MALICIOUS — 8dde66_2d22398d84a443f7b06e1366d5e8bc37.pdf
MALICIOUS — 8dde66_2d22398d84a443f7b06e1366d5e8bc37.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
73be15373d24ebe3db61c4876ff88cfc053fa1637df0498642d71cdbe2a7b97d - SHA-1:
b42b895421dfcb0aeb4880597b9fd49c4b2cf76b - MD5:
032178e2a4190918f05a507766905025 - ssdeep:
1536:HZw51pYtOGyjn5dfUKf3PPGq5DW7gmIaHDCOuB1paC9vcpqXWh:abFDn5dV3Gq5iUmFCOuB1paAcpqI - TLSH:
T10738CFF3B193DE8C6A5E9F47B9AA119C558DA344623297E404C8B73CC47C1BE7D20960 - Submitted as: 8dde66_2d22398d84a443f7b06e1366d5e8bc37.pdf
- File type: pdf · Size: 80649 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!032178E2A419
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://87c8fc71-818b-4167-bf0d-2ac3bc49ffd1.filesusr.com/ugd/f9d4cd_f32febf3afbc4fb3bfc4b208f440a598.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://xezojetit.ru/wix?keyword=nervous+tissue+structure+and+function+worksheet, https://uploads.strikinglycdn.com/files/ec40b261-e398-49d0-afe8-ead316128440/asus_maximus_viii_hero_memory_compatibility_list.pdf, https://uploads.strikinglycdn.com/files/ad7d6aa9-dbd9-49ea-91be-7632c0016a9f/gufegejine.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://xezojetit.ru/wix?keyword=nervous+tissue+structure+and+function+worksheet
- https://uploads.strikinglycdn.com/files/ec40b261-e398-49d0-afe8-ead316128440/asus_maximus_viii_hero_memory_compatibility_list.pdf
- https://uploads.strikinglycdn.com/files/ad7d6aa9-dbd9-49ea-91be-7632c0016a9f/gufegejine.pdf
- https://uploads.strikinglycdn.com/files/7e80d26d-4ed9-4e74-86a6-c0d2515682d2/duzedezatojukunu.pdf
- https://uploads.strikinglycdn.com/files/2e65b96c-dbd1-4b94-a667-a3d22befaa3e/lifadusunoraburonetar.pdf
- https://uploads.strikinglycdn.com/files/7bc2eb4b-e767-45c9-b039-b2b76752c558/xoxalam.pdf
- https://uploads.strikinglycdn.com/files/285280dd-baee-4272-91d7-ab75726720f7/wetubesuxal.pdf
- https://uploads.strikinglycdn.com/files/5cf08c80-bc91-4eb5-9b4e-d1a88b883b95/where_can_i_rent_a_good_metal_detector.pdf
- https://s3.amazonaws.com/gedimuta/telecommuting_agreement_template.pdf
- https://87c8fc71-818b-4167-bf0d-2ac3bc49ffd1.filesusr.com/ugd/f9d4cd_f32febf3afbc4fb3bfc4b208f440a598.pdf?index=true
- https://f5d5bca3-0ffd-41e3-a77d-3d805a1e43e5.filesusr.com/ugd/4e23ca_a5fc26feb9c74c118d2572b0e950b8b0.pdf?index=true
- https://78e27e65-9996-4239-a63d-7a21722db537.filesusr.com/ugd/03f576_9ead9ccdeb1944eca9589929a9bc92ba.pdf?index=true
- https://uploads.strikinglycdn.com/files/3f5150f4-7922-4b32-b17b-75a238a35074/feken.pdf
- https://cdn.sqhk.co/vabalogu/iaGgfgd/voltage_drop_across_resistors_in_series.pdf
- https://cdn.sqhk.co/daborofus/a02ghZC/cake_decorating_supplies.pdf
- https://s3.amazonaws.com/jirebonudur/denatuwogibozafexetuvofo.pdf
- https://liletalezawo.weebly.com/uploads/1/3/4/5/134591830/faa443.pdf
- https://cdn.sqhk.co/ruvonusebex/wjbbPgH/zidaxonabidoxi.pdf
- https://uploads.strikinglycdn.com/files/200b82aa-092a-47e4-a181-2015f34be4b3/dictionary_of_literary_terms_by_martin_gray_free_download.pdf
- https://uploads.strikinglycdn.com/files/0be4b65c-74a5-47ba-ae44-d37dcc5621bf/chess_puzzles_lichess.pdf
- https://cdn.sqhk.co/kuzetuzame/HijAihR/good_practice_guidelines_fur_business_continuity_management_deutsch.pdf
- https://tidekomix.weebly.com/uploads/1/3/4/4/134441433/benojisa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- xezojetit.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- 87c8fc71-818b-4167-bf0d-2ac3bc49ffd1.filesusr.com
- f5d5bca3-0ffd-41e3-a77d-3d805a1e43e5.filesusr.com
- 78e27e65-9996-4239-a63d-7a21722db537.filesusr.com
- cdn.sqhk.co
- liletalezawo.weebly.com
- tidekomix.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report