MALICIOUS — 66c92f7f98b51.pdf
MALICIOUS — 66c92f7f98b51.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7319a3e68329c8ff9040edc5cc8573063b07de9e98323f6eb5f20ce557236807 - SHA-1:
25fba22102a2e164748db5992c17fb2e8319f7c5 - MD5:
12dc7437d0e352aad9e674338c230842 - ssdeep:
1536:zYQUzdZzqJ0APjIovGU0/uEWGOpIxtq+/yRwgdcJN5UEBZt/4+VFMI:wzvm9qAn8tq6owgdcJN5ZQ+Vl - TLSH:
T1C738D0F33093ED4CBB4FAB177A9B24AE5485E79454369BD41088763CC4BC6BE6D00622 - Submitted as: 66c92f7f98b51.pdf
- File type: pdf · Size: 79458 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!12DC7437D0E3
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4473030/normal_5ff30ba4578ce.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://adea4596-07c4-4c45-ba97-107779ed6dc5.filesusr.com/ugd/5bd9e2_b8a0ab348ded42ecaf6e1294ac619f92.pdf?index=true, https://jegivobepumo.weebly.com/uploads/1/3/4/4/134444156/5a56b075e60.pdf, https://zusikoxapumobib.weebly.com/uploads/1/3/4/7/134766975/be0f88b9c8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/4NO0L8wlyOA/wb?keyword=pantum%20p2500w%20wireless%20setup
- https://s3.amazonaws.com/sefepugolupalax/37828943491.pdf
- https://adea4596-07c4-4c45-ba97-107779ed6dc5.filesusr.com/ugd/5bd9e2_b8a0ab348ded42ecaf6e1294ac619f92.pdf?index=true
- https://s3.amazonaws.com/wivunonovef/beetroot_cell_membrane_permeability_experiment_lab_report.pdf
- https://jegivobepumo.weebly.com/uploads/1/3/4/4/134444156/5a56b075e60.pdf
- https://s3.amazonaws.com/tajimipojimo/3973526451.pdf
- https://zusikoxapumobib.weebly.com/uploads/1/3/4/7/134766975/be0f88b9c8.pdf
- http://femejedad.epizy.com/73873600321.pdf
- https://6c036dbd-b327-4678-b778-de8a2ee7bb50.filesusr.com/ugd/ed64d2_351170b0743b4ffd8054fd0f76e729c6.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4473030/normal_5ff30ba4578ce.pdf
- https://s3.amazonaws.com/petikamov/bts_butterfly_mv_mp4_free.pdf
- https://static.s123-cdn-static.com/uploads/4409420/normal_5fe07cae93f77.pdf
- https://static.s123-cdn-static.com/uploads/4492253/normal_5fe3fcfc5a7a4.pdf
- https://nodekisoguzila.weebly.com/uploads/1/3/5/3/135313862/358ff73e4cd28.pdf
- https://depopuxa.weebly.com/uploads/1/3/4/8/134893869/jijidubisixumas.pdf
- http://kemawugaputawa.rf.gd/business_vocabulary_builder_paul_emmerson.pdf
- https://s3.amazonaws.com/tinezedu/36799340571.pdf
- http://sexupoweduf.epizy.com/15625624023.pdf
- https://vokuduvalabi.weebly.com/uploads/1/3/4/5/134502282/tapumolajutuf_raxamotasazu_nisebugakefiru_sasolera.pdf
- https://cdn-cms.f-static.net/uploads/4409396/normal_6057e5c464e07.pdf
- https://vasinurevesodux.weebly.com/uploads/1/3/4/6/134605286/4771330.pdf
- https://cdn-cms.f-static.net/uploads/4453118/normal_6039f90b99988.pdf
- https://vesedosaripiwuj.weebly.com/uploads/1/3/1/6/131636692/4669046.pdf
- http://fewaxizix.iblogger.org/76430456350.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- s3.amazonaws.com
- adea4596-07c4-4c45-ba97-107779ed6dc5.filesusr.com
- jegivobepumo.weebly.com
- zusikoxapumobib.weebly.com
- femejedad.epizy.com
- 6c036dbd-b327-4678-b778-de8a2ee7bb50.filesusr.com
- static.s123-cdn-static.com
- nodekisoguzila.weebly.com
- depopuxa.weebly.com
- sexupoweduf.epizy.com
- vokuduvalabi.weebly.com
- cdn-cms.f-static.net
- vasinurevesodux.weebly.com
- vesedosaripiwuj.weebly.com
- fewaxizix.iblogger.org
- www.w3.org
- purl.org
- ns.adobe.com
- kemawugaputawa.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report