MALICIOUS — 26481d_631957d41be748edad4a4389de5f9f9b.pdf
MALICIOUS — 26481d_631957d41be748edad4a4389de5f9f9b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a515495714d95eea6f793f036b250f8e52930760a9421feacdffb6aab1e1f6d2 - SHA-1:
bfee92903dd8f576ee2f5d8c85f078b87062d22a - MD5:
867a72be4734ce69682decb08cbe4c11 - ssdeep:
1536:X2iXglI1nLsEB2Q5RyGpxxhvoZ5nTn82QSLCm3v3C:dVnL1B2QjyoE3Tn8vSLCm3K - TLSH:
T15238C0F35057CD8C768B4B83AEFB2569A5CAD78D2121AF51144C732CC9BCA6CBD20A50 - Submitted as: 26481d_631957d41be748edad4a4389de5f9f9b.pdf
- File type: pdf · Size: 79710 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!867A72BE4734
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/70b01b97-ce5b-4165-9033-3873d7b7ec34/66650219156.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://jacksth.ru/wix?keyword=keepsafe+pc+descargar, https://fa53e508-d88d-41cb-897c-7a5b6f1bfcc3.filesusr.com/ugd/361045_38fea183a3344b0682f16717fb26a537.pdf?index=true, https://jurivulanikep.weebly.com/uploads/1/3/4/5/134525456/zepubuzun_nozeni.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/wix?keyword=keepsafe+pc+descargar
- https://fa53e508-d88d-41cb-897c-7a5b6f1bfcc3.filesusr.com/ugd/361045_38fea183a3344b0682f16717fb26a537.pdf?index=true
- https://jurivulanikep.weebly.com/uploads/1/3/4/5/134525456/zepubuzun_nozeni.pdf
- https://4465b75e-e642-4f53-8c89-e22f0b9d4994.filesusr.com/ugd/ecd213_cc97d6c618d04fe9a5727197c4cd514d.pdf?index=true
- https://52a1af19-6946-4c37-aba6-ab00a30e4874.filesusr.com/ugd/5dc3ca_a5570851ad50439fa133dddd7af52646.pdf?index=true
- https://7fe6b731-3703-45da-bcbe-faf39b4d3392.filesusr.com/ugd/880a7e_f10b47d7d5f549edae19736783334082.pdf?index=true
- https://uploads.strikinglycdn.com/files/70b01b97-ce5b-4165-9033-3873d7b7ec34/66650219156.pdf
- http://help-bluebadgecenter.com/75096390684bi978.pdf
- http://numberoone.xyz/fritzing_simulation_tutorial4mdla.pdf
- https://s3.amazonaws.com/wudibirewuduto/tetep.pdf
- https://uploads.strikinglycdn.com/files/205ab9d7-3c7e-4431-8b7d-49f924783989/ruwivutopawi.pdf
- https://656adf98-7a81-40bd-8d0f-2b9c27d09201.filesusr.com/ugd/268ab1_8ecee14f433343a6a67ccac808ccb441.pdf?index=true
- https://43a2ba88-5de9-465b-b95f-6a4d82f2d06e.filesusr.com/ugd/dcbeda_68a6fb5f5e0440488c52dc6ccf13e658.pdf?index=true
- https://s3.amazonaws.com/nemafu/fesakoxo.pdf
- https://1a441fb4-51dd-4528-a053-eb59ff664e18.filesusr.com/ugd/43d9d5_199c113e50cb4bfb9f13dc5741a1bd33.pdf?index=true
- https://povilaromegew.weebly.com/uploads/1/3/4/4/134486615/5208792.pdf
- https://058da8ce-bb30-4b8c-81eb-8903018cac65.filesusr.com/ugd/ab745b_d76db959d5e04222a94c9344420a1bf6.pdf?index=true
- https://438e95ed-c264-4db5-88d3-1a9ca8b91b86.filesusr.com/ugd/733c1f_eb69183361004e2b82d87b17f2c7a436.pdf?index=true
- https://uploads.strikinglycdn.com/files/5d08f7a2-3c18-4743-9493-5851af62f338/nijuxa.pdf
- https://3ecb585b-79b8-4502-8567-d9a17299c5c1.filesusr.com/ugd/4b874d_bd3b6ee9b97945efa9c975c42e67eba2.pdf?index=true
- https://uploads.strikinglycdn.com/files/7bfa40af-f9e4-40dd-b4e4-dbd12433729f/how_to_open_a_zaxbys_franchise.pdf
- http://paksorond.xyz/10307200580bwkr.pdf
- https://s3.amazonaws.com/pazovugal/arnica_creme_bula.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- jacksth.ru
- fa53e508-d88d-41cb-897c-7a5b6f1bfcc3.filesusr.com
- jurivulanikep.weebly.com
- 4465b75e-e642-4f53-8c89-e22f0b9d4994.filesusr.com
- 52a1af19-6946-4c37-aba6-ab00a30e4874.filesusr.com
- 7fe6b731-3703-45da-bcbe-faf39b4d3392.filesusr.com
- uploads.strikinglycdn.com
- help-bluebadgecenter.com
- numberoone.xyz
- s3.amazonaws.com
- 656adf98-7a81-40bd-8d0f-2b9c27d09201.filesusr.com
- 43a2ba88-5de9-465b-b95f-6a4d82f2d06e.filesusr.com
- 1a441fb4-51dd-4528-a053-eb59ff664e18.filesusr.com
- povilaromegew.weebly.com
- 058da8ce-bb30-4b8c-81eb-8903018cac65.filesusr.com
- 438e95ed-c264-4db5-88d3-1a9ca8b91b86.filesusr.com
- 3ecb585b-79b8-4502-8567-d9a17299c5c1.filesusr.com
- paksorond.xyz
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report