MALICIOUS — normal_601475fe4546a.pdf
MALICIOUS — normal_601475fe4546a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
daadbe9fe645ef715a159d1b8d8552952e225a4916ad66adb9afadd9a191c18d - SHA-1:
658deb5c07894f0c06887f58ed80077da6288567 - MD5:
1dfc565f4e43cfc14a5c263c00c58471 - ssdeep:
1536:9rdsu1WkpXjJg7LPMy+r71/zzu0h/56HefF0EKe3XX+dmCLE23aZw:Dp1ZjJqLPMy+l/XhwEF0FgCd3X - TLSH:
T13737D0F3711BED8C3A869F436DD210AD25DFCA482532C7A4148CBA2D84BC66E6F58D50 - Submitted as: normal_601475fe4546a.pdf
- File type: pdf · Size: 74566 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!1DFC565F4E43
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4493545/normal_5fded9694e032.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://bologen.ru/123?utm_term=asus+touchscreen+laptop+stylus, http://cosmostil.top/technics_sl_1900_preamprm2v8.pdf, https://cdn-cms.f-static.net/uploads/4411923/normal_5fd159d7ec17c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://bologen.ru/123?utm_term=asus+touchscreen+laptop+stylus
- http://cosmostil.top/technics_sl_1900_preamprm2v8.pdf
- https://cdn-cms.f-static.net/uploads/4411923/normal_5fd159d7ec17c.pdf
- https://tekeginisexufu.weebly.com/uploads/1/3/1/3/131381150/suxesuvogulate_gatutopa_nerezuzagux_bexuzovegu.pdf
- http://zelopaqq.xyz/arma_3_kp_liberation_guiderc3ax.pdf
- https://static.s123-cdn-static.com/uploads/4493545/normal_5fded9694e032.pdf
- https://static.s123-cdn-static.com/uploads/4482636/normal_6001dada37bac.pdf
- https://vemetufubejukat.weebly.com/uploads/1/3/4/3/134367776/xuzusigedituperi.pdf
- http://fukatotapi.epizy.com/past_simple_regular_verbs.pdf
- https://bexusisase.weebly.com/uploads/1/3/4/5/134596812/lakabekalusawil.pdf
- https://lafefetakizin.weebly.com/uploads/1/3/2/7/132712235/gifokijoji.pdf
- https://safasisi.weebly.com/uploads/1/3/4/4/134472516/baboto.pdf
- https://cdn-cms.f-static.net/uploads/4485946/normal_600ff15eda1f9.pdf
- https://pufokebisuniga.weebly.com/uploads/1/3/5/3/135324869/1182081.pdf
- https://pojojozujivalim.weebly.com/uploads/1/3/1/1/131164399/9809998.pdf
- https://bomejafir.weebly.com/uploads/1/3/4/7/134725936/sunaxafukafudoxito.pdf
- https://wovovude.weebly.com/uploads/1/3/1/3/131397940/3180926.pdf
- https://static.s123-cdn-static.com/uploads/4496378/normal_5fe0fc00cb236.pdf
- http://biweekamnf.com/jipeviwumelotamubitatun7o3lh.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- bologen.ru
- cosmostil.top
- cdn-cms.f-static.net
- tekeginisexufu.weebly.com
- zelopaqq.xyz
- static.s123-cdn-static.com
- vemetufubejukat.weebly.com
- fukatotapi.epizy.com
- bexusisase.weebly.com
- lafefetakizin.weebly.com
- safasisi.weebly.com
- pufokebisuniga.weebly.com
- pojojozujivalim.weebly.com
- bomejafir.weebly.com
- wovovude.weebly.com
- biweekamnf.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report