MALICIOUS — normal_60b4262a51106.pdf
MALICIOUS — normal_60b4262a51106.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cc1751e347c633cb92799d133ef00a4e8fa0daa177f98f6e470dac5b9d01415c - SHA-1:
adb52834b0c9ec88e3f3f92e7770602d28c470fc - MD5:
10ae06885d379747895b081bfac7a6fd - ssdeep:
1536:gE76yk3mZFq1GPocODpfv3bZGSvKRE/8A9/oYcGnUvZD:D76TH1GuR9GquA9/nc7V - TLSH:
T1F538E1F750ABEC8C2E4BEB832EF22199744FD2897226C7A11488766CC5BC16D3F10950 - Submitted as: normal_60b4262a51106.pdf
- File type: pdf · Size: 79978 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!10AE06885D37
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/fca63494-569f-4486-ad7d-7463b17b7386/mechanics_of_materials_beer_4th_edition_solutions.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://pelibifir.ru/123?utm_term=simple+alarm+clock+app+android+free, https://gokejaxax.weebly.com/uploads/1/3/6/0/136056436/nutafejosanunabip.pdf, https://uploads.strikinglycdn.com/files/fca63494-569f-4486-ad7d-7463b17b7386/mechanics_of_materials_beer_4th_edition_solutions.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pelibifir.ru/123?utm_term=simple+alarm+clock+app+android+free
- https://gokejaxax.weebly.com/uploads/1/3/6/0/136056436/nutafejosanunabip.pdf
- https://uploads.strikinglycdn.com/files/fca63494-569f-4486-ad7d-7463b17b7386/mechanics_of_materials_beer_4th_edition_solutions.pdf
- https://uploads.strikinglycdn.com/files/62859a77-24fd-44c6-9ec5-73a27c785f90/classification_of_antibiotics_chart.pdf
- https://gupimarozak.weebly.com/uploads/1/3/4/3/134350981/3aff2e7733.pdf
- https://uploads.strikinglycdn.com/files/a8873413-41a5-414a-b12b-9ed18a93b2d9/72328175124.pdf
- https://uploads.strikinglycdn.com/files/521fbdd1-0afc-4c86-8790-b5c68f9da468/nilelu.pdf
- https://uploads.strikinglycdn.com/files/9991fe31-b531-472c-98a5-cb3fd47ad8a9/98554376430.pdf
- https://uploads.strikinglycdn.com/files/cbcf118c-1a89-4e52-9484-72ec6c202de2/monster_girl_doctor_episode_9_dub.pdf
- https://uploads.strikinglycdn.com/files/5686e1a9-e3b2-4e41-8660-a398296eb65e/93080179169.pdf
- https://uploads.strikinglycdn.com/files/57899731-a917-4167-8a7e-47d0252466a2/88009647947.pdf
- https://uploads.strikinglycdn.com/files/0e129de7-7a65-45b1-ad50-4778fe8dc918/lista_de_verbos_irregulares_en_ingles_los_mas_usados.pdf
- https://uploads.strikinglycdn.com/files/1a4996e6-009c-4112-91b9-fd4e9296266a/4598850676.pdf
- https://uploads.strikinglycdn.com/files/045eec57-073b-47e7-ad11-19d7cee7ec11/68926168365.pdf
- https://kizofirelurok.weebly.com/uploads/1/3/1/6/131606598/5329176.pdf
- https://uploads.strikinglycdn.com/files/c5be1beb-d4bc-4a8c-82c9-d0da57567be8/the_hangover_download_in_tamilyogi.pdf
- https://uploads.strikinglycdn.com/files/b52e30ef-6e2b-4483-8114-0cc10279259c/ejercicios_futuro_simple_ingles.pdf
- https://sonadenazutimiw.weebly.com/uploads/1/3/4/6/134654654/gizutikinili-fitaxuxe.pdf
- https://waguwejulunesu.weebly.com/uploads/1/3/5/3/135301122/tolesopojabifivunab.pdf
- https://uploads.strikinglycdn.com/files/80e50331-9747-4515-8fc6-ef047a570caf/diroxesawe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- pelibifir.ru
- gokejaxax.weebly.com
- uploads.strikinglycdn.com
- gupimarozak.weebly.com
- kizofirelurok.weebly.com
- sonadenazutimiw.weebly.com
- waguwejulunesu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report