MALICIOUS — b06f92cb59b37d2f97d39c83695b714cdf23ecfcbbf269171a614441991640f9
MALICIOUS — b06f92cb59b37d2f97d39c83695b714cdf23ecfcbbf269171a614441991640f9 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b06f92cb59b37d2f97d39c83695b714cdf23ecfcbbf269171a614441991640f9 - SHA-1:
95a94d3f2135df4de77e4d2ef8609bca114a6f69 - MD5:
611bf6beecedce0230256e1ae1515a59 - ssdeep:
1536:i25DobdhCtZkA/icj6nAXQJlJAHLIJFUzZgkHfL0MYy6N5oIWzSxX6sni1eUHd:NDoZAtWAHj6nAAzJrJFUFPfL0tRWux5w - TLSH:
T16538D0F36097DE9C7A8ADF43BDA615AAB4C997487131EBA004C8B32DC46C5BD3D14A00 - Submitted as: b06f92cb59b37d2f97d39c83695b714cdf23ecfcbbf269171a614441991640f9
- File type: pdf · Size: 84086 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4425728/normal_5fe56e3052c81.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://inwebjor.ru/pbw?utm_term=graphing+exponential+functions+worksheet+with+answers+pdf+algebra+2, https://uploads.strikinglycdn.com/files/2fc6a0d7-b1a1-4bb5-b3cf-41b5d67fbab2/hill-rom_total_care_bariatric_bed_manual.pdf, http://zulamiz.pbworks.com/w/file/fetch/144705444/software_project_manager_roles_and_responsibilities.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://inwebjor.ru/pbw?utm_term=graphing+exponential+functions+worksheet+with+answers+pdf+algebra+2
- https://uploads.strikinglycdn.com/files/2fc6a0d7-b1a1-4bb5-b3cf-41b5d67fbab2/hill-rom_total_care_bariatric_bed_manual.pdf
- http://zulamiz.pbworks.com/w/file/fetch/144705444/software_project_manager_roles_and_responsibilities.pdf
- https://static.s123-cdn-static.com/uploads/4425728/normal_5fe56e3052c81.pdf
- https://uploads.strikinglycdn.com/files/eab2e921-0cd7-46dc-9b6e-b304757c2461/how_big_is_30_by_30_inches.pdf
- https://static.s123-cdn-static.com/uploads/4484639/normal_5fe41d742b0ac.pdf
- https://uploads.strikinglycdn.com/files/9a8eae39-1681-46be-ba78-1af94e241f38/38921604298.pdf
- https://befetoxakotupo.weebly.com/uploads/1/3/0/7/130738956/8a9038397af8a04.pdf
- https://uploads.strikinglycdn.com/files/1da866cb-2e39-4913-8736-bbafe956482f/91688905239.pdf
- http://demopefo.pbworks.com/f/87014850559.pdf
- https://vunafenivanisip.weebly.com/uploads/1/3/5/3/135303543/mevejifotaj-bifude-mobokelana-rojat.pdf
- https://majizozu.weebly.com/uploads/1/3/4/5/134598595/51e61c8c.pdf
- https://cdn-cms.f-static.net/uploads/4373516/normal_601dbeee0c431.pdf
- https://zigiruma.weebly.com/uploads/1/3/7/5/137517675/5705080.pdf
- http://kusarolox.pbworks.com/w/file/fetch/144680652/41898264323.pdf
- https://uploads.strikinglycdn.com/files/ee9fe6a2-cdb3-448d-8b66-45f625396793/ejercicios_de_division_de_polinomios_con_fracciones_resueltos.pdf
- https://vesasasafej.weebly.com/uploads/1/3/4/7/134758359/jivitu-xisub.pdf
- http://negovijalulu.pbworks.com/w/file/fetch/144426408/96350385726.pdf
- https://cdn-cms.f-static.net/uploads/4391907/normal_604680e64a01c.pdf
- https://cdn-cms.f-static.net/uploads/4469827/normal_601e70474cb93.pdf
- https://uploads.strikinglycdn.com/files/dd9637be-9f6a-4ba5-ac2d-ba44fbd69613/professional_development_plan_for_nurses_and_midwives.pdf
- https://uploads.strikinglycdn.com/files/67f6ad68-24da-42e8-89d9-0ec903ccb51e/new_video_games_christmas_2020.pdf
- https://cdn-cms.f-static.net/uploads/4368487/normal_5fe81ba218d8c.pdf
- https://uploads.strikinglycdn.com/files/b34d25d9-04e9-4153-8960-9170a85d9d89/61815110183.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- inwebjor.ru
- uploads.strikinglycdn.com
- zulamiz.pbworks.com
- static.s123-cdn-static.com
- befetoxakotupo.weebly.com
- demopefo.pbworks.com
- vunafenivanisip.weebly.com
- majizozu.weebly.com
- cdn-cms.f-static.net
- zigiruma.weebly.com
- kusarolox.pbworks.com
- vesasasafej.weebly.com
- negovijalulu.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report