MALICIOUS — tovedetogoxogud.pdf
MALICIOUS — tovedetogoxogud.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b60fff80acdd54e1a0728e4ce5525a551131ee804af59dbfc6acfcca3737e354 - SHA-1:
8dd6215ca08af8e1a06f6997b9379321b8bacac6 - MD5:
eec309f2a6043abcbdd0a9c19a66d2b3 - ssdeep:
1536:N/JWC0187hoX6Wosh/8ZEBm6YkKX7dwtlqdUlYiTPijQhWFKi4bcdxuZmN9BP1:/6SM7kZEBmrgUdiePYc7uZmDBd - TLSH:
T10538E1F3219BEE8C7A4B6F4369E210459441D78A2633EB6458887B3CC4BC37E7E10A51 - Submitted as: tovedetogoxogud.pdf
- File type: pdf · Size: 79986 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!EEC309F2A604
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://1de4b56a-3309-4767-83a2-f1bb1ea7c594.filesusr.com/ugd/a6e5e9_95cdeb51c5a74817bf490a57abb357ee.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://jumiwimov.ru/strik?utm_term=how+to+relieve+cellulitis+infection+pain, https://1de4b56a-3309-4767-83a2-f1bb1ea7c594.filesusr.com/ugd/a6e5e9_95cdeb51c5a74817bf490a57abb357ee.pdf?index=true, https://uploads.strikinglycdn.com/files/5a871b91-c7c3-4f40-9559-0748148745ac/can_scoliosis_cause_hip_pain.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jumiwimov.ru/strik?utm_term=how+to+relieve+cellulitis+infection+pain
- https://1de4b56a-3309-4767-83a2-f1bb1ea7c594.filesusr.com/ugd/a6e5e9_95cdeb51c5a74817bf490a57abb357ee.pdf?index=true
- https://uploads.strikinglycdn.com/files/5a871b91-c7c3-4f40-9559-0748148745ac/can_scoliosis_cause_hip_pain.pdf
- https://a68e2ff5-bf17-48e3-82d4-ceb975b85758.filesusr.com/ugd/760101_0d4456009ea04a8bbab357ee97d82409.pdf?index=true
- http://dosaxixapaxa.medianewsonline.com/64283508507.pdf
- https://s3.amazonaws.com/ragejufa/german_address_format_apartment_number.pdf
- https://393102e6-89af-4738-8cad-89662dba8dc5.filesusr.com/ugd/33a16d_009300b326024c43a212bb5e4dab3197.pdf?index=true
- http://4338bacchus.com/dutibokonilirovenitema3fotd.pdf
- https://uploads.strikinglycdn.com/files/b0be1934-ac2f-40a9-8f43-d9ee50306053/4553115295.pdf
- https://genebametujo.weebly.com/uploads/1/3/4/9/134904617/lexab-rurixiwenosalup.pdf
- http://nanonewe.scienceontheweb.net/beats_solo_3_wireless_release_date.pdf
- https://s3.amazonaws.com/topipovikapari/34246727323.pdf
- https://ab25a8b3-4d80-4d4b-93a1-c1347014fa7c.filesusr.com/ugd/8d0191_d6f4d7740eb74c6c8d272feace7ab962.pdf?index=true
- https://lokugejepotag.weebly.com/uploads/1/3/4/3/134318746/wosetufuwagumes.pdf
- http://mybiol.site/example_of_acknowledgement_for_group_project_reportsoqas.pdf
- http://sawurawefivovo.myartsonline.com/agatha_christie_movies_online_youtube.pdf
- http://ryursew.space/nonlinear_ordinary_differential_equationsqop76.pdf
- https://de2ee6d5-caaa-4265-b15c-40100ab77d99.filesusr.com/ugd/d43733_805f5cc828bd485c8fcd7a696af8d4f9.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- jumiwimov.ru
- 1de4b56a-3309-4767-83a2-f1bb1ea7c594.filesusr.com
- uploads.strikinglycdn.com
- a68e2ff5-bf17-48e3-82d4-ceb975b85758.filesusr.com
- dosaxixapaxa.medianewsonline.com
- s3.amazonaws.com
- 393102e6-89af-4738-8cad-89662dba8dc5.filesusr.com
- 4338bacchus.com
- genebametujo.weebly.com
- nanonewe.scienceontheweb.net
- ab25a8b3-4d80-4d4b-93a1-c1347014fa7c.filesusr.com
- lokugejepotag.weebly.com
- mybiol.site
- sawurawefivovo.myartsonline.com
- ryursew.space
- de2ee6d5-caaa-4265-b15c-40100ab77d99.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report