MALICIOUS — 5bd9e2_b8a0ab348ded42ecaf6e1294ac619f92.pdf
MALICIOUS — 5bd9e2_b8a0ab348ded42ecaf6e1294ac619f92.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b2b147a1f0efaf7a497e252dc329119c2b9aeb2d2b4198b4f95851d5f90969e0 - SHA-1:
63856be7084fae0682f9fa391d9d8113ec95c879 - MD5:
1fdcfc5e0e0548a7a8eba5cc6b593d34 - ssdeep:
1536:nd1QgGw3g8EIs+6Lhd/ygeZGZ8mWMXEx+KUTqIHsnmaYy93:HQglLETuZGZFUoKLbYs - TLSH:
T1A638D0F36183CDDCBA8B2B4399B915A9688ED2C9112265A015CC737DC47CADDBE20E50 - Submitted as: 5bd9e2_b8a0ab348ded42ecaf6e1294ac619f92.pdf
- File type: pdf · Size: 79556 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!1FDCFC5E0E05
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://73c25812-7308-4b32-b985-10e2a25710ca.filesusr.com/ugd/5b604d_0738575af1ea4b34b2fe35a60dacdf9a.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://jacksth.ru/wix?keyword=trail+rite+boat+trailer+vin+location, https://73c25812-7308-4b32-b985-10e2a25710ca.filesusr.com/ugd/5b604d_0738575af1ea4b34b2fe35a60dacdf9a.pdf?index=true, https://e5058785-d3d1-442e-b0ad-d0045053dde7.filesusr.com/ugd/17c622_76f23e80e2a54c5fa85f294e164319e0.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/wix?keyword=trail+rite+boat+trailer+vin+location
- https://73c25812-7308-4b32-b985-10e2a25710ca.filesusr.com/ugd/5b604d_0738575af1ea4b34b2fe35a60dacdf9a.pdf?index=true
- https://e5058785-d3d1-442e-b0ad-d0045053dde7.filesusr.com/ugd/17c622_76f23e80e2a54c5fa85f294e164319e0.pdf?index=true
- https://uploads.strikinglycdn.com/files/71e682b8-de42-4129-8510-77a917b3ddbf/ethicon_knot_tying_practice_board.pdf
- http://jiwapadenejeza.getenjoyment.net/how_to_do_standard_enthalpy_change_calculate.pdf
- https://83c30a2d-d83c-4020-88f4-fdb7bed8c9e2.filesusr.com/ugd/e59e18_37b62908c17b4b5c95d3e0456919097b.pdf?index=true
- https://uploads.strikinglycdn.com/files/88ae6ce7-dc44-43a3-a6bc-6dc6deac5bf4/27275005096.pdf
- https://67bb8873-ca08-4da4-87c0-60a8072ebff6.filesusr.com/ugd/a838c0_528fc5195e134a6eaf0b851c6949fc1c.pdf?index=true
- http://dezobod.onlinewebshop.net/baloney_book.pdf
- http://teachost.com/93797466272bcszn.pdf
- http://instapodarok.site/minarazadofa8t31j.pdf
- https://858e1da1-ad31-4e5b-aec0-89c59c6c71f6.filesusr.com/ugd/6240f8_8691852d5368431e9c6dd719634d869f.pdf?index=true
- https://95e354e6-8561-4e52-807b-deb85f3b5fdd.filesusr.com/ugd/ca9b0a_b6ced971ed424853b8c5d87318d862f4.pdf?index=true
- https://wofofubuw.weebly.com/uploads/1/3/2/7/132710679/fitupulurefop.pdf
- https://wujenorap.weebly.com/uploads/1/3/5/3/135322769/vepunugal_gekusavapod_lanujobarafovun_zewapurewiduwav.pdf
- https://a581e706-3bf6-41fb-8978-ad4d4077590d.filesusr.com/ugd/afbe6b_b2d44a4020cb45a4b1c0ee9087ef94b5.pdf?index=true
- https://xupumoga.weebly.com/uploads/1/3/1/1/131164417/bukog-funonafida-fosapojojinu-pudut.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- jacksth.ru
- 73c25812-7308-4b32-b985-10e2a25710ca.filesusr.com
- e5058785-d3d1-442e-b0ad-d0045053dde7.filesusr.com
- uploads.strikinglycdn.com
- jiwapadenejeza.getenjoyment.net
- 83c30a2d-d83c-4020-88f4-fdb7bed8c9e2.filesusr.com
- 67bb8873-ca08-4da4-87c0-60a8072ebff6.filesusr.com
- dezobod.onlinewebshop.net
- teachost.com
- instapodarok.site
- 858e1da1-ad31-4e5b-aec0-89c59c6c71f6.filesusr.com
- 95e354e6-8561-4e52-807b-deb85f3b5fdd.filesusr.com
- wofofubuw.weebly.com
- wujenorap.weebly.com
- a581e706-3bf6-41fb-8978-ad4d4077590d.filesusr.com
- xupumoga.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report