MALICIOUS — 25270e_eff3f50a6aa248c898e99b8d5386d279.pdf
MALICIOUS — 25270e_eff3f50a6aa248c898e99b8d5386d279.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6d06d5019bbb7198775c932a71e30ff8e6623a3ab70362db9fc3b1502693cc31 - SHA-1:
ea11b01144042d67dcb59829a696764229ce140b - MD5:
53aabbf7d494280858a7ef792ff406bc - ssdeep:
3072:s914Suy0GNXQDh1JH0LW1/TpKbBo+EB4Ct:sD4SdXQ1XULGMOn - TLSH:
T1D03CF2F3A0B3DE4CFAC7AB03F9E7252C948787C46462AF540484BA6CD41C2AD7E55611 - Submitted as: 25270e_eff3f50a6aa248c898e99b8d5386d279.pdf
- File type: pdf · Size: 120909 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://d73c234d-0e3d-497d-8108-d5659bace061.filesusr.com/ugd/58a813_c5b6fdbb254148bc89736a4c3bac2c59.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://botokaw.ru/wix?keyword=roblox+void+script+builder+sans, http://nomokesus.sportsontheweb.net/botany_practical_book_part_1.pdf, https://uploads.strikinglycdn.com/files/cc6a0327-4980-469f-864d-e7e6e16805b5/18849427839.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: js, uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://botokaw.ru/wix?keyword=roblox+void+script+builder+sans
- http://nomokesus.sportsontheweb.net/botany_practical_book_part_1.pdf
- https://uploads.strikinglycdn.com/files/cc6a0327-4980-469f-864d-e7e6e16805b5/18849427839.pdf
- https://uploads.strikinglycdn.com/files/7066b752-faba-4c00-ab7e-e7bfc6956a67/definition_of_legal_terminology.pdf
- https://d73c234d-0e3d-497d-8108-d5659bace061.filesusr.com/ugd/58a813_c5b6fdbb254148bc89736a4c3bac2c59.pdf?index=true
- https://uploads.strikinglycdn.com/files/e1409562-1bb0-49c4-a2b6-dbd5cd0f9f5d/demumesuvuwinokenufet.pdf
- https://1cb55408-229d-4ffc-b0b8-1541e98da6b7.filesusr.com/ugd/455f95_265d37782c544062b61a4b05f7c850a1.pdf?index=true
- http://premiumpornclips.com/67162271029zpr25.pdf
- http://gloslides.com/why_is_my_fire_alarm_blinking_greenodzce.pdf
- https://6d4a8fb0-9a8a-4850-8aa1-2b5706121c9a.filesusr.com/ugd/ff2e72_ec8c053d2392419daf9b175108ff271e.pdf?index=true
- https://uploads.strikinglycdn.com/files/54609bd3-aa0f-46f2-83af-e2d76fffaeef/jugikezufexafode.pdf
- http://pelubexeto.getenjoyment.net/food_allergen_list.pdf
- https://uploads.strikinglycdn.com/files/5335d5e8-6273-4f08-bb86-96daadeee9bd/xobugamojuv.pdf
- https://cb47f074-0476-4434-b381-5672a365cab8.filesusr.com/ugd/c46c8a_1531285d35a84118bd460a9a3e389ee3.pdf?index=true
- https://c6de0af5-2a4c-46da-924c-839bccb102c6.filesusr.com/ugd/5f1f0f_f8b467cda30e4ea0835c3195fcb5f966.pdf?index=true
- https://780c8f77-0f51-49ab-8dd1-60a90eb210a4.filesusr.com/ugd/1b8612_4ac6835dd84a46079ed5acab8931c607.pdf?index=true
- http://freud.icu/how_to_calculate_p_value_from_f_statistic_in_rw6pqj.pdf
- http://xemigososefof.atwebpages.com/strongs_exhaustive_concordance_of_the_bible_the_old-time_gospel_hour_edition.pdf
- http://remont-kvartir-otzyvy.moscow/demon_spirit_seed_manual_malclf8e.pdf
- https://6e7ef639-f89a-4701-86f9-710a836f1183.filesusr.com/ugd/12745a_9b04125a7cb74a60b91cbf669e0307a1.pdf?index=true
- https://uploads.strikinglycdn.com/files/fe00d98e-136b-429f-bafa-06242912a09d/26745310539.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- botokaw.ru
- nomokesus.sportsontheweb.net
- uploads.strikinglycdn.com
- d73c234d-0e3d-497d-8108-d5659bace061.filesusr.com
- 1cb55408-229d-4ffc-b0b8-1541e98da6b7.filesusr.com
- premiumpornclips.com
- gloslides.com
- 6d4a8fb0-9a8a-4850-8aa1-2b5706121c9a.filesusr.com
- pelubexeto.getenjoyment.net
- cb47f074-0476-4434-b381-5672a365cab8.filesusr.com
- c6de0af5-2a4c-46da-924c-839bccb102c6.filesusr.com
- 780c8f77-0f51-49ab-8dd1-60a90eb210a4.filesusr.com
- freud.icu
- xemigososefof.atwebpages.com
- 6e7ef639-f89a-4701-86f9-710a836f1183.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- remont-kvartir-otzyvy.moscow
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report