MALICIOUS — labumurij.pdf
MALICIOUS — labumurij.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e9340d5ad517a07dea410d75b2c777db8703a2d9e3a364b923df5b1f70ddde3e - SHA-1:
dde4ec73815ccbfd84c0bc9fa95572730b34006f - MD5:
f3d71a5fa7d22c4583b8783fcc6d49f8 - ssdeep:
1536:tASnRBfup3bSVTFVaZTuJdIvZP/f8XwTvjcNgL1WtgFzv:yYRNu0VTFVaFuJivZHugBWtgp - TLSH:
T1FE37D1F3A39BDD4C778ACF5775E62825454AD3886132CA6008843D6CC97C7BE7E20941 - Submitted as: labumurij.pdf
- File type: pdf · Size: 71846 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F3D71A5FA7D2
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4377936/normal_5ff015c73c089.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://maypoin.ru/wb?keyword=the%20walking%20dead%20ps4%20game%202019, http://avto-trokot.xyz/family_feud_live_play_with_friendsgakac.pdf, http://shoes-storie.club/indian_astrology_books_in_telugufslnr.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://maypoin.ru/wb?keyword=the%20walking%20dead%20ps4%20game%202019
- http://avto-trokot.xyz/family_feud_live_play_with_friendsgakac.pdf
- http://shoes-storie.club/indian_astrology_books_in_telugufslnr.pdf
- http://filopibat.22web.org/house_renovation_budget_spreadsheet_template.pdf
- http://xadamun.epizy.com/genetics_some_of_the_basics_worksheet_answers.pdf
- https://static.s123-cdn-static.com/uploads/4377936/normal_5ff015c73c089.pdf
- http://nifiloxoburufi.rf.gd/63716314823.pdf
- https://static.s123-cdn-static.com/uploads/4366024/normal_5fe2caac78d83.pdf
- http://nisogifamesada.epizy.com/kexuvojofaroviziledu.pdf
- https://simepatu.weebly.com/uploads/1/3/4/2/134267103/36eb71d67c30182.pdf
- https://static.s123-cdn-static.com/uploads/4414680/normal_5feb8d439d6fd.pdf
- http://pakafadudu.epizy.com/love_you_good_morning_photo.pdf
- http://pititonekeget.epizy.com/aol_mail_android_authentication_failed.pdf
- https://manovofaripoluf.weebly.com/uploads/1/3/1/4/131453531/42811707e9506a.pdf
- https://zopokobo.weebly.com/uploads/1/3/1/3/131383813/7bd60469a69343.pdf
- http://shoop-ff.ru/werodofarewezekitebafuz9lw0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- maypoin.ru
- avto-trokot.xyz
- shoes-storie.club
- filopibat.22web.org
- xadamun.epizy.com
- static.s123-cdn-static.com
- nisogifamesada.epizy.com
- simepatu.weebly.com
- pakafadudu.epizy.com
- pititonekeget.epizy.com
- manovofaripoluf.weebly.com
- zopokobo.weebly.com
- shoop-ff.ru
- www.w3.org
- purl.org
- ns.adobe.com
- nifiloxoburufi.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report