MALICIOUS — normal_6056047c135fb.pdf
MALICIOUS — normal_6056047c135fb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8f8382332950f1c2291c46877f7ec7f796046c1c899257b184d7641d1140ed48 - SHA-1:
4f2aa9f869b461274339cef3e06f3adb3527456e - MD5:
2e51588df8a2c2bad8e7fe3716627e54 - ssdeep:
1536:OzdOfRivEe76oVg3maiE37GdAUg8JcjcmV5Rhg5X:aIcN68dTE3K5TJcjJV5Rh+ - TLSH:
T11E38D0F36057CE4F7D839B13BAE2509D6189CBCA61256BA0088CB73C85BC1BDBE14561 - Submitted as: normal_6056047c135fb.pdf
- File type: pdf · Size: 79279 bytes
- Verdict: malicious (75/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!2E51588DF8A2
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/56f60a9f-5abd-4010-a225-c191ab7b61e3/power_cooker_instruction_guide.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://yafferge.ru/123?utm_term=balloon+tower+defense+6+free, https://e148473a-3d1a-46f8-b788-fbc1f5af68d4.filesusr.com/ugd/e1e70b_5c2338b4eead41609105f9f32e831d65.pdf?index=true, https://loponulofaxoli.weebly.com/uploads/1/3/4/3/134324484/bozizagus_juxopemowa_tetasopabo_babewo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://yafferge.ru/123?utm_term=balloon+tower+defense+6+free
- https://e148473a-3d1a-46f8-b788-fbc1f5af68d4.filesusr.com/ugd/e1e70b_5c2338b4eead41609105f9f32e831d65.pdf?index=true
- https://loponulofaxoli.weebly.com/uploads/1/3/4/3/134324484/bozizagus_juxopemowa_tetasopabo_babewo.pdf
- https://s3.amazonaws.com/voxazedisula/carrom_game_rules.pdf
- https://uploads.strikinglycdn.com/files/56f60a9f-5abd-4010-a225-c191ab7b61e3/power_cooker_instruction_guide.pdf
- https://gawudizilox.weebly.com/uploads/1/3/5/3/135300959/b247b5.pdf
- http://esportzmlevent.com/kosusebasupigulotqlv3w.pdf
- https://s3.amazonaws.com/kakekojezutok/antivirus_software_free_for_windows.pdf
- https://s3.amazonaws.com/pusori/kikubigapiwapetisepoti.pdf
- http://sutekotuluzuwed.rf.gd/lds_primary_birthday_gift_ideas_2021.pdf
- https://s3.amazonaws.com/sobaketemu/83750215450.pdf
- http://robefixelajimod.22web.org/jajugutadelubaveg.pdf
- https://uploads.strikinglycdn.com/files/3a3159eb-2922-4160-841d-11942a27513a/levujexer.pdf
- https://uploads.strikinglycdn.com/files/6cd4e2ce-c903-4523-b870-8476737139f6/cooks_essentials_electric_pressure_cooker_instruction_manual.pdf
- http://bamisuk.rf.gd/valkyrie_movie_english_subtitles_free.pdf
- https://s3.amazonaws.com/sobaketemu/como_comprimir_un_archivo_winrar_zip.pdf
- https://uploads.strikinglycdn.com/files/e1e27987-9d40-4872-bea8-172ae6f83662/ford_explorer_sport_trac_2002_specs.pdf
- http://iclod.tech/367550377792jtt3.pdf
- https://d064ede3-316f-4d13-8ec5-014b2136b3bd.filesusr.com/ugd/154db6_3f4416b0dc9c4966b8e9a5ee6cbe6e80.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- yafferge.ru
- e148473a-3d1a-46f8-b788-fbc1f5af68d4.filesusr.com
- loponulofaxoli.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- gawudizilox.weebly.com
- esportzmlevent.com
- robefixelajimod.22web.org
- iclod.tech
- d064ede3-316f-4d13-8ec5-014b2136b3bd.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- sutekotuluzuwed.rf.gd
- bamisuk.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report