MALICIOUS — 923104_49a1f74b5a3a4665acf50b31c805b79b.pdf
MALICIOUS — 923104_49a1f74b5a3a4665acf50b31c805b79b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b4c522e2d19dff1e0c5d2dfe796e2561eac9606dfdd8083118f8bf93df543d2f - SHA-1:
6258bacf08bda30b4987cb0e94b644b41d908e25 - MD5:
829eaa774ca8fa5439916cadce97ce63 - ssdeep:
1536:d1whVUPtWlUgK/tHx3H7XSAddvhmbKSHjrU1nEQ9BayQmVjGkdomvdU3/w34h7Ox:4hVdlBYR3DSWlomSHcJBauy/wIh/w - TLSH:
T1FF39E1F361CBED4C5BD55B039AF6145994DE93CE71329BA118883A2DC47C6FE6E00412 - Submitted as: 923104_49a1f74b5a3a4665acf50b31c805b79b.pdf
- File type: pdf · Size: 88171 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!829EAA774CA8
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://b7eb3c74-9f10-4efd-a612-efb7ea03662f.filesusr.com/ugd/7198c1_8473bc9eaed54ab0bbccecbdd55eaac0.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://pelibifir.ru/wix?keyword=vocabulary+power+2+answers, https://seruvukajobal.weebly.com/uploads/1/3/4/4/134479042/diveladufanerab.pdf, https://uploads.strikinglycdn.com/files/0cb41219-c309-4869-99a5-70b3fcf4a534/36766064805.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pelibifir.ru/wix?keyword=vocabulary+power+2+answers
- https://s3.amazonaws.com/muvevanepen/itunes_manually_backup_iphone_greyed_out.pdf
- https://s3.amazonaws.com/donukadizolin/abdomen_and_kub_scan_report.pdf
- https://seruvukajobal.weebly.com/uploads/1/3/4/4/134479042/diveladufanerab.pdf
- https://uploads.strikinglycdn.com/files/0cb41219-c309-4869-99a5-70b3fcf4a534/36766064805.pdf
- https://b7eb3c74-9f10-4efd-a612-efb7ea03662f.filesusr.com/ugd/7198c1_8473bc9eaed54ab0bbccecbdd55eaac0.pdf?index=true
- https://uploads.strikinglycdn.com/files/51bd61a8-4b1b-44e6-863d-85b7f1014bf5/wurifesufujofewodekin.pdf
- https://s3.amazonaws.com/jaxesabi/fefoveralinexig.pdf
- https://lovarewido.weebly.com/uploads/1/3/4/3/134322716/11289a9.pdf
- https://0502d5d0-a0f5-47b8-bc1c-644c46e4e431.filesusr.com/ugd/6cabbb_241f8fc13a4a43ceaa1b14d0824ec348.pdf?index=true
- https://36622f5a-5a1b-41a5-aa98-965156e47ac2.filesusr.com/ugd/804ff6_28f9421a71bf4850b4213c00e5f5875e.pdf?index=true
- https://paterixif.weebly.com/uploads/1/3/1/4/131454766/gorodakaxokidunoxup.pdf
- https://s3.amazonaws.com/zabejuvijolu/percentage_to_fraction_simplest_form_calculator.pdf
- https://livuwijonirib.weebly.com/uploads/1/3/4/7/134732661/f286c6f6117131.pdf
- https://s3.amazonaws.com/selivuvumepaveb/blackberry_z10_android_os_install.pdf
- https://s3.amazonaws.com/sefiwegegagu/how_do_you_get_a_royal_crown_acnh.pdf
- https://cf176ec6-4820-456b-adf9-61e5f06c968f.filesusr.com/ugd/43d598_190d7d882f1e42c0ba813af3bca5fba5.pdf?index=true
- https://sagetiruguw.weebly.com/uploads/1/3/0/8/130814856/foxow.pdf
- https://s3.amazonaws.com/gaxuremewuger/android_version_pie_game.pdf
- https://d7ae471b-a447-437d-81b4-4e603f8679d9.filesusr.com/ugd/0a3240_458257c99b604cd4afe3f935c97f9206.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- pelibifir.ru
- s3.amazonaws.com
- seruvukajobal.weebly.com
- uploads.strikinglycdn.com
- b7eb3c74-9f10-4efd-a612-efb7ea03662f.filesusr.com
- lovarewido.weebly.com
- 0502d5d0-a0f5-47b8-bc1c-644c46e4e431.filesusr.com
- 36622f5a-5a1b-41a5-aa98-965156e47ac2.filesusr.com
- paterixif.weebly.com
- livuwijonirib.weebly.com
- cf176ec6-4820-456b-adf9-61e5f06c968f.filesusr.com
- sagetiruguw.weebly.com
- d7ae471b-a447-437d-81b4-4e603f8679d9.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report