8%25AF%25D9%2584+%25D9%2584%25D9%2588%25D9%2586%25D8%25A7
- https://cdn.sqhk.co/butofelo/odVhgoP/sumo_logic_stock_ipo_date.pdf
- https://cdn.sqhk.co/sunomedude/jahjUgh/demolition_derby_crash_racing_mod_apk_unlimited_money.pdf
- https://cdn.sqhk.co/tatidukigag/hagdidm/64308510573.pdf
- https://cdn.sqhk.co/sidamebo/h203tzz/joxifilizima.pdf
- https://uploads.strikinglycdn.com/files/5d106535-54cb-4c60-a9e7-c647e2f6ba96/poxopofedutamawob.pdf
- https://0e627107-309b-4451-a84d-e7064c41fccd.filesusr.com/ugd/04c368_4eff5670be8349d5b524db8b5657d9e9.pdf?index=true
- https://uploads.strikinglycdn.com/files/ef73652b-0050-4585-9926-e6ec8c01bd18/lagirelijajuzegasezuzifaz.pdf
- https://cdn.sqhk.co/xasakeza/hnGSvjj/54199582674.pdf
- http://pukujadud.getenjoyment.net/parts_of_speech_worksheets_with_answer_key.pdf
- https://7a48fde5-f9d1-4ce4-84a2-8b156d245d18.filesusr.com/ugd/8127dd_585cd92d4eea493981ab2f838080ff70.pdf?index=true
- https://cdn.sqhk.co/rowubuvuke/HoTgigd/shtf_survival_items.pdf
- http://vaxisezawoged.scienceontheweb.net/novewipogam.pdf
- http://puvuwanixos.rf.gd/53832865993.pdf
- https://cdn.sqhk.co/kelarega/ciSTHif/84701475674.pdf
- http://kasaxamaburabuz.epizy.com/59907575008.pdf
- http://movawizaxaxato.mywebcommunity.org/ropuboxivaginepo.pdf
- https://uploads.strikinglycdn.com/files/4e6494cc-545e-4a9b-899f-410d19ea0b12/mebopofegolefuvibexideja.pdf
- http://mufutekuson.getenjoyment.net/how_much_does_it_cost_to_fix_a_refrigerator_compressor.pdf
- http://vifezitenof.getenjoyment.net/was_the_progressive_era_really_progressive.pdf
- https://uploads.strikinglycdn.com/files/6490dd00-0791-4ca5-8b21-ef8775cadd3d/masurapukabarilakuwubegoj.pdf
- http://wawutanow.epizy.com/telangana_janapada_dj_songs_naa.pdf
- http://zavinawotomuvef.epizy.com/polo_shirt_mockup_free.pdf
- https://uploads.strikinglycdn.com/files/5f118c22-1d02-4649-b911-fc2645a87813/lyman_reloading_press_shell_holder.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- fokemale.ru
- cdn.sqhk.co
- uploads.strikinglycdn.com
- 0e627107-309b-4451-a84d-e7064c41fccd.filesusr.com
- pukujadud.getenjoyment.net
- 7a48fde5-f9d1-4ce4-84a2-8b156d245d18.filesusr.com
- vaxisezawoged.scienceontheweb.net
- kasaxamaburabuz.epizy.com
- movawizaxaxato.mywebcommunity.org
- mufutekuson.getenjoyment.net
- vifezitenof.getenjoyment.net
- wawutanow.epizy.com
- zavinawotomuvef.epizy.com
- www.w3.org
- purl.org
- ns.adobe.com
- puvuwanixos.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report