MALICIOUS — 6ca3f6_7eec40df4ae44d259fc45e85b03f7801.pdf
MALICIOUS — 6ca3f6_7eec40df4ae44d259fc45e85b03f7801.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8f9b054c5a413e19bf31127b36c3a7d79fc2c780e8c5b290b2d7654287b18639 - SHA-1:
388f6448ab81e506ec82349b9bc7cda296c50e30 - MD5:
d8855a6d1c62513267807db7eb180bb1 - ssdeep:
1536:YgI6SrCZnb3GHZVXIdtbQdbJDPZbzyMki2V4ntXCIi71wg88QlNbL+TwZ:1SmVb3GHXI8txRberLV4nUH6g88QlNbT - TLSH:
T15238D1F37197ED4CBE9A9B53B5EF305C6045D28C2126DA60448CBA2DC4BC7AE7E24510 - Submitted as: 6ca3f6_7eec40df4ae44d259fc45e85b03f7801.pdf
- File type: pdf · Size: 81938 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D8855A6D1C62
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://4541bc1c-e35c-4de3-bb44-1f53c3e1a56d.filesusr.com/ugd/68f66e_09c31e70ffaf411ba0b3e4d286fc77cc.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://xajibur.ru/wix?keyword=runescape+giant+mole+guide, https://4541bc1c-e35c-4de3-bb44-1f53c3e1a56d.filesusr.com/ugd/68f66e_09c31e70ffaf411ba0b3e4d286fc77cc.pdf?index=true, https://7084e6a0-ac83-435c-bfb8-dc9616ff97fd.filesusr.com/ugd/c068f8_f6d956d0202b49d9a33091e912ee8bba.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://xajibur.ru/wix?keyword=runescape+giant+mole+guide
- https://4541bc1c-e35c-4de3-bb44-1f53c3e1a56d.filesusr.com/ugd/68f66e_09c31e70ffaf411ba0b3e4d286fc77cc.pdf?index=true
- https://7084e6a0-ac83-435c-bfb8-dc9616ff97fd.filesusr.com/ugd/c068f8_f6d956d0202b49d9a33091e912ee8bba.pdf?index=true
- https://cdn.sqhk.co/xevowuto/9VBaXgh/82849793158.pdf
- https://uploads.strikinglycdn.com/files/37ac3b69-4c55-49d5-8010-bcbee26c12f7/should_covid_be_capitalized_mla.pdf
- https://557345b1-98c6-442d-b460-9e357c178e5b.filesusr.com/ugd/dfb5f8_46e0d69c7123455f986cacc3f11f0ec6.pdf?index=true
- https://f11c4bf2-12a6-49f8-9590-07a94b689168.filesusr.com/ugd/11276f_cb55fb0934824ad39c5551103808c5cc.pdf?index=true
- https://748e62c5-a849-4dff-87e7-3b5f74cb3522.filesusr.com/ugd/0df896_aba0b506aad644d48905b2280f22a0bf.pdf?index=true
- http://foxiduwanati.mygamesonline.org/toro_60v_trimmer_string_replacement.pdf
- https://cdn.sqhk.co/bitaxukezor/hgfKAhh/77652987930.pdf
- https://uploads.strikinglycdn.com/files/0a7e2dc7-0eaa-40da-b1fc-4d4a471873a1/how_many_section_in_negotiable_instrument_act.pdf
- http://woziwowariv.sportsontheweb.net/91939990949.pdf
- https://29aa9d28-cc9d-45fc-8d86-3718b5881c84.filesusr.com/ugd/74c34a_a8002477789b42769e0740bf9104d09b.pdf?index=true
- https://3f054cde-0430-4828-89d0-5f77035cf230.filesusr.com/ugd/d93890_eb20ca004b7a4c6fa846013360c9f46a.pdf?index=true
- https://dc273c12-e125-4738-b2e6-b96bc4bd5eb7.filesusr.com/ugd/c8df25_8388eb98d9c040899aa4b3a599e9d91e.pdf?index=true
- https://cdn.sqhk.co/kadeposamo/PHWQgg6/free_basic_computer_skills_for_seniors.pdf
- https://cdn.sqhk.co/levowexesu/phi6Yic/velodrome_track_day.pdf
- http://tuparibuju.atwebpages.com/10697076839.pdf
- https://178c1879-e916-404b-9861-a2431bd0f83a.filesusr.com/ugd/1aace6_2926a420980948c09462dd80f112408c.pdf?index=true
- http://bidetoluji.getenjoyment.net/kevasununiwejanorobukal.pdf
- https://uploads.strikinglycdn.com/files/3d2f972a-7d17-4d80-8dc8-32cc4a9c20f9/34159966385.pdf
- https://cdn.sqhk.co/fowijuseziju/l8gjchc/cbs_app_directv_login.pdf
- http://rogijowop.sportsontheweb.net/11th_std_botany_practical_book.pdf
- https://cdn.sqhk.co/susiwozobo/igihgVk/92145000019.pdf
- https://636e06b3-920c-4898-b827-ef778bbbc101.filesusr.com/ugd/40512e_b14614ae8e484bcdb858f60dcd41fd0f.pdf?index=true
Embedded domains
- xajibur.ru
- 4541bc1c-e35c-4de3-bb44-1f53c3e1a56d.filesusr.com
- 7084e6a0-ac83-435c-bfb8-dc9616ff97fd.filesusr.com
- cdn.sqhk.co
- uploads.strikinglycdn.com
- 557345b1-98c6-442d-b460-9e357c178e5b.filesusr.com
- f11c4bf2-12a6-49f8-9590-07a94b689168.filesusr.com
- 748e62c5-a849-4dff-87e7-3b5f74cb3522.filesusr.com
- foxiduwanati.mygamesonline.org
- woziwowariv.sportsontheweb.net
- 29aa9d28-cc9d-45fc-8d86-3718b5881c84.filesusr.com
- 3f054cde-0430-4828-89d0-5f77035cf230.filesusr.com
- dc273c12-e125-4738-b2e6-b96bc4bd5eb7.filesusr.com
- tuparibuju.atwebpages.com
- 178c1879-e916-404b-9861-a2431bd0f83a.filesusr.com
- bidetoluji.getenjoyment.net
- rogijowop.sportsontheweb.net
- 636e06b3-920c-4898-b827-ef778bbbc101.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report