MALICIOUS — c9a3b54504255e680fb950fd7008c89b9dc6a8d41068135da4f11a73029c150b
MALICIOUS — c9a3b54504255e680fb950fd7008c89b9dc6a8d41068135da4f11a73029c150b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c9a3b54504255e680fb950fd7008c89b9dc6a8d41068135da4f11a73029c150b - SHA-1:
d12019bce19cfb567d19dec9e8683d37431fcd90 - MD5:
d3a6a16326c6fbcfe674638fddcd8068 - ssdeep:
1536:b+QGof5yb5zJvKY2eYQ63sLWrjTNWeF/VvSIe0EBhpkiAzlHr0vaOIC:sof4xJvKLeYQ6dNlLpe0TiAzlHaBN - TLSH:
T11437CFF32157DC8C6B8B9B836EA319DDB0CAC2886421C750A4D5B39C84BCAED3F14915 - Submitted as: c9a3b54504255e680fb950fd7008c89b9dc6a8d41068135da4f11a73029c150b
- File type: pdf · Size: 75292 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D3A6A16326C6
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4451927/normal_603346dd7d4f9.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://medvor.ru/pbw?utm_term=ejercicios+de+razonamiento+logico+matematico+resueltos+pdf, http://lezakoliz.pbworks.com/w/file/fetch/144597234/10349717285.pdf, https://mivifasev.weebly.com/uploads/1/3/1/4/131483453/60c9bbd5a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/pbw?utm_term=ejercicios+de+razonamiento+logico+matematico+resueltos+pdf
- http://lezakoliz.pbworks.com/w/file/fetch/144597234/10349717285.pdf
- https://mivifasev.weebly.com/uploads/1/3/1/4/131483453/60c9bbd5a.pdf
- http://pijipusap.pbworks.com/w/file/fetch/144620745/what_is_solution_focused_brief_therapy_used_for.pdf
- https://cdn-cms.f-static.net/uploads/4451927/normal_603346dd7d4f9.pdf
- http://jujirafamena.pbworks.com/f/descargar_emulador_de_xbox_360_para_pc_full_espaol.pdf
- http://wufamazajo.pbworks.com/f/64251168523.pdf
- http://pibadaro.pbworks.com/w/file/fetch/144582834/flip_professional_2.4.9.39_serial_number.pdf
- https://cdn-cms.f-static.net/uploads/4489247/normal_6015b9f3e3183.pdf
- http://pifiloxema.pbworks.com/f/what_are_the_odds_of_getting_a_29_hand_in_cribbage.pdf
- http://kafunujazuwo.pbworks.com/f/34523365871.pdf
- http://niwomif.pbworks.com/w/file/fetch/144427422/o_poder_est_dentro_de_voc_louise_hay.pdf
- http://jedilukiwo.pbworks.com/f/ohio_child_support_calculator_50_50_custody.pdf
- https://cdn-cms.f-static.net/uploads/4371497/normal_60409e866271a.pdf
- https://tobevasisutigi.weebly.com/uploads/1/3/0/8/130814636/xaketego.pdf
- https://static.s123-cdn-static.com/uploads/4417808/normal_5ff0b1431e94c.pdf
- http://komogabovuwa.pbworks.com/f/star_trek_technical_manual_online.pdf
- https://bagukewedofitaf.weebly.com/uploads/1/3/4/5/134507185/fa0dd4ef.pdf
- https://kimuximufa.weebly.com/uploads/1/3/4/1/134132687/dedunates-tumemuzipu.pdf
- https://cdn-cms.f-static.net/uploads/4419198/normal_6069338ee81e7.pdf
- http://naxoxututal.pbworks.com/w/file/fetch/144444402/59698300808.pdf
- https://turuposuka.weebly.com/uploads/1/3/5/4/135400354/1378237.pdf
- https://fulinufifirop.weebly.com/uploads/1/3/4/6/134656376/jawakujuwut_pexajesek.pdf
- http://foziwedugumu.pbworks.com/f/kereneguzebuwu.pdf
- https://wabiwuwisurukim.weebly.com/uploads/1/3/2/6/132682822/3d6369b194eee.pdf
Embedded domains
- medvor.ru
- lezakoliz.pbworks.com
- mivifasev.weebly.com
- pijipusap.pbworks.com
- cdn-cms.f-static.net
- jujirafamena.pbworks.com
- wufamazajo.pbworks.com
- pibadaro.pbworks.com
- pifiloxema.pbworks.com
- kafunujazuwo.pbworks.com
- niwomif.pbworks.com
- jedilukiwo.pbworks.com
- tobevasisutigi.weebly.com
- static.s123-cdn-static.com
- komogabovuwa.pbworks.com
- bagukewedofitaf.weebly.com
- kimuximufa.weebly.com
- naxoxututal.pbworks.com
- turuposuka.weebly.com
- fulinufifirop.weebly.com
- foziwedugumu.pbworks.com
- wabiwuwisurukim.weebly.com
- fufitiruw.pbworks.com
- midevodimu.pbworks.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report