MALICIOUS — 3b3fbb_b9af6556f89541c49d6a530edb460b7b.pdf
MALICIOUS — 3b3fbb_b9af6556f89541c49d6a530edb460b7b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e60a26636ce4d860c6d221a5fd4d8802a6c604bc97721079c26d70eceec9ddf1 - SHA-1:
a5ff16e92d6124c4960a61919cc571b028d5d49c - MD5:
5a3f3bfc29b24896bfebcbd7b1f6bb23 - ssdeep:
3072:kz4rJpLx2n6MKz1nFDkL8HxDh7Bu/2JCDGnnOLQ:M4rJpJBFLHth9OEn1 - TLSH:
T1693AF0F36167DE9D768B5B03BCAD2059608ECB84A031DAE04449B66CC47C7BE3E15E90 - Submitted as: 3b3fbb_b9af6556f89541c49d6a530edb460b7b.pdf
- File type: pdf · Size: 99616 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4368221/normal_600779e7396b5.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://druttle.ru/wix?keyword=cisco+chapter+11+exam+answers+7.0, http://kinorio5.xyz/sivowekadebuvosafisiyj3sn.pdf, http://naturaitalia.space/xuxewisodamepadakadifvp5ot.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://druttle.ru/wix?keyword=cisco+chapter+11+exam+answers+7.0
- http://kinorio5.xyz/sivowekadebuvosafisiyj3sn.pdf
- http://naturaitalia.space/xuxewisodamepadakadifvp5ot.pdf
- http://anbieterbewertung-autoscoutch.com/bank_nifty_booksvtf22.pdf
- http://ita-bio.space/learn_how_to_sketch_for_beginners6yyx0.pdf
- http://sivopob.epizy.com/badri_audio_songs_telugu_ing.pdf
- https://static.s123-cdn-static.com/uploads/4368221/normal_600779e7396b5.pdf
- https://gefifilasi.weebly.com/uploads/1/3/0/8/130814980/sukade_gadus_nitiripuputin.pdf
- http://organicsss.space/wekabolewuganugabafeust53.pdf
- http://shop-onlain.fun/53910899095xkgno.pdf
- https://jikumuwalomaj.weebly.com/uploads/1/3/1/3/131383204/b161235bdf6.pdf
- https://funotagikaxu.weebly.com/uploads/1/3/1/8/131857914/rokopazutav.pdf
- http://dazefoxezizu.iblogger.org/difojibumusafirer.pdf
- https://cdn-cms.f-static.net/uploads/4414679/normal_602183f04c0f6.pdf
- http://onlineeshop24.xyz/neil_gaiman_american_gods_free_do4lvs.pdf
- http://homebig.space/73611909228unspp.pdf
- https://rubosesizip.weebly.com/uploads/1/3/4/7/134744628/7464a3223d4eb8.pdf
- http://cccckkkkkdd.space/pufejezumg45r2.pdf
- https://cdn-cms.f-static.net/uploads/4367289/normal_6027a642db781.pdf
- https://nolutoxut.weebly.com/uploads/1/3/4/6/134683805/3964817.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- druttle.ru
- kinorio5.xyz
- naturaitalia.space
- anbieterbewertung-autoscoutch.com
- ita-bio.space
- sivopob.epizy.com
- static.s123-cdn-static.com
- gefifilasi.weebly.com
- organicsss.space
- shop-onlain.fun
- jikumuwalomaj.weebly.com
- funotagikaxu.weebly.com
- dazefoxezizu.iblogger.org
- cdn-cms.f-static.net
- onlineeshop24.xyz
- homebig.space
- rubosesizip.weebly.com
- cccckkkkkdd.space
- nolutoxut.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report