MALICIOUS — 8b97dd_a48367aa31b44f01837000b22f3d586e.pdf
MALICIOUS — 8b97dd_a48367aa31b44f01837000b22f3d586e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9d1dc8171eea1a96006989845cb2e565229b5ab788d2ed0d0f1a3230d90ccd0d - SHA-1:
b55e7c542d1bd09da415cc55fc5b61c5f1e53002 - MD5:
99b743209caae89f20f483184210fffc - ssdeep:
1536:Lvn5W7oqqKF4epByjkRZd9d2IvIJZu7Ytdx13avlnJr6P/InWOjU:T5W7oqqzeOQfvUIvI3u7EJKpJr6PQnWL - TLSH:
T1F938E0F7505BDD8CF9C9AF03ADF3615CA58DC68EA122DA64088D762CC5786DD3C10A60 - Submitted as: 8b97dd_a48367aa31b44f01837000b22f3d586e.pdf
- File type: pdf · Size: 80238 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!99B743209CAA
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://e85625e8-91d5-48c2-95a4-67b7b95d5b39.filesusr.com/ugd/b97a97_a2352033aee04ea2afb2c114769e798c.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://zajinet.ru/wix?keyword=sohcahtoa+word+problems+hw+answer+key, https://e85625e8-91d5-48c2-95a4-67b7b95d5b39.filesusr.com/ugd/b97a97_a2352033aee04ea2afb2c114769e798c.pdf?index=true, http://rumagadoli.22web.org/happy_birthday_love_gif.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://zajinet.ru/wix?keyword=sohcahtoa+word+problems+hw+answer+key
- https://e85625e8-91d5-48c2-95a4-67b7b95d5b39.filesusr.com/ugd/b97a97_a2352033aee04ea2afb2c114769e798c.pdf?index=true
- http://rumagadoli.22web.org/happy_birthday_love_gif.pdf
- http://wokulorumal.iblogger.org/xesivivegimajidajelikerij.pdf
- https://9d50af6f-dbf7-41ba-b854-83985329a12b.filesusr.com/ugd/33c377_a113a44f7c094da2955ba868e005183f.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4454671/normal_603135f16770a.pdf
- http://fawixixajij.rf.gd/manual_de_hatha_yoga_108_asanas.pdf
- https://cdn-cms.f-static.net/uploads/4424637/normal_5fd0e553b8a70.pdf
- https://madugonado.weebly.com/uploads/1/3/2/8/132815119/9283079.pdf
- https://51956041-da35-40aa-96c1-085c1f47c80d.filesusr.com/ugd/e6e573_c3b87a3dd76841fc9ec2c13e79b56105.pdf?index=true
- https://dekukosozo.weebly.com/uploads/1/3/1/0/131070054/tiwoxi_vagozuvoweku_makusuxub_sukikoxogat.pdf
- https://rilumawireg.weebly.com/uploads/1/3/5/9/135981263/maragozu_fowik.pdf
- https://a35aa970-3e4e-4c20-be1f-53d10001bce9.filesusr.com/ugd/af4e73_c6c6eb58458c4a7181bb8efd88646df7.pdf?index=true
- https://a1d1c4ac-cf1d-4c58-861c-45d1188f4b60.filesusr.com/ugd/052f3a_3fb11431b4894e779cf2a0dff1108a30.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4370304/normal_5ff692cb28240.pdf
- https://surapurefolax.weebly.com/uploads/1/3/5/3/135327325/gisipo_babigamod_japufewo_tuxiraraw.pdf
- https://bdee3e82-1fe6-4084-b289-f15f5249f83e.filesusr.com/ugd/749937_2c0284e4295441f4911ddb3d820c832f.pdf?index=true
- https://kavanezeso.weebly.com/uploads/1/3/4/4/134477356/152333a11e33.pdf
- http://vusedew.myartsonline.com/counting_numbers_worksheets_for_kindergarten.pdf
- http://lipexifinidoda.scienceontheweb.net/atresia_pulmonar_con_septum_intacto.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- zajinet.ru
- e85625e8-91d5-48c2-95a4-67b7b95d5b39.filesusr.com
- rumagadoli.22web.org
- wokulorumal.iblogger.org
- 9d50af6f-dbf7-41ba-b854-83985329a12b.filesusr.com
- cdn-cms.f-static.net
- madugonado.weebly.com
- 51956041-da35-40aa-96c1-085c1f47c80d.filesusr.com
- dekukosozo.weebly.com
- rilumawireg.weebly.com
- a35aa970-3e4e-4c20-be1f-53d10001bce9.filesusr.com
- a1d1c4ac-cf1d-4c58-861c-45d1188f4b60.filesusr.com
- static.s123-cdn-static.com
- surapurefolax.weebly.com
- bdee3e82-1fe6-4084-b289-f15f5249f83e.filesusr.com
- kavanezeso.weebly.com
- vusedew.myartsonline.com
- lipexifinidoda.scienceontheweb.net
- www.w3.org
- purl.org
- ns.adobe.com
- fawixixajij.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report