MALICIOUS — interior_design_magazine_subscription_uk.pdf
MALICIOUS — interior_design_magazine_subscription_uk.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cca7284cc2cd1fecbd80011177ada0183f8fd4a6075edeafab5a2fc657ed5f70 - SHA-1:
5c37e1896c8e421b16cc7a73780da7a6d2f182ae - MD5:
3d073931d04ff1e2f91ecd5cd8b0f018 - ssdeep:
1536:Gr5ituhorJAtHd4eCGMum1NQnSczpxlzR3XfBwTFBoTsutD0zZwq5BEA:Y+AtHSzQnSczpVG3oTlYaqrL - TLSH:
T19036D0F3609FED9D7F8B5B035DAA225D65C9DBDCA032AA5004487A2DC47D6BE3E10810 - Submitted as: interior_design_magazine_subscription_uk.pdf
- File type: pdf · Size: 67096 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!3D073931D04F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://f26e6bca-ce10-4524-9610-ed5ef7c8d48b.filesusr.com/ugd/ac8c68_12e5460d49894d11a55cdcf37b2f9081.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://zajinet.ru/strik?utm_term=interior+design+magazine+subscription+uk, http://liroporuki.myartsonline.com/online_banking_services.pdf, https://f26e6bca-ce10-4524-9610-ed5ef7c8d48b.filesusr.com/ugd/ac8c68_12e5460d49894d11a55cdcf37b2f9081.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://zajinet.ru/strik?utm_term=interior+design+magazine+subscription+uk
- http://liroporuki.myartsonline.com/online_banking_services.pdf
- https://f26e6bca-ce10-4524-9610-ed5ef7c8d48b.filesusr.com/ugd/ac8c68_12e5460d49894d11a55cdcf37b2f9081.pdf?index=true
- https://cdn.sqhk.co/nipigagavadu/jijf7DG/little_foxes_spoil_the_vine_sermon.pdf
- http://wenibeliso.atwebpages.com/makalah_multimeter_analog_dan_digital.pdf
- http://bivitajuteje.mypressonline.com/super_mario_bros_nintendo_switch_2_players.pdf
- http://silujokiz.mypressonline.com/90212705323.pdf
- http://wurebosuloxu.myartsonline.com/gepelavapiwisanuvepogakem.pdf
- https://uploads.strikinglycdn.com/files/168563e7-d176-4380-b325-de7dd9f6b847/79291750971.pdf
- https://05e27880-d5e1-4d3d-8428-ba943e9300bc.filesusr.com/ugd/b56239_50b79a54daf0494c84091e7e29ea597f.pdf?index=true
- http://kulanefimolon.mypressonline.com/tutomezas.pdf
- https://c4e42e93-254c-4ba8-b495-737f84002742.filesusr.com/ugd/ddb60a_910009b4f8ef4fc78a18bf9628d06d49.pdf?index=true
- https://2571d5ef-7130-409a-b87d-c3fd18a83f30.filesusr.com/ugd/71fc55_ef4723baae974bdc8f59f5bdbcba3301.pdf?index=true
- http://zudupaxub.myartsonline.com/are_pointers_cuddly.pdf
- https://cdn.sqhk.co/sunidoxil/Vgihhhd/23657095775.pdf
- https://uploads.strikinglycdn.com/files/7310c126-7376-42e3-a3ff-2096b931c229/ifr_6000_calibration.pdf
- http://forajadafogaxuv.medianewsonline.com/steering_the_craft_epub.pdf
- https://uploads.strikinglycdn.com/files/141a4d8f-6249-4b2a-b95e-150c32efaa95/how_to_do_citations_in_google_docs.pdf
- http://jeseselanus.scienceontheweb.net/caminito_del_rey_mapa.pdf
- https://5a8aee2d-3d68-4c09-98ed-743c9c56d6fd.filesusr.com/ugd/460efe_20827f71abd24a9d9344cc31102bca39.pdf?index=true
- https://23da7c74-6e14-424a-b22a-901aa35eafb1.filesusr.com/ugd/9cc572_28c1bdc69a404ea8bc8747a50380c8cc.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- zajinet.ru
- liroporuki.myartsonline.com
- f26e6bca-ce10-4524-9610-ed5ef7c8d48b.filesusr.com
- cdn.sqhk.co
- wenibeliso.atwebpages.com
- bivitajuteje.mypressonline.com
- silujokiz.mypressonline.com
- wurebosuloxu.myartsonline.com
- uploads.strikinglycdn.com
- 05e27880-d5e1-4d3d-8428-ba943e9300bc.filesusr.com
- kulanefimolon.mypressonline.com
- c4e42e93-254c-4ba8-b495-737f84002742.filesusr.com
- 2571d5ef-7130-409a-b87d-c3fd18a83f30.filesusr.com
- zudupaxub.myartsonline.com
- forajadafogaxuv.medianewsonline.com
- jeseselanus.scienceontheweb.net
- 5a8aee2d-3d68-4c09-98ed-743c9c56d6fd.filesusr.com
- 23da7c74-6e14-424a-b22a-901aa35eafb1.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report