MALICIOUS — bff586d9f1c5c86ded2639b723ebd51e7b30f44a3294c9a85087bb80cff6eccd
MALICIOUS — bff586d9f1c5c86ded2639b723ebd51e7b30f44a3294c9a85087bb80cff6eccd is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bff586d9f1c5c86ded2639b723ebd51e7b30f44a3294c9a85087bb80cff6eccd - SHA-1:
adc65a86a4642c545f796944b4cd164a06bf62e9 - MD5:
1b0343ed1b83b8558797a337896b7160 - ssdeep:
1536:czkQY5toA5SaFKmmvcLse34t2d/R9cyKFCrLeWV5KRq2NaXijUbYQEjJr/upsGuu:g4ZFKmmvcsk3/RNXeWV5KRq2EcFQEFrA - TLSH:
T10839D1F3605BCD4CB64E8B037AB7156C609AD6853532D760548CB22CC8BD6BDBC20A15 - Submitted as: bff586d9f1c5c86ded2639b723ebd51e7b30f44a3294c9a85087bb80cff6eccd
- File type: pdf · Size: 89162 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!1B0343ED1B83
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://ceter.xyz/what_causes_a_dryer_to_keep_shutting_off7zsv4.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://nipisod.ru/123?utm_term=reliability+centered+maintenance+ppt, http://wovubixagoxix.rf.gd/14147792685.pdf, http://ceter.xyz/what_causes_a_dryer_to_keep_shutting_off7zsv4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nipisod.ru/123?utm_term=reliability+centered+maintenance+ppt
- http://wovubixagoxix.rf.gd/14147792685.pdf
- http://ceter.xyz/what_causes_a_dryer_to_keep_shutting_off7zsv4.pdf
- https://tujezagen.weebly.com/uploads/1/3/4/7/134775207/tekemitumodanuw.pdf
- http://perexuwofogefo.onlinewebshop.net/el_camino_del_heroe.pdf
- https://numeroluxovuz.weebly.com/uploads/1/3/4/7/134733954/lumifinuxojaxe_senizedipisazix_bativi.pdf
- http://tigafik.mygamesonline.org/fawujezavefegujezisen.pdf
- https://s3.amazonaws.com/zagapaxa/77864574154.pdf
- https://s3.amazonaws.com/besafefaf/bunanawopafola.pdf
- http://woodbonus.net/rabixutidikisw9525.pdf
- https://cdn-cms.f-static.net/uploads/4445735/normal_60163186bb669.pdf
- https://s3.amazonaws.com/lodazojamuva/blue_eyes_technology_abstract.pdf
- http://kuliwegi.sportsontheweb.net/zafidito.pdf
- https://s3.amazonaws.com/zebarufuridorur/78673119626.pdf
- http://greyfruit.space/yasin_suresi_mp3_indir_download_dinle9rozc.pdf
- https://xefegirabiveg.weebly.com/uploads/1/3/0/9/130969499/f5695b5556.pdf
- http://7evenrp.ru/sociology_optional_for_upsc_syllabus8988p.pdf
- https://cdn-cms.f-static.net/uploads/4414678/normal_60524cd8edf66.pdf
- http://crysety.xyz/47651911209h7icm.pdf
- https://cdn-cms.f-static.net/uploads/4496826/normal_5fd70a24922f0.pdf
- http://tisawefe.rf.gd/92885589724.pdf
- http://zejuruk.rf.gd/what_major_event_occurred_in_1877.pdf
- https://s3.amazonaws.com/labitajaxatufib/grim_soul_dark_fantasy_guide.pdf
- https://cdn-cms.f-static.net/uploads/4446781/normal_601f623837007.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- nipisod.ru
- ceter.xyz
- tujezagen.weebly.com
- perexuwofogefo.onlinewebshop.net
- numeroluxovuz.weebly.com
- tigafik.mygamesonline.org
- s3.amazonaws.com
- woodbonus.net
- cdn-cms.f-static.net
- kuliwegi.sportsontheweb.net
- greyfruit.space
- xefegirabiveg.weebly.com
- 7evenrp.ru
- crysety.xyz
- www.w3.org
- purl.org
- ns.adobe.com
- wovubixagoxix.rf.gd
- tisawefe.rf.gd
- zejuruk.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report