MALICIOUS — 2385548.pdf
MALICIOUS — 2385548.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a4311db807d6faeb840cbb432db4d857776b818bcfa16c3771b5d15f4faa0bab - SHA-1:
f8b2c6ef174c7719b84706d1afee089ddae3b83d - MD5:
f6e4e4a1b3df664d1a9f7a2c31cced74 - ssdeep:
1536:iecg5uNOO4G4dzC80LSwyP9VQHOu/QaZy4UtlS3q34nkNx:CgQNOO78+SwyP/Q1Q6y4Utlf+U - TLSH:
T17D38D0F3609FDD5C2B8F6F5379AA066930CD938972335B211588772E807C1AD7E20962 - Submitted as: 2385548.pdf
- File type: pdf · Size: 81674 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F6E4E4A1B3DF
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://356bbf58-84af-4bff-99a9-d03346e46411.filesusr.com/ugd/b5472a_31d3908cd43644ce90455c3ba8015c96.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://zajinet.ru/wb?keyword=what%20disease%20does%20stephen%20hawking%20have, https://uploads.strikinglycdn.com/files/17b8e3c6-f63b-4ab1-804e-9b0cf148a5b3/79506828529.pdf, https://uploads.strikinglycdn.com/files/ccbc2aed-fa4b-465f-9146-49d6de52bdcd/can_i_go_shooting_without_a_license.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://zajinet.ru/wb?keyword=what%20disease%20does%20stephen%20hawking%20have
- https://uploads.strikinglycdn.com/files/17b8e3c6-f63b-4ab1-804e-9b0cf148a5b3/79506828529.pdf
- https://uploads.strikinglycdn.com/files/ccbc2aed-fa4b-465f-9146-49d6de52bdcd/can_i_go_shooting_without_a_license.pdf
- http://rajixubododafu.epizy.com/converting_decimal_degrees_to_dms_worksheet.pdf
- http://kusugafunerepo.rf.gd/kufek.pdf
- https://356bbf58-84af-4bff-99a9-d03346e46411.filesusr.com/ugd/b5472a_31d3908cd43644ce90455c3ba8015c96.pdf?index=true
- https://uploads.strikinglycdn.com/files/c9f374a2-2185-439f-aa98-b9c1efe17bc3/49190702904.pdf
- http://fitimulosegi.epizy.com/attestation_fin_de_formation_professionnelle_continue.pdf
- http://udilische.club/28604414348p6u5h.pdf
- https://zotagozugub.weebly.com/uploads/1/3/0/7/130739891/4287360.pdf
- http://xinaxidupazuso.iblogger.org/kabbalistic_astrology_and_the_meaning_of_our_lives.pdf
- http://roxeruteruda.epizy.com/zigevilorak.pdf
- http://datab.vip/how_much_is_tuition_at_our_lady_of_the_lakeftxx0.pdf
- http://gagezejiwakale.iblogger.org/gidodumofajogonosavuti.pdf
- https://5c2df1de-05ea-4e17-9aa3-38adc7ce3153.filesusr.com/ugd/ddd609_d18700e6347f4af797682a1fb183dc2b.pdf?index=true
- https://zuwukozoxuwiged.weebly.com/uploads/1/3/4/7/134713444/foruxubuki_wavep_gunusupij.pdf
- https://fevuxutub.weebly.com/uploads/1/3/4/1/134131759/5938687.pdf
- https://xonalofogikovor.weebly.com/uploads/1/3/4/3/134372302/6364745.pdf
- http://natbeach.space/47058404474fynmj.pdf
- https://valezofijamope.weebly.com/uploads/1/3/4/4/134445284/8113242.pdf
- https://uploads.strikinglycdn.com/files/2ee2fdcd-d3ed-4c19-9c53-b900296c76f9/lactancia_materna_posiciones.pdf
- https://3e1af3dc-cf37-4f58-935d-0a6065bc5ce9.filesusr.com/ugd/3ca236_67d2e784f1014e99a646f0bb9e95ada4.pdf?index=true
- http://kekomoxigidagug.iblogger.org/xopuxevolufexabumononik.pdf
- https://edb7bb8d-792a-4213-93ec-7f573d37cc74.filesusr.com/ugd/bfd504_0e7d4a562af14c32ac535e96b39f7d94.pdf?index=true
- https://6b137298-3864-41c5-aaa3-11744000c3c2.filesusr.com/ugd/b916f4_bb00273226754d56b3fcaed1daf4bc27.pdf?index=true
Embedded domains
- zajinet.ru
- uploads.strikinglycdn.com
- rajixubododafu.epizy.com
- 356bbf58-84af-4bff-99a9-d03346e46411.filesusr.com
- fitimulosegi.epizy.com
- udilische.club
- zotagozugub.weebly.com
- xinaxidupazuso.iblogger.org
- roxeruteruda.epizy.com
- datab.vip
- gagezejiwakale.iblogger.org
- 5c2df1de-05ea-4e17-9aa3-38adc7ce3153.filesusr.com
- zuwukozoxuwiged.weebly.com
- fevuxutub.weebly.com
- xonalofogikovor.weebly.com
- natbeach.space
- valezofijamope.weebly.com
- 3e1af3dc-cf37-4f58-935d-0a6065bc5ce9.filesusr.com
- kekomoxigidagug.iblogger.org
- edb7bb8d-792a-4213-93ec-7f573d37cc74.filesusr.com
- 6b137298-3864-41c5-aaa3-11744000c3c2.filesusr.com
- kvyovk.xyz
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report