MALICIOUS — bfd78a_98cb88d9ae8042ec9c933fe79446df9b.pdf
MALICIOUS — bfd78a_98cb88d9ae8042ec9c933fe79446df9b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7f15b11a07fa04dd4e134543a9d971aefdbeddec1687cef89ed9f8b4aaf4a4bf - SHA-1:
7e40c93c5825e6679a14e393bea62bc0bf8b14ef - MD5:
e27070ca99956546b9868cacef45ace8 - ssdeep:
1536:cNQWW7tSevgWiktxQCBgDyHj98nGuCABZgmW2Nk+H5xJtys5GAT:mm7tH4ethyDm5SqKZOSdtysT - TLSH:
T13F38C0F330A7DE8CB68FAB53AAE3115D7047C38DB132AA745444B66C806C3AD7E60951 - Submitted as: bfd78a_98cb88d9ae8042ec9c933fe79446df9b.pdf
- File type: pdf · Size: 80578 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!E27070CA9995
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://6f465708-eb37-4ee2-8658-ebeec6cd93ea.filesusr.com/ugd/4bb103_51c7b0181d5f4c9fa57557b6464cd809.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://resalured.ru/wix?keyword=7+days+to+die+launch+options, https://6f465708-eb37-4ee2-8658-ebeec6cd93ea.filesusr.com/ugd/4bb103_51c7b0181d5f4c9fa57557b6464cd809.pdf?index=true, http://fedezin.scienceontheweb.net/97418953866.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://resalured.ru/wix?keyword=7+days+to+die+launch+options
- https://6f465708-eb37-4ee2-8658-ebeec6cd93ea.filesusr.com/ugd/4bb103_51c7b0181d5f4c9fa57557b6464cd809.pdf?index=true
- http://fedezin.scienceontheweb.net/97418953866.pdf
- https://94db4134-5784-44c5-a63d-963e509970fa.filesusr.com/ugd/9c58c5_590fa000553d4b90a64395d7c1001eda.pdf?index=true
- https://ddb0fe67-a09a-413d-b59a-c21b1dde3186.filesusr.com/ugd/3f0e57_8d82293ced6844579915ede76bfec855.pdf?index=true
- https://doguxugufini.weebly.com/uploads/1/3/0/7/130739878/bemijisamoroza_vimexoduka.pdf
- http://safijejog.mygamesonline.org/45509971127.pdf
- http://meletemobu.iblogger.org/51258372041.pdf
- https://4c72699b-aa2e-4dc8-8bd5-1a54e8f938a6.filesusr.com/ugd/f3cb45_96f850f2c56b450d8117d7f4be81caee.pdf?index=true
- http://lubevos.scienceontheweb.net/piwinedodivo.pdf
- https://8641c524-1fb5-4292-87ed-dd72f64d6c22.filesusr.com/ugd/9b7d8a_cb26c435765446179c2efe574e9350b7.pdf?index=true
- http://saroforati.medianewsonline.com/longman_photo_dictionary_free_download.pdf
- http://mojenisijita.mywebcommunity.org/nudupegebu.pdf
- http://pidawudimo.scienceontheweb.net/xezogoxepu.pdf
- http://kubenusuwixop.rf.gd/83592503301.pdf
- https://9e269ae7-c3cf-4b9f-bde2-1d9be064b7bf.filesusr.com/ugd/139869_d87f4d0884374a5386963ceee0b07c30.pdf?index=true
- http://siwupojotuj.getenjoyment.net/wulevodimubabagatozovutog.pdf
- https://pagowabelada.weebly.com/uploads/1/3/0/8/130874520/remujowefuxitel-bupegunotik-zimizivejezora.pdf
- https://taxufutusa.weebly.com/uploads/1/3/4/5/134514166/9a475cd44a6.pdf
- http://wororezijetixa.atwebpages.com/html_to_python_flask.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- resalured.ru
- 6f465708-eb37-4ee2-8658-ebeec6cd93ea.filesusr.com
- fedezin.scienceontheweb.net
- 94db4134-5784-44c5-a63d-963e509970fa.filesusr.com
- ddb0fe67-a09a-413d-b59a-c21b1dde3186.filesusr.com
- doguxugufini.weebly.com
- safijejog.mygamesonline.org
- meletemobu.iblogger.org
- 4c72699b-aa2e-4dc8-8bd5-1a54e8f938a6.filesusr.com
- lubevos.scienceontheweb.net
- 8641c524-1fb5-4292-87ed-dd72f64d6c22.filesusr.com
- saroforati.medianewsonline.com
- mojenisijita.mywebcommunity.org
- pidawudimo.scienceontheweb.net
- 9e269ae7-c3cf-4b9f-bde2-1d9be064b7bf.filesusr.com
- siwupojotuj.getenjoyment.net
- pagowabelada.weebly.com
- taxufutusa.weebly.com
- wororezijetixa.atwebpages.com
- www.w3.org
- purl.org
- ns.adobe.com
- kubenusuwixop.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report