MALICIOUS — 83f66e75ebf4973cb481f6853ab68a764b7b65823638add71db92da16547394a
MALICIOUS — 83f66e75ebf4973cb481f6853ab68a764b7b65823638add71db92da16547394a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
83f66e75ebf4973cb481f6853ab68a764b7b65823638add71db92da16547394a - SHA-1:
4bc9ec6d861d0e6419f3628d559a7af577373767 - MD5:
d8cc56f7c7ec0c63ea05ffce801c79c1 - ssdeep:
1536:RxU82b5BX01eDwbf2bouFmLZn2zDaDET4RtKh7E7J+/AhGr:sx6es72bnsnYmDEkRtKhIJ+4U - TLSH:
T12838DFF31197FC4C7AD7AB036DA35568548CE2982173DB5064C8732CC96CAAEBD60B90 - Submitted as: 83f66e75ebf4973cb481f6853ab68a764b7b65823638add71db92da16547394a
- File type: pdf · Size: 77222 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D8CC56F7C7EC
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4366000/normal_60038f339db46.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://dugedepap.ru/strik?utm_term=sap+inbound+delivery+type+determination, https://static.s123-cdn-static.com/uploads/4366000/normal_60038f339db46.pdf, https://uploads.strikinglycdn.com/files/37738444-1007-4ce8-bbc9-9637d0f9c3fb/figufozopotepudi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://dugedepap.ru/strik?utm_term=sap+inbound+delivery+type+determination
- https://static.s123-cdn-static.com/uploads/4366000/normal_60038f339db46.pdf
- https://uploads.strikinglycdn.com/files/37738444-1007-4ce8-bbc9-9637d0f9c3fb/figufozopotepudi.pdf
- http://limirosu.rf.gd/comparative_superlative_exercise.pdf
- http://usacreditmonitoring.info/webogufewenobibamoboli4vakm.pdf
- https://static.s123-cdn-static.com/uploads/4452863/normal_5fe30bf688449.pdf
- https://cdn-cms.f-static.net/uploads/4473340/normal_604f92dae0dee.pdf
- https://uploads.strikinglycdn.com/files/aff801b1-6b58-4133-9d93-81d774295bd7/the_hunger_games_catching_fire_full_movie_free_online_123.pdf
- https://uploads.strikinglycdn.com/files/58e60f86-389d-4dd6-b5c7-a30607c4b750/3534368200.pdf
- http://samettemiz.xyz/18332402667yi44r.pdf
- http://rentline.pro/fixawiko46vrz.pdf
- http://lnstagram-blue-ticks.com/58963813241o3sa0.pdf
- https://cdn-cms.f-static.net/uploads/4368752/normal_6058bef054907.pdf
- https://uploads.strikinglycdn.com/files/a26124e3-67a7-4e40-bd06-bbd7af4b2900/trimet_bus_48_schedule_sunday.pdf
- http://worakozun.22web.org/jejixexasuwodux.pdf
- http://dopovis.myartsonline.com/english_file_beginner_teacher_s_book.pdf
- https://uploads.strikinglycdn.com/files/134ee89e-2393-48dc-a661-af7105499ce4/63148082825.pdf
- http://lesuxofozadize.mygamesonline.org/missing_411_ebook.pdf
- http://nakanilo.club/manette_wii_ne_s_allume_plusphqu1.pdf
- http://bijowuxupolapi.sportsontheweb.net/7626548371.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- dugedepap.ru
- static.s123-cdn-static.com
- uploads.strikinglycdn.com
- usacreditmonitoring.info
- cdn-cms.f-static.net
- samettemiz.xyz
- rentline.pro
- lnstagram-blue-ticks.com
- worakozun.22web.org
- dopovis.myartsonline.com
- lesuxofozadize.mygamesonline.org
- nakanilo.club
- bijowuxupolapi.sportsontheweb.net
- www.w3.org
- purl.org
- ns.adobe.com
- limirosu.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report