MALICIOUS — b10d2acf2908a669e4fea71ee6caf2cf5b832d6f4406b558f5206a2099fb60ef
MALICIOUS — b10d2acf2908a669e4fea71ee6caf2cf5b832d6f4406b558f5206a2099fb60ef is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b10d2acf2908a669e4fea71ee6caf2cf5b832d6f4406b558f5206a2099fb60ef - SHA-1:
de16deb9a7a44d60452710542cd119eb34d3d1d9 - MD5:
bcdabeddee956c6d7fe8ae75b34630f1 - ssdeep:
1536:LrEXsIiKryvPOUs2K+siMRc6GhY3TlpY74Gy8AajholAeu:WyvPOUsMAmLa074GMaj6l4 - TLSH:
T1B737C0F72187DCCCAB4A6F53A9A615AC6086C3C46231EB6440CCB77DD47CA7D2E60A50 - Submitted as: b10d2acf2908a669e4fea71ee6caf2cf5b832d6f4406b558f5206a2099fb60ef
- File type: pdf · Size: 73070 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!BCDABEDDEE95
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/e1109106-dcca-47be-a8c7-ed183fb97459/samsung_galaxy_note_10.1_n8000_firmware_free_download.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://drafthe.ru/pbw?utm_term=flushed+away+2006+part+1, https://uploads.strikinglycdn.com/files/e1109106-dcca-47be-a8c7-ed183fb97459/samsung_galaxy_note_10.1_n8000_firmware_free_download.pdf, https://gowumobajakexe.weebly.com/uploads/1/3/4/5/134585768/xizar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://drafthe.ru/pbw?utm_term=flushed+away+2006+part+1
- https://uploads.strikinglycdn.com/files/e1109106-dcca-47be-a8c7-ed183fb97459/samsung_galaxy_note_10.1_n8000_firmware_free_download.pdf
- https://gowumobajakexe.weebly.com/uploads/1/3/4/5/134585768/xizar.pdf
- http://xifatarege.pbworks.com/w/file/fetch/144690477/how_to_make_income_statement_and_balance_sheet_in_excel.pdf
- https://uploads.strikinglycdn.com/files/35076135-5387-4bb2-8f5d-5c1256adc216/class_3_math_practice.pdf
- https://zogolobogin.weebly.com/uploads/1/3/4/6/134690222/5590186.pdf
- http://lekipirunezi.pbworks.com/w/file/fetch/144427962/uppababy_vista_double_configurations_with_bassinet.pdf
- https://uploads.strikinglycdn.com/files/f14409ad-a30d-447f-9a09-97cad30053a7/best_romance_thriller_books_2020.pdf
- https://cdn-cms.f-static.net/uploads/4446915/normal_6014732e75cb4.pdf
- http://wenuveraroto.pbworks.com/w/file/fetch/144528732/1477194421.pdf
- https://uploads.strikinglycdn.com/files/21b8e608-b04c-4020-b940-8ce7786b179b/blood_bowl_2_passing_rules.pdf
- https://ximavubakalik.weebly.com/uploads/1/3/0/7/130776508/db5bdbae2bb.pdf
- https://static.s123-cdn-static-d.com/uploads/4529697/normal_60b6daa328960.pdf
- https://fovinekepug.weebly.com/uploads/1/3/4/5/134587719/6606383.pdf
- https://guvatezip.weebly.com/uploads/1/3/0/7/130776756/a6dd388ddf6af.pdf
- https://uploads.strikinglycdn.com/files/7162382c-af82-45f9-95ff-879a64dd8579/how_to_connect_chromecast_to_phone.pdf
- https://sagakoto.weebly.com/uploads/1/3/0/8/130814189/5632059.pdf
- https://cdn-cms.f-static.net/uploads/4450260/normal_6010b762e458d.pdf
- https://pupaxutakigi.weebly.com/uploads/1/3/4/5/134579126/vogevimun-jevig-lopanezidalo.pdf
- https://uploads.strikinglycdn.com/files/77e35bd6-d930-47bd-b3ac-c927c757bdb8/rosetta_stone_spanish_workbook_level_3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- drafthe.ru
- uploads.strikinglycdn.com
- gowumobajakexe.weebly.com
- xifatarege.pbworks.com
- zogolobogin.weebly.com
- lekipirunezi.pbworks.com
- cdn-cms.f-static.net
- wenuveraroto.pbworks.com
- ximavubakalik.weebly.com
- static.s123-cdn-static-d.com
- fovinekepug.weebly.com
- guvatezip.weebly.com
- sagakoto.weebly.com
- pupaxutakigi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report