MALICIOUS — 9d7ad9_8158d1e02648489e94bac2d2712100c8.pdf
MALICIOUS — 9d7ad9_8158d1e02648489e94bac2d2712100c8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b8c0132ddeb6b54c815f9a01b0084303f467e8c505265cbc4c2345b33f96d10f - SHA-1:
954efc384d0474efd2c5506205b4fa02f56352ff - MD5:
659f1b377a89faae07da826cee8021b5 - ssdeep:
1536:3xlU/WgA12MGkVr4QlZVuE/vp0Lf6YUpEULjub7d:nU/NALGVAucvp0HAbLjut - TLSH:
T11037DFF38197ED4CBA8B5B037EEA01AC544AD7882132EB515588B71CC8BC66F3F60516 - Submitted as: 9d7ad9_8158d1e02648489e94bac2d2712100c8.pdf
- File type: pdf · Size: 72348 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!659F1B377A89
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://0eaabcdb-938a-45a6-85a3-1a7d796bbcdd.filesusr.com/ugd/8d6d25_daac9352119d413ebf5e431882cf8cbb.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://fokemale.ru/wix?keyword=puns+worksheet+for+grade+3, https://0eaabcdb-938a-45a6-85a3-1a7d796bbcdd.filesusr.com/ugd/8d6d25_daac9352119d413ebf5e431882cf8cbb.pdf?index=true, https://cdn.sqhk.co/letaziseb/Tyvgdhg/jeluridesodapejab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://fokemale.ru/wix?keyword=puns+worksheet+for+grade+3
- https://0eaabcdb-938a-45a6-85a3-1a7d796bbcdd.filesusr.com/ugd/8d6d25_daac9352119d413ebf5e431882cf8cbb.pdf?index=true
- https://cdn.sqhk.co/letaziseb/Tyvgdhg/jeluridesodapejab.pdf
- https://f8bd9030-4518-40b4-9047-d478e6ffc17b.filesusr.com/ugd/608fe2_9b1c053212764328850c2e8e37b5797b.pdf?index=true
- http://velawomonoxejuz.epizy.com/mivibajigekot.pdf
- https://a82c121c-2200-4cd7-aff6-47cf910fdadb.filesusr.com/ugd/117c17_e7c60d0c52004ea9a623453a253c052c.pdf?index=true
- https://cdn.sqhk.co/febapaji/jbCLsvQ/free_condition_zero_game_download_for_pc.pdf
- https://cdn.sqhk.co/rujopupomob/jgkexid/live_groups_champions_league.pdf
- https://cdn.sqhk.co/sewizefaxiki/eggBhia/fiseluvadiri.pdf
- https://cdn.sqhk.co/balaragu/rOighEU/16675614106.pdf
- https://4f65703b-d4c0-4c9c-9e30-73c8cc83ec5d.filesusr.com/ugd/54fa57_a732d61ad04543bd81d60f22f1c7f72a.pdf?index=true
- http://xakafoboveje.rf.gd/2732716670.pdf
- https://cdn.sqhk.co/xupodafib/WgjHbgi/niwurotudesakurirevulibop.pdf
- https://cdn.sqhk.co/sipebililofo/gjd1hbK/8623583392.pdf
- https://cdn.sqhk.co/duloputemab/OoTihdG/kazozidibevasinunusile.pdf
- http://bunokupisosep.epizy.com/passport_photo_editor_free.pdf
- https://dab7fb03-f2af-4a8e-9cb9-31de623bedb3.filesusr.com/ugd/58b596_00803045290f49e4953cbdcd6d83ef1f.pdf?index=true
- http://kedekivotizera.epizy.com/exponent_and_scientific_notation_study_guide.pdf
- https://5634f520-c25d-421d-ab67-3d94505d13cb.filesusr.com/ugd/1b85ab_58f54e4645cf4879a561d09ca87c473a.pdf?index=true
- https://cdn.sqhk.co/zozimevoket/8Ijjfgh/top_100_best_ringtones_2020.pdf
- https://d23eb412-52e1-45ef-a32a-0c032022daee.filesusr.com/ugd/03485a_0019f885ac314e539353cc0e9736c10d.pdf?index=true
- http://sowinoto.epizy.com/self_certification_form_scotland.pdf
- https://7404da97-7fcf-4d5f-9d5f-3f8644e6773a.filesusr.com/ugd/35f767_2466cbf436774baa8ddc65c67eda0bca.pdf?index=true
- https://16e729f2-8c5c-4787-b670-14aeba6c5e03.filesusr.com/ugd/ac55e2_c80255b61b204ec6976680ec90e1b27f.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- fokemale.ru
- 0eaabcdb-938a-45a6-85a3-1a7d796bbcdd.filesusr.com
- cdn.sqhk.co
- f8bd9030-4518-40b4-9047-d478e6ffc17b.filesusr.com
- velawomonoxejuz.epizy.com
- a82c121c-2200-4cd7-aff6-47cf910fdadb.filesusr.com
- 4f65703b-d4c0-4c9c-9e30-73c8cc83ec5d.filesusr.com
- bunokupisosep.epizy.com
- dab7fb03-f2af-4a8e-9cb9-31de623bedb3.filesusr.com
- kedekivotizera.epizy.com
- 5634f520-c25d-421d-ab67-3d94505d13cb.filesusr.com
- d23eb412-52e1-45ef-a32a-0c032022daee.filesusr.com
- sowinoto.epizy.com
- 7404da97-7fcf-4d5f-9d5f-3f8644e6773a.filesusr.com
- 16e729f2-8c5c-4787-b670-14aeba6c5e03.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- xakafoboveje.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report