MALICIOUS — normal_6049866ae3b1e.pdf
MALICIOUS — normal_6049866ae3b1e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bca6f0a56872d1e69978639e38fedaa2002186b7a901cd27d1e022fdc1b69087 - SHA-1:
1bbec1091fb1e77dd725d5ed1cd6e26f67249a6f - MD5:
59fce18fa8b984cc666343708760bfc9 - ssdeep:
1536:n/4r95kg8XXlKxtQukU1BNqkw/amZ//wTLfoSrZZK+tS1OPC4YGlk3PYVWZ/bwzO:/4rnkg8XXUcukU1BAkw5+LfoKbxS10YX - TLSH:
T18839C0F36187DD8C3AC7AF43BCE2262D558BDB8C3122DE905058636DC46CAAEBE14550 - Submitted as: normal_6049866ae3b1e.pdf
- File type: pdf · Size: 88660 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!59FCE18FA8B9
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://0491f86b-060d-4f4a-be23-b0d01488777f.filesusr.com/ugd/faa7ef_b71214bf08a64a98845f4f34ac36a515.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://leonvi.ru/123?utm_term=kombucha+guide+pdf, https://zalivibutadugaf.weebly.com/uploads/1/3/5/3/135391941/7403319.pdf, http://bcipreactivaperu.com/martin_luther_on_romans_8vfj4t.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://leonvi.ru/123?utm_term=kombucha+guide+pdf
- https://zalivibutadugaf.weebly.com/uploads/1/3/5/3/135391941/7403319.pdf
- http://bcipreactivaperu.com/martin_luther_on_romans_8vfj4t.pdf
- http://detonic-italia.website/635775836720yezh.pdf
- https://0491f86b-060d-4f4a-be23-b0d01488777f.filesusr.com/ugd/faa7ef_b71214bf08a64a98845f4f34ac36a515.pdf?index=true
- http://italystore.pro/boworipisexitokezijewotegyk1u.pdf
- http://trysol.xyz/the_belgariad_series_in_order0646t.pdf
- http://prizinsta.online/pegodeduxonozugoyrs.pdf
- http://tpdreport.com/kemavojutinuvawimopuwkbdpj.pdf
- https://cdn.sqhk.co/gotoruzud/iijdkgG/rebuilding_database_ps4_risks.pdf
- http://gsmall.space/cardiovascular_system_structure_and_functionqkes9.pdf
- http://copyrighytsupport.com/21530255823ul81x.pdf
- https://cdn.sqhk.co/dejuxafe/crIjjj5/luvozozekik.pdf
- https://lowarimubabop.weebly.com/uploads/1/3/4/7/134712264/zowuwuko-dovuzevikizutux.pdf
- https://ba739632-11db-41f7-a023-683a20e55d36.filesusr.com/ugd/99835b_d6fa175378ad419c8d80fcbb56576fa3.pdf?index=true
- https://973697ad-ffa4-4f9d-85cd-0c9d1ea039ee.filesusr.com/ugd/5f5755_fa465472c09f4948aac1d9be8d41ef94.pdf?index=true
- https://1c92f6d8-19eb-429c-9239-1cf6be91372f.filesusr.com/ugd/cc1a03_7db2e0aecbc04a249cb2581cffbd8de5.pdf?index=true
- https://webuxeneme.weebly.com/uploads/1/3/4/3/134368634/jexem.pdf
- https://cdn.sqhk.co/legezuseg/fgGhjhc/donwload_game_street_racing_hd_mod.pdf
- https://ebba3e40-d49f-4cc8-b137-373bb1124918.filesusr.com/ugd/384ea4_deb19793bd5549cb949f4ba6489a0014.pdf?index=true
- https://wufikasuruxur.weebly.com/uploads/1/3/1/6/131636700/livazo.pdf
- http://qiwi-wallet.online/8959696210593wji.pdf
- http://cucoupon.info/11733744999yoqmx.pdf
- http://health-top.ru/is_the_body_reset_diet_gluten_free2ziqc.pdf
- https://bukowimulo.weebly.com/uploads/1/3/1/4/131407836/381341e.pdf
Embedded domains
- leonvi.ru
- zalivibutadugaf.weebly.com
- bcipreactivaperu.com
- 0491f86b-060d-4f4a-be23-b0d01488777f.filesusr.com
- italystore.pro
- trysol.xyz
- prizinsta.online
- tpdreport.com
- cdn.sqhk.co
- gsmall.space
- copyrighytsupport.com
- lowarimubabop.weebly.com
- ba739632-11db-41f7-a023-683a20e55d36.filesusr.com
- 973697ad-ffa4-4f9d-85cd-0c9d1ea039ee.filesusr.com
- 1c92f6d8-19eb-429c-9239-1cf6be91372f.filesusr.com
- webuxeneme.weebly.com
- ebba3e40-d49f-4cc8-b137-373bb1124918.filesusr.com
- wufikasuruxur.weebly.com
- qiwi-wallet.online
- cucoupon.info
- health-top.ru
- bukowimulo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report