MALICIOUS — 2937315.pdf
MALICIOUS — 2937315.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d7bca67c9182f7d4c2ceac50a57b1e821336eeba81d0c56e4cd8437d3edcdf00 - SHA-1:
fb135d80593ce49e23138aa44d5231fb9ff705ee - MD5:
5c9fbe80f33408c6d68826780e3d2f5d - ssdeep:
1536:Bu8/y+3Qh+nDXROPJXJ2mdu6Kik9pVwt3H7h4aYyxeynXxwCudHT/Jv0h2g2ExRS:o8/y+hnDXRO9HbKBVsh4aYyxXnXpudHx - TLSH:
T15C38CFF7A2ABDD4C6E4F9B036EB72499588CD348B423C78491C8AA3DD4793BD6E10501 - Submitted as: 2937315.pdf
- File type: pdf · Size: 80846 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!5C9FBE80F334
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://9cc02d22-446e-415d-9686-6e49aadcb3b3.filesusr.com/ugd/aa6a08_876760e6d23a4cc59024c1b07d0ab149.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://lofupiwosilabo.epizy.com/final_fantasy_xv_royal_edition_ps4_review.pdf, https://a181bb3e-7445-4f1f-a1cf-b2fe66c13e92.filesusr.com/ugd/91ce54_8a37633f802b44328736ec3207271aef.pdf?index=true, https://cdn.sqhk.co/nowavutu/h53OIgi/sevevasi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/G1IkLG9TFNM/wb?keyword=bostitch%20f21pl2%20review
- http://lofupiwosilabo.epizy.com/final_fantasy_xv_royal_edition_ps4_review.pdf
- https://a181bb3e-7445-4f1f-a1cf-b2fe66c13e92.filesusr.com/ugd/91ce54_8a37633f802b44328736ec3207271aef.pdf?index=true
- https://cdn.sqhk.co/nowavutu/h53OIgi/sevevasi.pdf
- https://9cc02d22-446e-415d-9686-6e49aadcb3b3.filesusr.com/ugd/aa6a08_876760e6d23a4cc59024c1b07d0ab149.pdf?index=true
- http://rasudilikid.mywebcommunity.org/utmost_good_faith_in_insurance.pdf
- https://cdn.sqhk.co/vanewano/idgghhW/nimejajanolisezikeba.pdf
- https://746420f6-3007-491b-ba72-fd43be5094e5.filesusr.com/ugd/277b62_36a9782226694f17b3e4d86f99a02388.pdf?index=true
- http://mibobugaf.rf.gd/dojizokejimuwij.pdf
- http://tejovotemikodes.getenjoyment.net/a_study_on_ratio_analysis_project_report.pdf
- https://cdn-cms.f-static.net/uploads/4380883/normal_5fd7a5d1bb69d.pdf
- https://static.s123-cdn-static.com/uploads/4406782/normal_5ff5599ee65ac.pdf
- https://cdn-cms.f-static.net/uploads/4469136/normal_60581e0e10c06.pdf
- https://lulofaki.weebly.com/uploads/1/3/1/4/131453598/4184465.pdf
- http://goledipe.22web.org/different_types_of_flowers_with_pictures_and_names.pdf
- https://cdn.sqhk.co/libavesonon/Wjj2aS5/aliexpress_product_images_lts.pdf
- http://dinewegivogofe.mygamesonline.org/agricultural_marketing_channels.pdf
- http://memimusisat.getenjoyment.net/49783262455.pdf
- http://favodokoleti.mypressonline.com/i_am_malala_book_in_tamil.pdf
- https://kuwuxezito.weebly.com/uploads/1/3/6/0/136090431/bifuwurelunejofowa.pdf
- http://nofosofeze.iblogger.org/jamipegaganafujivi.pdf
- https://sipedevete.weebly.com/uploads/1/3/1/4/131438766/wovalam.pdf
- https://3d7c42e8-cad9-4196-8f3c-0f210fd97588.filesusr.com/ugd/1b7c00_7c1f280006234fd88f85e7712cfff6e9.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4456998/normal_5ff57a063835a.pdf
- https://cdn.sqhk.co/retesixabe/ijeghjh/color_taper_candles.pdf
Embedded domains
- feedproxy.google.com
- lofupiwosilabo.epizy.com
- a181bb3e-7445-4f1f-a1cf-b2fe66c13e92.filesusr.com
- cdn.sqhk.co
- 9cc02d22-446e-415d-9686-6e49aadcb3b3.filesusr.com
- rasudilikid.mywebcommunity.org
- 746420f6-3007-491b-ba72-fd43be5094e5.filesusr.com
- tejovotemikodes.getenjoyment.net
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- lulofaki.weebly.com
- goledipe.22web.org
- dinewegivogofe.mygamesonline.org
- memimusisat.getenjoyment.net
- favodokoleti.mypressonline.com
- kuwuxezito.weebly.com
- nofosofeze.iblogger.org
- sipedevete.weebly.com
- 3d7c42e8-cad9-4196-8f3c-0f210fd97588.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- mibobugaf.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report