SUSPICIOUS — e5a943_8d3e3f7355074c12930f84dd2ecaa39b.pdf
SUSPICIOUS — e5a943_8d3e3f7355074c12930f84dd2ecaa39b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c35bce06d4f6b03638b26b9062b20afbad9a2068f781f82bca76a1b002f6acb5 - SHA-1:
4c7524247c779f259f46e50d9316c0d5efbf7dd0 - MD5:
c2baf57b75bebd388c7cdf60dbf92a3a - ssdeep:
1536:TURVTBuG9OnH8xdRXclOLmq4/kHRjNeVg175ufz+4/:OVduG9OcUI0SjEGufzT - TLSH:
T18A38D0F361A7CD8C7A536B03AEEB135C65D9D6802173A35188C4766D84BC0AEBF10D51 - Submitted as: e5a943_8d3e3f7355074c12930f84dd2ecaa39b.pdf
- File type: pdf · Size: 78791 bytes
- Verdict: suspicious (58/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!C2BAF57B75BE
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://6e37e838-c278-4d46-baa9-25b8497af200.filesusr.com/ugd/fbcb80_f10e5a8c52714dc9b4f1e40520ba6356.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://yafferge.ru/wix?keyword=blackweb+wireless+charger+7.5w+%2526+10w, https://cdn.sqhk.co/gotulurowav/ogijhgl/febezabonimazivowesar.pdf, http://magnitoli-2ekran.site/crypto_stocks_2020xagk1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://yafferge.ru/wix?keyword=blackweb+wireless+charger+7.5w+%2526+10w
- https://cdn.sqhk.co/gotulurowav/ogijhgl/febezabonimazivowesar.pdf
- http://magnitoli-2ekran.site/crypto_stocks_2020xagk1.pdf
- https://6e37e838-c278-4d46-baa9-25b8497af200.filesusr.com/ugd/fbcb80_f10e5a8c52714dc9b4f1e40520ba6356.pdf?index=true
- https://d23eb412-52e1-45ef-a32a-0c032022daee.filesusr.com/ugd/03485a_52dc420828264d13ac41c36de81646d7.pdf?index=true
- https://178c1879-e916-404b-9861-a2431bd0f83a.filesusr.com/ugd/1aace6_c40c0798ac6e4665a98bf362c3af226e.pdf?index=true
- https://cdn.sqhk.co/xasurila/jehbii8/snake_puzzle_ball_solution.pdf
- http://flylovel.com/karadeniz_arklar_indir_mp3g1dhw.pdf
- https://cdn-cms.f-static.net/uploads/4454971/normal_6048cae81e014.pdf
- https://18d8f76e-0bdd-4b96-b744-fee987eed1b0.filesusr.com/ugd/1486c8_7eedb79ea22f448b873a2ec2ce87c2e7.pdf?index=true
- https://cdn.sqhk.co/kutajanode/cVa0BGs/28577385796.pdf
- https://cdn.sqhk.co/gugivusofed/cgeQhfU/expel_evil_spirits_crossword_clue.pdf
- http://bcipreactivaperu.com/fulokedddogw.pdf
- https://cdn-cms.f-static.net/uploads/4473902/normal_604dc4d81e9c6.pdf
- https://88211235-bf86-4d40-a6ec-a052db2f682e.filesusr.com/ugd/94e5ef_53eb784bc47d4d14a608be88cdaef4a9.pdf?index=true
- https://cdn.sqhk.co/dirajafowevo/WifPfR6/attarintiki_daredi_movie_lo_songs.pdf
- http://rubewox.sportsontheweb.net/kojivabugas.pdf
- http://raisinsapp.club/zajusorgvq6g.pdf
- http://rozujed.sportsontheweb.net/52971868841.pdf
- http://tulifal.onlinewebshop.net/waniwojokikod.pdf
- https://ac09d6fb-20d1-47e2-97cb-2568fc137cdf.filesusr.com/ugd/03dcd4_774a27ef63b64d06bdfb866daeaac7e4.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- yafferge.ru
- cdn.sqhk.co
- magnitoli-2ekran.site
- 6e37e838-c278-4d46-baa9-25b8497af200.filesusr.com
- d23eb412-52e1-45ef-a32a-0c032022daee.filesusr.com
- 178c1879-e916-404b-9861-a2431bd0f83a.filesusr.com
- flylovel.com
- cdn-cms.f-static.net
- 18d8f76e-0bdd-4b96-b744-fee987eed1b0.filesusr.com
- bcipreactivaperu.com
- 88211235-bf86-4d40-a6ec-a052db2f682e.filesusr.com
- rubewox.sportsontheweb.net
- raisinsapp.club
- rozujed.sportsontheweb.net
- tulifal.onlinewebshop.net
- ac09d6fb-20d1-47e2-97cb-2568fc137cdf.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report