MALICIOUS — normal_604ebe48ba25f.pdf
MALICIOUS — normal_604ebe48ba25f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 6 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a64a6df1a86977e6f77fa15077c554eaa5d60b8df04180e670ca9cf31bf15a67 - SHA-1:
b49d4063602bfcb8dbf82765ca89a3897c99111b - MD5:
6f5bbaef0b7d401d221b32f8abed7a44 - ssdeep:
1536:5XQIMEtE+TQiK1UQWdZ9rMclD7Le+cltLa:aT+TQiK1UbdZpJd7Leflg - TLSH:
T19D38BFF351C7ED4CBA8AEF0369BB396A5145D38C74328AA4804C6A7CC4BC6BE7D04951 - Submitted as: normal_604ebe48ba25f.pdf
- File type: pdf · Size: 82829 bytes
- Verdict: malicious (94/100)
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!6F5BBAEF0B7D
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://44f68060-d5e3-4d58-b4e7-e3760392f352.filesusr.com/ugd/49488e_8be98bbdeaa447ef8a99d1064e985877.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://midufefew.ru/123?utm_term=causes+of+inflation+and+deflation+pdf, https://44f68060-d5e3-4d58-b4e7-e3760392f352.filesusr.com/ugd/49488e_8be98bbdeaa447ef8a99d1064e985877.pdf?index=true, https://sinukofulav.weebly.com/uploads/1/3/4/6/134634738/6343182.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://midufefew.ru/123?utm_term=causes+of+inflation+and+deflation+pdf
- https://44f68060-d5e3-4d58-b4e7-e3760392f352.filesusr.com/ugd/49488e_8be98bbdeaa447ef8a99d1064e985877.pdf?index=true
- https://sinukofulav.weebly.com/uploads/1/3/4/6/134634738/6343182.pdf
- http://buzevuzelape.mywebcommunity.org/37932533640.pdf
- https://d3df31c7-72fe-42b1-a92e-0723e8ed7a16.filesusr.com/ugd/5bf82b_5bf0d8dc381f4faeb12359ca4f2dc2a3.pdf?index=true
- https://cdn.sqhk.co/nokotadi/MwugfPj/love_letters_to_the_dead_ava_dellaira.pdf
- https://s3.amazonaws.com/devuxuzejozam/fibeloriwavibokokam.pdf
- https://cdn.sqhk.co/xegunorasu/jfM6gcN/31354668800.pdf
- https://5a995288-ce6f-4ae3-a3e6-14272d8003db.filesusr.com/ugd/7be1cd_b890b38c2c9f474db4718b0ab634b17b.pdf?index=true
- http://punejew.mygamesonline.org/xowaxutatemapijomekuwir.pdf
- http://gomigapujasep.sportsontheweb.net/como_ser_un_buen_lider_en_tu_trabajo.pdf
- https://safamitiwifiro.weebly.com/uploads/1/3/0/7/130739579/bopafi.pdf
- https://dotanivim.weebly.com/uploads/1/3/4/7/134705276/vizavipaw.pdf
- http://effektzhizni.ru/quickbooks_edit_email_invoice_templatezjaj2.pdf
- https://lideteli.weebly.com/uploads/1/3/0/7/130775407/fevimegadowaji.pdf
- https://zevuvizaxetu.weebly.com/uploads/1/3/4/8/134887967/rekuzini_tevozaxe_pesezovi.pdf
- http://front-glass.website/form_ct-1040_instructions_2016nj70g.pdf
- http://itfamily.info/destiny_2_raid_guide_last_wishrzkct.pdf
- http://lg-supportteam.com/5188090312as9u4.pdf
- https://cdn.sqhk.co/zinazejoras/hijgiPP/playstation_4_slim.pdf
- https://cdn.sqhk.co/wazikunal/au23jbL/bekonamibojimukuxanepuda.pdf
- https://cdn.sqhk.co/nujusowidom/jhjf0AX/samsung_split_ac_indoor_unit_price.pdf
- https://s3.amazonaws.com/webipejonavuv/fontanela_anterior_cierre.pdf
- https://4abf464d-34d5-4c80-8de5-e64f30e04530.filesusr.com/ugd/8b3eb5_08ec88710009477799be628e6a9dac00.pdf?index=true
- https://14535e1a-360a-4d01-a655-fa33e115c80e.filesusr.com/ugd/b222ea_24b613c09b394a53b5599e3be470545a.pdf?index=true
Embedded domains
- midufefew.ru
- 44f68060-d5e3-4d58-b4e7-e3760392f352.filesusr.com
- sinukofulav.weebly.com
- buzevuzelape.mywebcommunity.org
- d3df31c7-72fe-42b1-a92e-0723e8ed7a16.filesusr.com
- cdn.sqhk.co
- s3.amazonaws.com
- 5a995288-ce6f-4ae3-a3e6-14272d8003db.filesusr.com
- punejew.mygamesonline.org
- gomigapujasep.sportsontheweb.net
- safamitiwifiro.weebly.com
- dotanivim.weebly.com
- effektzhizni.ru
- lideteli.weebly.com
- zevuvizaxetu.weebly.com
- itfamily.info
- lg-supportteam.com
- 4abf464d-34d5-4c80-8de5-e64f30e04530.filesusr.com
- 14535e1a-360a-4d01-a655-fa33e115c80e.filesusr.com
- i.se
- www.w3.org
- purl.org
- ns.adobe.com
- front-glass.website
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report