MALICIOUS — bb78f02d3d0cbf6d9a21ad92a3f06fe799ad1523dea4c6a9ff97e8d748768e81
MALICIOUS — bb78f02d3d0cbf6d9a21ad92a3f06fe799ad1523dea4c6a9ff97e8d748768e81 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bb78f02d3d0cbf6d9a21ad92a3f06fe799ad1523dea4c6a9ff97e8d748768e81 - SHA-1:
3d5ad47d9922c193fd66f450432e8d1c0de9966b - MD5:
3bc79b594a25c15818197cdb74a74052 - ssdeep:
1536:S4bE+9OdDpjBGyseQK50fL/QyBZoamIDEi7MONr/lNT1dvOy4BQn/:1E+9OdDpUyseQKWP5Qi7MONrNNTfOyUq - TLSH:
T16A37C0F3A1C7DC5CBE8A4B53ADB70468944EC7CCA123EA9054887B1CC4AC7AC3D55A60 - Submitted as: bb78f02d3d0cbf6d9a21ad92a3f06fe799ad1523dea4c6a9ff97e8d748768e81
- File type: pdf · Size: 73044 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!3BC79B594A25
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://siruzosu.pbworks.com/f/silapepaxuj.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://catamma.ru/pbw?utm_term=12+week+metabolic+renewal+meal+plan+pdf, http://siruzosu.pbworks.com/f/silapepaxuj.pdf, http://fubajulak.pbworks.com/w/file/fetch/144677067/3369905979.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://catamma.ru/pbw?utm_term=12+week+metabolic+renewal+meal+plan+pdf
- http://siruzosu.pbworks.com/f/silapepaxuj.pdf
- http://fubajulak.pbworks.com/w/file/fetch/144677067/3369905979.pdf
- https://static.s123-cdn-static.com/uploads/4502698/normal_6007eab4bfcec.pdf
- http://vawaguzidatu.pbworks.com/f/present_tense_english_worksheets.pdf
- http://xutosop.pbworks.com/f/which_of_the_following_is_example_of_direct_indirect_addressing_mode_cs501.pdf
- https://cdn-cms.f-static.net/uploads/4381318/normal_602d0e5f20958.pdf
- https://static.s123-cdn-static.com/uploads/4384320/normal_5fdcef06f08cd.pdf
- https://cdn-cms.f-static.net/uploads/4412387/normal_5fdc25d677c61.pdf
- https://uploads.strikinglycdn.com/files/8a26f2b2-5553-4b77-98e5-c545914af821/46375575851.pdf
- https://static.s123-cdn-static-d.com/uploads/4493221/normal_60b4eee0a03e6.pdf
- https://static.s123-cdn-static.com/uploads/4501042/normal_6008839084352.pdf
- https://cdn-cms.f-static.net/uploads/4392649/normal_60bd5e6680906.pdf
- http://bowawesup.pbworks.com/w/file/fetch/144639696/29824449143.pdf
- https://cdn-cms.f-static.net/uploads/4501201/normal_602b7b3386ed8.pdf
- https://uploads.strikinglycdn.com/files/f7f2c852-3616-43b0-b094-1a91ef4d4230/free_minecraft_windows_10_code_generator.pdf
- https://cdn-cms.f-static.net/uploads/4417032/normal_6037309d0c90a.pdf
- https://cdn-cms.f-static.net/uploads/4384323/normal_605d65deabf8d.pdf
- https://cdn-cms.f-static.net/uploads/4366354/normal_601b350dc63da.pdf
- https://cdn-cms.f-static.net/uploads/4411220/normal_6063f3c172f37.pdf
- http://jutopar.pbworks.com/f/jeleketiwiz.pdf
- https://cdn-cms.f-static.net/uploads/4485813/normal_6044d57c61221.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- catamma.ru
- siruzosu.pbworks.com
- fubajulak.pbworks.com
- static.s123-cdn-static.com
- vawaguzidatu.pbworks.com
- xutosop.pbworks.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- static.s123-cdn-static-d.com
- bowawesup.pbworks.com
- jutopar.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report