MALICIOUS — 952c2e_c2614480af5e4a17a72644ce6cb518cd.pdf
MALICIOUS — 952c2e_c2614480af5e4a17a72644ce6cb518cd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bc50469940d9b36772251a07804a4e833ade79625b5be83e38b930cbabf23fde - SHA-1:
85b08194592cf2e18840aa433908c320950c4aba - MD5:
a9feebc8b47fff1453867cd4c7978727 - ssdeep:
1536:vA8pjxIe3NVoCc3kRtesRYQpe+NjB3wq/KrJfkpBrE:LHz3fS3kxYL+NdwqGJ8pW - TLSH:
T1E338D0F36157ED8C3EDF879379BB00296489D38960328B9085587A6DC0BC36EBF10911 - Submitted as: 952c2e_c2614480af5e4a17a72644ce6cb518cd.pdf
- File type: pdf · Size: 78321 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!A9FEEBC8B47F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://rirudelibuwa.weebly.com/uploads/1/3/1/6/131606594/pavixi_lanobepukose_sizup.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://xajibur.ru/wix?keyword=clarion+car+stereo+for+sale, http://mofawab.66ghz.com/ccna_download.pdf, https://rirudelibuwa.weebly.com/uploads/1/3/1/6/131606594/pavixi_lanobepukose_sizup.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://xajibur.ru/wix?keyword=clarion+car+stereo+for+sale
- http://mofawab.66ghz.com/ccna_download.pdf
- https://rirudelibuwa.weebly.com/uploads/1/3/1/6/131606594/pavixi_lanobepukose_sizup.pdf
- https://77701ba7-c5ad-4750-ab17-5b03548f7fc0.filesusr.com/ugd/9a242c_2641cf4354e844bb852142fd623e6303.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4372753/normal_6030a0d0cecd1.pdf
- https://02bc4616-4eae-4b38-b2c9-0e654f754ee0.filesusr.com/ugd/069df5_ff13b76c8c934927a539986493d9c0cd.pdf?index=true
- http://zagavogafewakud.iblogger.org/already_yet_exercise.pdf
- https://c1d61d78-9bae-425c-b347-ee91470fe4f1.filesusr.com/ugd/60933b_7b5fbf2f83a54395a359488963a789cb.pdf?index=true
- https://9c789f27-b70c-4c9d-9e83-211ee8f99b38.filesusr.com/ugd/bdeb4c_ef432637d9534c9ebfe9217329124f6d.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4369646/normal_602f22c151d2f.pdf
- http://mopawok.epizy.com/python_reportlab_merge_files.pdf
- http://xapakiz.rf.gd/ridimitidugajafit.pdf
- http://rabewifawilowe.epizy.com/curso_de_ingles_gratuito.pdf
- https://fozaxuvuten.weebly.com/uploads/1/3/3/9/133986835/xokufix_retudulafado_ninogi.pdf
- https://roromitekavu.weebly.com/uploads/1/3/4/5/134528712/110d07f2a33d10.pdf
- https://91953a53-6f32-4f2a-9b2e-0f954541ff31.filesusr.com/ugd/dad90e_3550afa1da2447009616b20f395d7d61.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4450638/normal_5fff4e57904f6.pdf
- https://0eb00d84-361a-45dc-b346-1af5c8eb785c.filesusr.com/ugd/d79848_b07ab8fdc9724ad38d9d5b354e26838f.pdf?index=true
- http://vutevesofu.rf.gd/asterism_bold_font_free.pdf
- http://vasedazixi.rf.gd/13000491152.pdf
- https://vavivaso.weebly.com/uploads/1/3/0/8/130873957/7193926.pdf
- https://wugeneziwepuzi.weebly.com/uploads/1/3/4/4/134494794/ec6ca504af7d41e.pdf
- http://fopaguduvogo.rf.gd/fofakedab.pdf
- https://104e0e48-a4c2-4a03-8647-06ef64d4e6ac.filesusr.com/ugd/e2c6c1_48a2539484ec434692fa077d255fb4bd.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- xajibur.ru
- mofawab.66ghz.com
- rirudelibuwa.weebly.com
- 77701ba7-c5ad-4750-ab17-5b03548f7fc0.filesusr.com
- cdn-cms.f-static.net
- 02bc4616-4eae-4b38-b2c9-0e654f754ee0.filesusr.com
- zagavogafewakud.iblogger.org
- c1d61d78-9bae-425c-b347-ee91470fe4f1.filesusr.com
- 9c789f27-b70c-4c9d-9e83-211ee8f99b38.filesusr.com
- mopawok.epizy.com
- rabewifawilowe.epizy.com
- fozaxuvuten.weebly.com
- roromitekavu.weebly.com
- 91953a53-6f32-4f2a-9b2e-0f954541ff31.filesusr.com
- static.s123-cdn-static.com
- 0eb00d84-361a-45dc-b346-1af5c8eb785c.filesusr.com
- vavivaso.weebly.com
- wugeneziwepuzi.weebly.com
- 104e0e48-a4c2-4a03-8647-06ef64d4e6ac.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- xapakiz.rf.gd
- vutevesofu.rf.gd
- vasedazixi.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report