MALICIOUS — a25eee_d9608abd5e3b4e1ea81c4218f4c21a2e.pdf
MALICIOUS — a25eee_d9608abd5e3b4e1ea81c4218f4c21a2e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ebd0ac329bc2ca37a84426c52b9035de800cd821e6b0da54853ca5bb20c2e784 - SHA-1:
48d01705f2717c4c18c0258880cb0b21c774a1f8 - MD5:
f88cd5c0011d9bcae1d7ef67f0780180 - ssdeep:
1536:aLyYUo4fFjJKZ7GW6BRgHaiU8X6jGX6ygO0YJF3vPBz2W0ukS5O5SH5uTx6N:QIFjJKwRBqHawX4i6y1xBtp5O5jTK - TLSH:
T13B38D0F3608BCD4C7A865F036DE72A6950C9D7886533EA641088776DE0BC6EEBE10512 - Submitted as: a25eee_d9608abd5e3b4e1ea81c4218f4c21a2e.pdf
- File type: pdf · Size: 80048 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F88CD5C0011D
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://30d6ba4c-d201-4e26-8f31-a0e059b28788.filesusr.com/ugd/f9b8bb_0b1cb5b60517421a968b9c3454a2bc52.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://fokemale.ru/wix?keyword=spark+plug+reading+tool, http://jejunobu.iblogger.org/the_5_minute_journal.pdf, http://zunufofidufup.rf.gd/zumiwode.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://fokemale.ru/wix?keyword=spark+plug+reading+tool
- https://s3.amazonaws.com/gusule/29919178403.pdf
- https://s3.amazonaws.com/purufiz/248234290.pdf
- http://jejunobu.iblogger.org/the_5_minute_journal.pdf
- http://zunufofidufup.rf.gd/zumiwode.pdf
- http://rumavajusugeg.rf.gd/fuzixaxukogujemigoxu.pdf
- http://mevuxuru.atwebpages.com/congenital_heart_disease_file.pdf
- http://goladelexugezi.sportsontheweb.net/thyristor_gto_francais.pdf
- https://30d6ba4c-d201-4e26-8f31-a0e059b28788.filesusr.com/ugd/f9b8bb_0b1cb5b60517421a968b9c3454a2bc52.pdf?index=true
- https://2df7536a-ab64-4dd3-a6ca-98e0eca144a4.filesusr.com/ugd/de578f_a5585bace11a41c5a34461566d9a0e50.pdf?index=true
- https://f9c380c0-3c9a-404e-8c76-a924832b335c.filesusr.com/ugd/9c8fb9_90ceaf137d9d416092094e9fabf98703.pdf?index=true
- http://wamuwosola.mygamesonline.org/godiduwajiguwizutunupis.pdf
- http://dinoxisajuz.rf.gd/66765619913.pdf
- http://tuxojemuje.rf.gd/alter_ego_2.pdf
- https://e4586023-485a-43f1-9451-2d404684c5b7.filesusr.com/ugd/95ff22_2d3d14bdae924f0d99e309f6d7ef6566.pdf?index=true
- http://mifedisiso.atwebpages.com/access_point_vs_router.pdf
- https://de99934f-f465-4d69-af5e-14f317c0a7c6.filesusr.com/ugd/4fea5c_3537a95fae7142a6b0926679e027cfce.pdf?index=true
- http://witibepav.rf.gd/cctv_ki_full_form.pdf
- https://f3dcd8e3-6656-4b47-a81e-a993d3c4f2a1.filesusr.com/ugd/aa9ef2_1325cefe350e41929afb20632db9a79f.pdf?index=true
- http://ximitexus.epizy.com/minecraft_apk_1._14._4_xbox.pdf
- http://fipelofi.22web.org/acrobat_editor_filehippo.pdf
- http://bagidopivulo.mywebcommunity.org/engg_drawing_book_download.pdf
- https://s3.amazonaws.com/fadadedezeker/3031502225.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- fokemale.ru
- s3.amazonaws.com
- jejunobu.iblogger.org
- mevuxuru.atwebpages.com
- goladelexugezi.sportsontheweb.net
- 30d6ba4c-d201-4e26-8f31-a0e059b28788.filesusr.com
- 2df7536a-ab64-4dd3-a6ca-98e0eca144a4.filesusr.com
- f9c380c0-3c9a-404e-8c76-a924832b335c.filesusr.com
- wamuwosola.mygamesonline.org
- e4586023-485a-43f1-9451-2d404684c5b7.filesusr.com
- mifedisiso.atwebpages.com
- de99934f-f465-4d69-af5e-14f317c0a7c6.filesusr.com
- f3dcd8e3-6656-4b47-a81e-a993d3c4f2a1.filesusr.com
- ximitexus.epizy.com
- fipelofi.22web.org
- bagidopivulo.mywebcommunity.org
- www.w3.org
- purl.org
- ns.adobe.com
- zunufofidufup.rf.gd
- rumavajusugeg.rf.gd
- dinoxisajuz.rf.gd
- tuxojemuje.rf.gd
- witibepav.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report