MALICIOUS — b371d9_4a6cc632efde4d31a68efc3a74a7e1b4.pdf
MALICIOUS — b371d9_4a6cc632efde4d31a68efc3a74a7e1b4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e2e8b3ce2f329dac93f6e238f2376365b1a321fce80385d94fae62104927932b - SHA-1:
64c3a8ec8547b02dfe480ca725baab90df251bde - MD5:
76aae54c0fbbf83b4c5a6c9ffab4be9a - ssdeep:
1536:bVRGYVZ8XZ3ch/u8ZG81q2vISKOefOrpSd78CA5GtmHTwxqy7EmbKFxWb9N31gmR:Bh+W881/SNf6Mt8Cj88xFgtFY9N31gmR - TLSH:
T14638C0F32187DDCCBA8B6F1779A512997546E28C6232A7904488736CD4B4BFDEE20841 - Submitted as: b371d9_4a6cc632efde4d31a68efc3a74a7e1b4.pdf
- File type: pdf · Size: 79567 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!76AAE54C0FBB
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://f9fc249e-2e6a-4908-9eb0-88005465a50d.filesusr.com/ugd/2530ee_c2e01647737b40d8934c55729374dcf4.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://fokemale.ru/wix?keyword=ecological+footprint+worksheet+pdf, http://grinallex.shop/bisosubam00orv.pdf, http://vebuwovivulab.mygamesonline.org/concise_paediatrics.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://fokemale.ru/wix?keyword=ecological+footprint+worksheet+pdf
- http://grinallex.shop/bisosubam00orv.pdf
- http://vebuwovivulab.mygamesonline.org/concise_paediatrics.pdf
- https://f9fc249e-2e6a-4908-9eb0-88005465a50d.filesusr.com/ugd/2530ee_c2e01647737b40d8934c55729374dcf4.pdf?index=true
- https://patawera.weebly.com/uploads/1/3/4/1/134131312/5999460.pdf
- http://gagafelame.22web.org/ambari-_server_rpm.pdf
- https://sedapelagug.weebly.com/uploads/1/3/4/1/134109100/xijatijej_filakiguze_runuzevuvuno.pdf
- http://bopalinowojege.iblogger.org/how_to_report_multiple_regression_results.pdf
- http://gefosezidubajoz.scienceontheweb.net/pojusodijifujatixupafaje.pdf
- http://verafewema.rf.gd/nolipolones.pdf
- http://xokawetuvon.epizy.com/zigotuvapatopamegobifij.pdf
- https://98748e4b-3258-471a-903e-8ea98415cca0.filesusr.com/ugd/fd7405_c613e41f030a47058068ab9ac7e2b69c.pdf?index=true
- http://zisuroto.mygamesonline.org/murray_riding_lawn_mowers_near_me.pdf
- https://0c2a7d7b-be9d-4ef2-a94c-09ca905cc17d.filesusr.com/ugd/7d21c0_f56e205334424793a0d7e8b9e82e0321.pdf?index=true
- https://692937ca-140d-46b9-9715-018e108c1018.filesusr.com/ugd/2540a5_fb09a57e14e74251ba0441c846e70f7a.pdf?index=true
- https://panikelixiguju.weebly.com/uploads/1/3/4/4/134478359/sogodi.pdf
- http://in-arenas.com/home_interior_designing_colleges_in_delhipwz2i.pdf
- http://zuxekagapefe.mygamesonline.org/16851629282.pdf
- http://gazagidumow.mygamesonline.org/2763760623.pdf
- https://guwosifewutus.weebly.com/uploads/1/3/4/6/134616196/zapolovumukon.pdf
- https://litazotivov.weebly.com/uploads/1/3/0/7/130740097/jigoko.pdf
- http://digovin.getenjoyment.net/hellyeah_i_dont_care_anymore_letra_espaol.pdf
- http://gebigulexejo.sportsontheweb.net/66619834849.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- fokemale.ru
- grinallex.shop
- vebuwovivulab.mygamesonline.org
- f9fc249e-2e6a-4908-9eb0-88005465a50d.filesusr.com
- patawera.weebly.com
- gagafelame.22web.org
- sedapelagug.weebly.com
- bopalinowojege.iblogger.org
- gefosezidubajoz.scienceontheweb.net
- xokawetuvon.epizy.com
- 98748e4b-3258-471a-903e-8ea98415cca0.filesusr.com
- zisuroto.mygamesonline.org
- 0c2a7d7b-be9d-4ef2-a94c-09ca905cc17d.filesusr.com
- 692937ca-140d-46b9-9715-018e108c1018.filesusr.com
- panikelixiguju.weebly.com
- in-arenas.com
- zuxekagapefe.mygamesonline.org
- gazagidumow.mygamesonline.org
- guwosifewutus.weebly.com
- litazotivov.weebly.com
- digovin.getenjoyment.net
- gebigulexejo.sportsontheweb.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report