MALICIOUS — e32da429af465a42d980f97bf4375d851ff3d424b6614bc722474e78f9c6010f
MALICIOUS — e32da429af465a42d980f97bf4375d851ff3d424b6614bc722474e78f9c6010f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e32da429af465a42d980f97bf4375d851ff3d424b6614bc722474e78f9c6010f - SHA-1:
ddefe14c316745ac6a17c93d24d05d868cb6fdc5 - MD5:
19e49d60ad8d49bdc55566968d95ac30 - ssdeep:
1536:MLTQBZWO2vpjXUb8xGWw55C0V9XWajqXNEOdRYiwAxG:eQ0pjX4AGWw5TJOXNEZiwL - TLSH:
T10337C0F7906BDE4C678B5BC369E7259D704886C97232E3A04088775CC5BC69DAF20E11 - Submitted as: e32da429af465a42d980f97bf4375d851ff3d424b6614bc722474e78f9c6010f
- File type: pdf · Size: 76224 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!19E49D60AD8D
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://bf130ee1-1463-4c69-9604-1b23772ced92.filesusr.com/ugd/b4609a_e532745989524b0d9130ae20895e13fd.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://leonvi.ru/award?keyword=bonafide+certificate+for+scholarship+pdf, https://cdn-cms.f-static.net/uploads/4497685/normal_6013cae33a47c.pdf, https://bf130ee1-1463-4c69-9604-1b23772ced92.filesusr.com/ugd/b4609a_e532745989524b0d9130ae20895e13fd.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://leonvi.ru/award?keyword=bonafide+certificate+for+scholarship+pdf
- https://cdn-cms.f-static.net/uploads/4497685/normal_6013cae33a47c.pdf
- https://bf130ee1-1463-4c69-9604-1b23772ced92.filesusr.com/ugd/b4609a_e532745989524b0d9130ae20895e13fd.pdf?index=true
- https://cdn.sqhk.co/tamenotu/6sjjgip/international_business_machines_corporation_and_subsidiary_companies.pdf
- https://warubexe.weebly.com/uploads/1/3/4/6/134647576/0fa59b1f8415e9.pdf
- https://ecfc1f44-6648-4072-bff5-6ee4adcfbe4f.filesusr.com/ugd/e5a943_8d3e3f7355074c12930f84dd2ecaa39b.pdf?index=true
- https://cdn.sqhk.co/zivupowixede/WhdQhaE/rackword_free_real-_time_multiplayer_word_game_apps.pdf
- https://4b3b4da4-1145-40fd-8a04-0ac29766dab0.filesusr.com/ugd/6c6203_82f7821a10304eba818d3a1902bab332.pdf?index=true
- https://xijexarara.weebly.com/uploads/1/3/4/0/134017378/vefem.pdf
- https://cdn.sqhk.co/tavolimogid/Fgix90Y/81193676954.pdf
- https://cdn.sqhk.co/zezinojox/Orahjia/wars_of_the_roses_movie.pdf
- https://55d63786-14d6-44de-84d0-33f1fb383c44.filesusr.com/ugd/45fd81_e7efe72a1130486ea12d1e3bca481ce7.pdf?index=true
- https://f1fb087f-5d49-4061-aa02-230b108315d3.filesusr.com/ugd/645068_d7800109662c4c2b96309cd4ac20e59c.pdf?index=true
- https://2ddc7431-ff91-46e9-9708-195efd6cc195.filesusr.com/ugd/ffe0d3_474e9f7c3bfd4d8ab9302eebe0aaadc4.pdf?index=true
- https://kuxalureb.weebly.com/uploads/1/3/1/3/131383592/sagugive.pdf
- https://fofelopuvamugav.weebly.com/uploads/1/3/4/7/134716477/topitutetu.pdf
- https://cdn.sqhk.co/siganewita/hqNHk3S/71668830648.pdf
- https://cdn.sqhk.co/penomufepuk/jjigiSh/95824084017.pdf
- https://zipuwuxa.weebly.com/uploads/1/3/4/3/134376087/mojolijaz_fekam_pizal.pdf
- https://static.s123-cdn-static.com/uploads/4448547/normal_5ff342bdc29db.pdf
- https://cdn.sqhk.co/noxivudeva/jfibDhh/sago_mini_world_characters.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- 5n.uk
- leonvi.ru
- cdn-cms.f-static.net
- bf130ee1-1463-4c69-9604-1b23772ced92.filesusr.com
- cdn.sqhk.co
- warubexe.weebly.com
- ecfc1f44-6648-4072-bff5-6ee4adcfbe4f.filesusr.com
- 4b3b4da4-1145-40fd-8a04-0ac29766dab0.filesusr.com
- xijexarara.weebly.com
- 55d63786-14d6-44de-84d0-33f1fb383c44.filesusr.com
- f1fb087f-5d49-4061-aa02-230b108315d3.filesusr.com
- 2ddc7431-ff91-46e9-9708-195efd6cc195.filesusr.com
- kuxalureb.weebly.com
- fofelopuvamugav.weebly.com
- zipuwuxa.weebly.com
- static.s123-cdn-static.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report