MALICIOUS — 2540a5_03c6b33a7a5b4f97a2388dd1a346db84.pdf
MALICIOUS — 2540a5_03c6b33a7a5b4f97a2388dd1a346db84.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cf2b1cec40172495bc8752291545906689ad2eb865d8744821749b680275d385 - SHA-1:
0690eb252fc984fab6a2f5774414caa94078bffa - MD5:
79839e31d074ed0caa58a088029ef011 - ssdeep:
1536:6Qo6E11eyRtS+tI/oPqDX9Tn6Hfki/G5un2ms/lUObxD+rifPK2fkNCHi:z/t+IoPctT0cAqun2ms/lUOVoifPK24Z - TLSH:
T17638D0F36187DDCC668A9F477DA7256EA1CAE3492021D7904848B7ACD4BC1FE6F90210 - Submitted as: 2540a5_03c6b33a7a5b4f97a2388dd1a346db84.pdf
- File type: pdf · Size: 82688 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!79839E31D074
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://041aa876-b65b-432c-96c0-58c8b295a4e4.filesusr.com/ugd/90d19e_acd0e77b024a4c1c8640daf14d08d620.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://nipisod.ru/wix?keyword=precalculus+piecewise+functions+worksheet, http://wenares.myartsonline.com/best_books_on_female_led_relationships.pdf, http://pevuzimoba.rf.gd/what_does_calorie_deficit_mean_on_fitbit.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nipisod.ru/wix?keyword=precalculus+piecewise+functions+worksheet
- http://wenares.myartsonline.com/best_books_on_female_led_relationships.pdf
- http://pevuzimoba.rf.gd/what_does_calorie_deficit_mean_on_fitbit.pdf
- http://damusoborubumo.epizy.com/ansys_workbench_14._5.pdf
- http://xofenejilomoz.iblogger.org/formas_normales_base_de_datos_ejemplos.pdf
- https://041aa876-b65b-432c-96c0-58c8b295a4e4.filesusr.com/ugd/90d19e_acd0e77b024a4c1c8640daf14d08d620.pdf?index=true
- https://da89e6ec-52f9-4c28-8de8-447a2e923c0c.filesusr.com/ugd/5e5b2a_cc4fa474a6a84d6fb20aaf3549ad6b80.pdf?index=true
- https://7e8267f5-6380-480e-ad72-df526eaefc07.filesusr.com/ugd/cbe325_f18ff8e9ace945a8b01b66637dc64300.pdf?index=true
- http://wiraxoxepopiret.rf.gd/countable_and_uncountable_nouns_worksheet_grade_4.pdf
- https://11627308-8c8f-4f08-99ed-0ad85160907d.filesusr.com/ugd/682d1c_42d0e3ae950941e8be1c2f095e4392d9.pdf?index=true
- http://pagefufobixew.22web.org/agreement_contract_letter_template.pdf
- https://cdn.sqhk.co/vozogekom/3egFjb5/lonopapoduxikudox.pdf
- https://vinenuji.weebly.com/uploads/1/3/1/4/131453259/wozovoro.pdf
- http://warofonatar.iblogger.org/nodikopagukufirijidusabuz.pdf
- https://besukobar.weebly.com/uploads/1/3/1/0/131069863/3846300.pdf
- http://fakesux.epizy.com/hypnosis_and_accelerated_learning_free_download.pdf
- http://wovuluvoju.onlinewebshop.net/is_chi_a_good_brand_shampoo.pdf
- http://ferenekukosazu.epizy.com/veremela.pdf
- https://joverukaded.weebly.com/uploads/1/3/4/4/134433057/baxofutelip.pdf
- https://cdn.sqhk.co/zumedizojas/jpjTihA/90713583336.pdf
- https://cdn.sqhk.co/kutajanode/RbsJVhh/wulivike.pdf
- https://ac3db616-04cb-40f1-8357-c67041f5e20c.filesusr.com/ugd/eda9ba_6e78a946d71546339fcc1afe5cd2cf8c.pdf?index=true
- http://goxulotevixoda.rf.gd/large_iced_coffee_dunkin_donuts_nutrition.pdf
- http://bavatesivo.myartsonline.com/pinorebi.pdf
- https://cdn.sqhk.co/nuditufu/7ijgggb/81829373378.pdf
Embedded domains
- nipisod.ru
- wenares.myartsonline.com
- damusoborubumo.epizy.com
- xofenejilomoz.iblogger.org
- 041aa876-b65b-432c-96c0-58c8b295a4e4.filesusr.com
- da89e6ec-52f9-4c28-8de8-447a2e923c0c.filesusr.com
- 7e8267f5-6380-480e-ad72-df526eaefc07.filesusr.com
- 11627308-8c8f-4f08-99ed-0ad85160907d.filesusr.com
- pagefufobixew.22web.org
- cdn.sqhk.co
- vinenuji.weebly.com
- warofonatar.iblogger.org
- besukobar.weebly.com
- fakesux.epizy.com
- wovuluvoju.onlinewebshop.net
- ferenekukosazu.epizy.com
- joverukaded.weebly.com
- ac3db616-04cb-40f1-8357-c67041f5e20c.filesusr.com
- bavatesivo.myartsonline.com
- xutezanepone.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- pevuzimoba.rf.gd
- wiraxoxepopiret.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report