MALICIOUS — 915a55_0c71ff7620f145fc80a3e0785296aaf2.pdf
MALICIOUS — 915a55_0c71ff7620f145fc80a3e0785296aaf2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
be85df9c24f38434fd6416b624e9e34483066c991166d3d22d55ac60454fc2fd - SHA-1:
5ec55ce2b021b929109758ed989c07785a83a7ff - MD5:
7fcf949d63f06e000f344475f3bb9134 - ssdeep:
1536:abdLLY7wuPQWwAWeQUMLZDWvrqAoo9Z30ZqVIsLpbXI:GdSe1VDP+kZ0IAy - TLSH:
T16136CFF762C3ED4CB68BDB137FA929A96585FACC50328651048C732CC4BC7AE6E10641 - Submitted as: 915a55_0c71ff7620f145fc80a3e0785296aaf2.pdf
- File type: pdf · Size: 69584 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!7FCF949D63F0
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://fb413987-6e77-4bf1-aaa6-e97eb550fbee.filesusr.com/ugd/108936_6f719d81d98c452a9257caae52c42034.pdf?index=true - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://dafemum.ru/wix?keyword=don+quijote+resumen+y+analisis+por+capitulos, https://cdn.sqhk.co/kupujape/XiijffK/86728073650.pdf, https://83372c7a-1065-4b07-8284-b64562b46e84.filesusr.com/ugd/035489_b0693aa04fea4469ab2329d147fc55c7.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://dafemum.ru/wix?keyword=don+quijote+resumen+y+analisis+por+capitulos
- https://cdn.sqhk.co/kupujape/XiijffK/86728073650.pdf
- https://83372c7a-1065-4b07-8284-b64562b46e84.filesusr.com/ugd/035489_b0693aa04fea4469ab2329d147fc55c7.pdf?index=true
- https://e8b83640-91e4-44a0-a69f-c2468797902f.filesusr.com/ugd/ee4a13_f3840db1b69c4b9c860f09d236a8d14b.pdf?index=true
- http://copyright-services-us.com/gunazepulijauoo5v.pdf
- https://fb413987-6e77-4bf1-aaa6-e97eb550fbee.filesusr.com/ugd/108936_6f719d81d98c452a9257caae52c42034.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4446152/normal_5ff4955370d6d.pdf
- http://topmassage.net/zubujoxokodidosupavabenamu7qv.pdf
- https://013c3ecd-17dd-4738-ad87-554153c764a5.filesusr.com/ugd/36f25b_af09f70e10db4aefbb40ed3c6befaeb7.pdf?index=true
- https://cdn.sqhk.co/mixirulizab/Jziegfi/luwanovubisamarime.pdf
- https://d25e5d79-f3dc-43ab-8538-58f2f4730235.filesusr.com/ugd/898300_bbceac237b7b4cbc99e1d82c6f6d8e8f.pdf?index=true
- http://luzofogobud.22web.org/troy_bilt_storm_2410_gas_shut_off.pdf
- https://static.s123-cdn-static.com/uploads/4379839/normal_6007fd890e664.pdf
- https://static.s123-cdn-static.com/uploads/4374957/normal_5ff9085351d9f.pdf
- https://f11c4bf2-12a6-49f8-9590-07a94b689168.filesusr.com/ugd/11276f_ea316cc7d90a43e599fb4e87d1a9f107.pdf?index=true
- https://ad9f1622-e3b7-49db-bfef-326c48fb2104.filesusr.com/ugd/a467d2_a5b940ac836a47809e7896b83752c664.pdf?index=true
- https://cdn.sqhk.co/najuvotuwoz/ajjTkib/blaze_of_battle_cheat_codes.pdf
- http://specrazreshenie.com/anne_bradstreet_poetry_worksheetjkucr.pdf
- http://matunojusorim.epizy.com/benefits_of_sex_education_in_schools_essay.pdf
- https://cdn-cms.f-static.net/uploads/4384149/normal_5fe82a1f232d7.pdf
- https://cdn.sqhk.co/numavagoko/bjbZ64h/wireless_fm_transmitter_circuit.pdf
- https://cdn.sqhk.co/vulovosovem/h9Ngihb/the_new_york_times_articles_2019.pdf
- https://e9593579-f51f-4dc6-af55-2543ab512b45.filesusr.com/ugd/37952c_4fcc2f616e234cad99bfda53a247ce13.pdf?index=true
- https://dc273c12-e125-4738-b2e6-b96bc4bd5eb7.filesusr.com/ugd/c8df25_e5a17901f4214c7aa0c59a89b731a910.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- dafemum.ru
- cdn.sqhk.co
- 83372c7a-1065-4b07-8284-b64562b46e84.filesusr.com
- e8b83640-91e4-44a0-a69f-c2468797902f.filesusr.com
- copyright-services-us.com
- fb413987-6e77-4bf1-aaa6-e97eb550fbee.filesusr.com
- static.s123-cdn-static.com
- topmassage.net
- 013c3ecd-17dd-4738-ad87-554153c764a5.filesusr.com
- d25e5d79-f3dc-43ab-8538-58f2f4730235.filesusr.com
- luzofogobud.22web.org
- f11c4bf2-12a6-49f8-9590-07a94b689168.filesusr.com
- ad9f1622-e3b7-49db-bfef-326c48fb2104.filesusr.com
- specrazreshenie.com
- matunojusorim.epizy.com
- cdn-cms.f-static.net
- e9593579-f51f-4dc6-af55-2543ab512b45.filesusr.com
- dc273c12-e125-4738-b2e6-b96bc4bd5eb7.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report