MALICIOUS — 8d50cd66.pdf
MALICIOUS — 8d50cd66.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bdbcce8f3b318a89d5bcdbecb56ec68999c014aea8b010185943e309b6fdf6da - SHA-1:
694f28914dee6b888efb098130bb4733f6dbb874 - MD5:
6e1ce9ea73ecc7e8a9c169cc54f954c8 - ssdeep:
1536:c8iGGnjrSF96hVlIbAxGf8oK3hP9U8yGr10SBjJsQGohUEPZJW8I58oPb:YG59mjLd3h71JaoSEhdI580 - TLSH:
T1333ACFF35097ED8C7ACB1B5379B60174744AEA593321CE9044C87A7C84786BDBF60A90 - Submitted as: 8d50cd66.pdf
- File type: pdf · Size: 95025 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://f733e552-90a1-4d1f-83ca-a6b36afcf31c.filesusr.com/ugd/38bf1f_b745554a2f494696a1ab5774a1d7eb10.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://zajinet.ru/wb?keyword=dark%20cave%20pokemon%20fire%20red, https://f733e552-90a1-4d1f-83ca-a6b36afcf31c.filesusr.com/ugd/38bf1f_b745554a2f494696a1ab5774a1d7eb10.pdf?index=true, https://uploads.strikinglycdn.com/files/7911d693-7472-462a-b931-61dd6f7ea152/basic_electronics_components_and_their_functions.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://zajinet.ru/wb?keyword=dark%20cave%20pokemon%20fire%20red
- https://f733e552-90a1-4d1f-83ca-a6b36afcf31c.filesusr.com/ugd/38bf1f_b745554a2f494696a1ab5774a1d7eb10.pdf?index=true
- https://uploads.strikinglycdn.com/files/7911d693-7472-462a-b931-61dd6f7ea152/basic_electronics_components_and_their_functions.pdf
- http://nosinoski.shop/sofewumezagadelipijugs08g.pdf
- http://umkatrade.ru/how_do_i_thread_my_kenmore_385_sewing_machineflhaw.pdf
- https://cdn-cms.f-static.net/uploads/4451544/normal_6023a10d15ee5.pdf
- https://cdn-cms.f-static.net/uploads/4408180/normal_601603010f154.pdf
- https://uploads.strikinglycdn.com/files/163457db-8cac-47a2-ba06-acc5cce4be43/lalitaget.pdf
- https://cdn-cms.f-static.net/uploads/4417214/normal_602c6b0b9e735.pdf
- http://maska-respirator.com/word_count_program_in_hadoop_mapreduceuqszw.pdf
- http://kataeta.club/febokelorevuduxo5xypl.pdf
- https://cdn-cms.f-static.net/uploads/4410199/normal_601cc1d19ce7b.pdf
- http://flowerport.store/baofeng_uv_5r_programming_software_chirp3zpog.pdf
- http://reduslim-officialsite.site/zajudugisiy4e7z.pdf
- https://uploads.strikinglycdn.com/files/b6e1d179-e983-4269-b312-ecc4c5a66d2d/69514454783.pdf
- http://creampiepow.club/dvdfab_10_crack_msvcr90_dllxq9xf.pdf
- https://fea50346-ab34-4b67-843e-90a6383c4983.filesusr.com/ugd/bf678e_10bb6a3779544af1a341790c02cc220b.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4365599/normal_6002f1af6d1ea.pdf
- https://ad9e3d1f-bb22-46ca-892e-b6aa3325a756.filesusr.com/ugd/837d34_c0f1526a4b754aff84da1800f1bf4ff8.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- zajinet.ru
- f733e552-90a1-4d1f-83ca-a6b36afcf31c.filesusr.com
- uploads.strikinglycdn.com
- nosinoski.shop
- umkatrade.ru
- cdn-cms.f-static.net
- maska-respirator.com
- kataeta.club
- flowerport.store
- reduslim-officialsite.site
- creampiepow.club
- fea50346-ab34-4b67-843e-90a6383c4983.filesusr.com
- static.s123-cdn-static.com
- ad9e3d1f-bb22-46ca-892e-b6aa3325a756.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report