MALICIOUS — jeremih_love_dont_change_mp3_download.pdf
MALICIOUS — jeremih_love_dont_change_mp3_download.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 6 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6f8a033b050d6bd36d0f950c9fb15a41f50f0718e94af839fb03e6fc51a4c5aa - SHA-1:
35da73431abd1eaacf4a041f7b737a8e380db2a8 - MD5:
c664d2e88406654816560ed0be0abf7b - ssdeep:
1536:j9ak/4eeoOITPVXuIsW+Ufe4rxMchgHk9R87xBy6V0c1ab09wJ6QBWlpbEjXn:pSyDPVXusHfeagHkHaq6V0qcY+60WgT - TLSH:
T15D38C0F361A7DD8C794FA753A9BB1258744ED3485632DB900489B66CC0AC2BD3F10A52 - Submitted as: jeremih_love_dont_change_mp3_download.pdf
- File type: pdf · Size: 83048 bytes
- Verdict: malicious (96/100)
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!C664D2E88406
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/92bbb659-00d8-4dea-b488-3fad2f5fc058/91935245505.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://krisoc.ru/pbw?utm_term=jeremih+love+dont+change+mp3+download, https://uploads.strikinglycdn.com/files/92bbb659-00d8-4dea-b488-3fad2f5fc058/91935245505.pdf, http://nusuwoxub.pbworks.com/f/lab_safety_rules_sheet.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://krisoc.ru/pbw?utm_term=jeremih+love+dont+change+mp3+download
- https://uploads.strikinglycdn.com/files/92bbb659-00d8-4dea-b488-3fad2f5fc058/91935245505.pdf
- http://nusuwoxub.pbworks.com/f/lab_safety_rules_sheet.pdf
- https://uploads.strikinglycdn.com/files/89bf54c2-c966-4428-a497-49ee9db7752c/who_owns_ruger.pdf
- https://cdn-cms.f-static.net/uploads/4418781/normal_5fd8b7373a780.pdf
- https://tutemedoz.weebly.com/uploads/1/3/2/8/132814241/jelekekebomizadal.pdf
- http://risuxujuvu.pbworks.com/f/pyar_kiya_to_nibhana_remix_mp3_free_download.pdf
- https://misamizejip.weebly.com/uploads/1/3/4/3/134348089/rivumif.pdf
- http://kunixove.pbworks.com/w/file/fetch/144485157/28565210786.pdf
- https://static.s123-cdn-static.com/uploads/4498376/normal_5ff8d9bd942df.pdf
- http://runaliguredu.pbworks.com/w/file/fetch/144475839/48662920868.pdf
- https://cdn-cms.f-static.net/uploads/4420430/normal_605714a63051c.pdf
- https://uploads.strikinglycdn.com/files/d035b64d-512e-4bc5-8db8-0bd20d8f7ecd/echo_blower_pb-250ln_no_spark.pdf
- https://cdn-cms.f-static.net/uploads/4413242/normal_6030fed59f027.pdf
- https://uploads.strikinglycdn.com/files/8c6184f5-67b3-4a77-a5d9-adc15782eafb/hot_fuzz_full_movie_watch_online_in_hindi.pdf
- https://uploads.strikinglycdn.com/files/18fd3a71-2fe9-4b00-b161-d01eb3d3adde/sowojinagizewilusekufiduf.pdf
- https://static.s123-cdn-static-d.com/uploads/4450151/normal_60b294dfbd10c.pdf
- https://wodirukuz.weebly.com/uploads/1/3/5/3/135398055/ebc06ed4072b.pdf
- https://cdn-cms.f-static.net/uploads/4378171/normal_6033a16ad459f.pdf
- https://uploads.strikinglycdn.com/files/d20cbcaa-7f3a-4d3d-a915-cdaf7ce69c4b/pofawatazodadekon.pdf
- https://cdn-cms.f-static.net/uploads/4388183/normal_606eaa7e37ac5.pdf
- https://givurarole.weebly.com/uploads/1/3/4/5/134578012/dubibuzetoda.pdf
- https://uploads.strikinglycdn.com/files/f58bcc84-3e41-439d-ba33-ba0eb7455f0b/estudios_biblicos_para_jovenes.pdf
- https://uploads.strikinglycdn.com/files/23e877ba-28ac-4a81-9edb-9ba58ea4a0bc/xejejebi.pdf
- https://cdn-cms.f-static.net/uploads/4419640/normal_605d758b2165f.pdf
Embedded domains
- krisoc.ru
- uploads.strikinglycdn.com
- nusuwoxub.pbworks.com
- cdn-cms.f-static.net
- tutemedoz.weebly.com
- risuxujuvu.pbworks.com
- misamizejip.weebly.com
- kunixove.pbworks.com
- static.s123-cdn-static.com
- runaliguredu.pbworks.com
- static.s123-cdn-static-d.com
- wodirukuz.weebly.com
- givurarole.weebly.com
- nitogufufuwal.weebly.com
- zowonixepor.pbworks.com
- 9jarocks.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report