MALICIOUS — 42c189_7d6ac8efa5a34de8a8bdc1cb4a199d90.pdf
MALICIOUS — 42c189_7d6ac8efa5a34de8a8bdc1cb4a199d90.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a13502f8154551f3530256cf7ab86f3fdc54d5e8474e750559633f0d7359ed74 - SHA-1:
1d05d012bd3a9ebdb2c3314b72964a564e6ab750 - MD5:
45be43e7474e00be30e57ffc3ab41139 - ssdeep:
1536:7RM0jgJ9yPInuTXH0uNMcsbJ2kuy9gYAjPt6dM+hl/F4Qt1Oi+y7UOLkcMSZ:F09yPInWXUuNLNkuE61PY/FH9oOwct - TLSH:
T10238CFF31157EE8CB7866B43BABB221E7559E3882037D7A14488372CC8BC5AD7C10951 - Submitted as: 42c189_7d6ac8efa5a34de8a8bdc1cb4a199d90.pdf
- File type: pdf · Size: 78065 bytes
- Verdict: malicious (99/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!45BE43E7474E
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/b7da7751-154e-4721-b98a-c70c3acf4ac1/josimevafezavop.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!45BE43E7474E (rule
PDF/Phish-FAB!45BE43E7474E) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://vilenefex.ru/wix?keyword=skyrim+old+hroldan+inn+map+location, https://xijiruxexewige.weebly.com/uploads/1/3/4/7/134725886/9095081.pdf, http://handler-autoscout24.com/excel_vba_online_tutorial_freevphpq.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://vilenefex.ru/wix?keyword=skyrim+old+hroldan+inn+map+location
- https://xijiruxexewige.weebly.com/uploads/1/3/4/7/134725886/9095081.pdf
- http://handler-autoscout24.com/excel_vba_online_tutorial_freevphpq.pdf
- http://pochta-24.cc/lowrance_elite_3x_dsi_installationpdxcn.pdf
- https://cdn.sqhk.co/jotepomi/Jjajcxk/truck_racing_driver_truck_simulator.pdf
- https://kenazago.weebly.com/uploads/1/3/1/0/131070597/90d615803fafd.pdf
- http://givetupazowo.onlinewebshop.net/why_dont_i_have_empathy_anymore.pdf
- https://cdn-cms.f-static.net/uploads/4408172/normal_603d91772a1d8.pdf
- https://cdn.sqhk.co/rowubuvuke/LijJH99/can_chiari_1_malformation_be_cured.pdf
- https://uploads.strikinglycdn.com/files/b7da7751-154e-4721-b98a-c70c3acf4ac1/josimevafezavop.pdf
- https://uploads.strikinglycdn.com/files/26b4ed0d-eaea-440c-a6dd-eab5f5d44419/19814221353.pdf
- http://123dutch.com/gesukb2lmx.pdf
- http://niwadeg.mywebcommunity.org/53632471043.pdf
- https://cdn.sqhk.co/guvevifowo/ciIjihj/if_i_die_don_t_cry_quotes.pdf
- https://cdn-cms.f-static.net/uploads/4446401/normal_5fd1d369dad24.pdf
- https://uploads.strikinglycdn.com/files/45dc83fd-6155-4d79-bb50-8d6a78d13557/nonifuxefinizakubeg.pdf
- http://dazejifudora.onlinewebshop.net/geologic_time_scale.pdf
- https://cdn.sqhk.co/buganisazobu/ds7kvja/71081371201.pdf
- https://cdn.sqhk.co/numovasovev/ahhYn5H/download_star_forces_space_shooter.pdf
- https://risegexof.weebly.com/uploads/1/3/4/6/134661868/selurunamefunigike.pdf
- http://tafiwon.mywebcommunity.org/vmware_vsphere_interview_questions_and_answers.pdf
- https://uploads.strikinglycdn.com/files/e75a7e42-d238-47d8-b958-dec2a005582f/what_do_you_plant_beets_in.pdf
- https://cdn-cms.f-static.net/uploads/4469106/normal_60116518896d7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- vilenefex.ru
- xijiruxexewige.weebly.com
- handler-autoscout24.com
- pochta-24.cc
- cdn.sqhk.co
- kenazago.weebly.com
- givetupazowo.onlinewebshop.net
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- 123dutch.com
- niwadeg.mywebcommunity.org
- dazejifudora.onlinewebshop.net
- risegexof.weebly.com
- tafiwon.mywebcommunity.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report