MALICIOUS — c987d9dc38054cbaa5d4868d12d952c81dbaf9e15b661da816669371a96407ad
MALICIOUS — c987d9dc38054cbaa5d4868d12d952c81dbaf9e15b661da816669371a96407ad is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c987d9dc38054cbaa5d4868d12d952c81dbaf9e15b661da816669371a96407ad - SHA-1:
4a507ec3f77cd99e9d4fbbe43976a40cf7746f75 - MD5:
c67a762ad5ef4fc02d9c4d1adaba21fd - ssdeep:
1536:mBnZUtojFIcfFYTLxZDvSvyeEZtA3MUXbBA2cXZ5L7Wgb4ycIYy/bshiDx:2UGj8b+vktoMO62+5LTbMI//IC - TLSH:
T17439C0F35487CC8CB6CEAF435DF62259518BD68862739BA04484EA7CC46CAAC7D60E10 - Submitted as: c987d9dc38054cbaa5d4868d12d952c81dbaf9e15b661da816669371a96407ad
- File type: pdf · Size: 85956 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!C67A762AD5EF
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://1a447ccf-a6a5-490c-ad31-399ae8169532.filesusr.com/ugd/cf5184_818bf06630e044c89c011161cb9e4841.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://dugedepap.ru/strik?utm_term=how+to+fix+a+frigidaire+refrigerator+ice+maker, https://1a447ccf-a6a5-490c-ad31-399ae8169532.filesusr.com/ugd/cf5184_818bf06630e044c89c011161cb9e4841.pdf?index=true, https://7095e710-59ac-4d27-8a5a-f3bbcaf65deb.filesusr.com/ugd/418e76_97687b046873427ab0e4a2111f34e281.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://dugedepap.ru/strik?utm_term=how+to+fix+a+frigidaire+refrigerator+ice+maker
- https://1a447ccf-a6a5-490c-ad31-399ae8169532.filesusr.com/ugd/cf5184_818bf06630e044c89c011161cb9e4841.pdf?index=true
- https://7095e710-59ac-4d27-8a5a-f3bbcaf65deb.filesusr.com/ugd/418e76_97687b046873427ab0e4a2111f34e281.pdf?index=true
- https://e50eee24-2d95-422d-8083-6f618d95927b.filesusr.com/ugd/594ae5_7e019e37aadc43c9ad040a5550a82ad0.pdf?index=true
- https://f4ef19d8-372f-49db-bbb6-0f5e16bfa625.filesusr.com/ugd/070799_0654fc2507e84e4e875c27e12dfbe60c.pdf?index=true
- https://77701ba7-c5ad-4750-ab17-5b03548f7fc0.filesusr.com/ugd/9a242c_27430c4b3a4346aeabca7eaaddb3292b.pdf?index=true
- https://d21da297-2d1c-4020-882f-059d99c29dc9.filesusr.com/ugd/3724a2_bb22392903a24d38aa4df53b904a9d18.pdf?index=true
- https://1b6fbac1-9b66-4609-9151-81f5d4c316f7.filesusr.com/ugd/5e81b9_b4839a79805d4dbab7e90e21617d8845.pdf?index=true
- https://2ad55d82-15d9-4995-b72c-f03dca93b5f4.filesusr.com/ugd/11b7eb_1335270460f446a8a3503d676e83a9f5.pdf?index=true
- https://86a6be6f-1c3f-48a2-98e5-8a654ddc1212.filesusr.com/ugd/027f51_11ce916881d446c988d026a188554e09.pdf?index=true
- https://6afed14e-2b01-442b-8c2e-11a8a6f39965.filesusr.com/ugd/46a5ae_d3cfd6359c354520a53897c7c1e3c985.pdf?index=true
- https://f4b9ed98-44c1-44e6-9966-d9817cd43de7.filesusr.com/ugd/9ced5d_d33346f3f577430f8347bc9f4f1fb58e.pdf?index=true
- http://yourlivehelp.com/what_is_the_base_rate_in_psychologyckasp.pdf
- http://wegamaluperetuj.atwebpages.com/55575153921.pdf
- http://mepitar.atwebpages.com/entrepreneur_books_free.pdf
- https://64f3f273-fd79-4cea-bc15-92b2431614e2.filesusr.com/ugd/542254_6df0ce3b30b84485a20b21001db1b2b8.pdf?index=true
- https://d1897088-ef6e-4b60-8303-910b4b551fc1.filesusr.com/ugd/4cfbbd_9263cc9f66094cafa7a30d1b24813e34.pdf?index=true
- https://88749095-6fd7-453f-8e8a-15b48fe47dd1.filesusr.com/ugd/e4d7df_da55eb3e996c4ebfa0d9afdab9aea8b4.pdf?index=true
- http://bizedesaxifu.onlinewebshop.net/jakaxutomimofivomonukite.pdf
- https://dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com/ugd/0ebc1f_19e440e19d3541669e7fe64244c6ea05.pdf?index=true
- https://6d706a39-1f93-4f1a-9423-caccf7e65e71.filesusr.com/ugd/69f91f_57ad6d10526b470981a3010fba85afde.pdf?index=true
- http://ig-copyrightnoticehelp.com/abbacchio_joins_the_kicking_meme_templatepzhag.pdf
- http://sajiwurejedetu.sportsontheweb.net/60853696313.pdf
- https://cb47f074-0476-4434-b381-5672a365cab8.filesusr.com/ugd/c46c8a_42db2169f6674b0f952ea3e00408e697.pdf?index=true
- https://667abc8f-92ca-45d9-bc9d-789c80a68858.filesusr.com/ugd/dcd78f_5d5137aa755a4a47bdd60501ee7518f5.pdf?index=true
Embedded domains
- dugedepap.ru
- 1a447ccf-a6a5-490c-ad31-399ae8169532.filesusr.com
- 7095e710-59ac-4d27-8a5a-f3bbcaf65deb.filesusr.com
- e50eee24-2d95-422d-8083-6f618d95927b.filesusr.com
- f4ef19d8-372f-49db-bbb6-0f5e16bfa625.filesusr.com
- 77701ba7-c5ad-4750-ab17-5b03548f7fc0.filesusr.com
- d21da297-2d1c-4020-882f-059d99c29dc9.filesusr.com
- 1b6fbac1-9b66-4609-9151-81f5d4c316f7.filesusr.com
- 2ad55d82-15d9-4995-b72c-f03dca93b5f4.filesusr.com
- 86a6be6f-1c3f-48a2-98e5-8a654ddc1212.filesusr.com
- 6afed14e-2b01-442b-8c2e-11a8a6f39965.filesusr.com
- f4b9ed98-44c1-44e6-9966-d9817cd43de7.filesusr.com
- yourlivehelp.com
- wegamaluperetuj.atwebpages.com
- mepitar.atwebpages.com
- 64f3f273-fd79-4cea-bc15-92b2431614e2.filesusr.com
- d1897088-ef6e-4b60-8303-910b4b551fc1.filesusr.com
- 88749095-6fd7-453f-8e8a-15b48fe47dd1.filesusr.com
- bizedesaxifu.onlinewebshop.net
- dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com
- 6d706a39-1f93-4f1a-9423-caccf7e65e71.filesusr.com
- ig-copyrightnoticehelp.com
- sajiwurejedetu.sportsontheweb.net
- cb47f074-0476-4434-b381-5672a365cab8.filesusr.com
- 667abc8f-92ca-45d9-bc9d-789c80a68858.filesusr.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report