MALICIOUS — a2de88_1727a9547e60422d96c5d994c5163e32.pdf
MALICIOUS — a2de88_1727a9547e60422d96c5d994c5163e32.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ec22e17e6973cb3a928db3e789284b46415ee91e22ad1e47ec017e1c38b1313e - SHA-1:
5b5189c4595f0dd3ccf97e06b7d8f62c76d29e31 - MD5:
2775cbfeab5b681ea45c4a8b2414e08b - ssdeep:
1536:VXBwm40xLqg1Sj3Q2xc0PRWkHqznT85+sGqJgtkzTLHB9ApweyO/5OofO7k:/wm409qg10xxcmR1qzoAtezjApwey85d - TLSH:
T1CC37D0F32167ED8C7B8BDB536EAB1479948AC6486132BB90044C6B5CD87C3AE7F10614 - Submitted as: a2de88_1727a9547e60422d96c5d994c5163e32.pdf
- File type: pdf · Size: 76220 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!2775CBFEAB5B
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4460946/normal_5fc7752d5f84a.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ponafet.ru/wix?keyword=aakash+module+answers, https://2386e270-bd20-42c1-b3e5-1ba7eaa1d68d.filesusr.com/ugd/b4f0c6_f41837e570544aeeaa2f34f55564d097.pdf?index=true, http://siwosupegejolop.medianewsonline.com/75193724939.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ponafet.ru/wix?keyword=aakash+module+answers
- https://s3.amazonaws.com/neporezofov/46293322546.pdf
- https://2386e270-bd20-42c1-b3e5-1ba7eaa1d68d.filesusr.com/ugd/b4f0c6_f41837e570544aeeaa2f34f55564d097.pdf?index=true
- http://siwosupegejolop.medianewsonline.com/75193724939.pdf
- https://xaroduzorosu.weebly.com/uploads/1/3/1/3/131398324/xerazezakubovoduxat.pdf
- https://s3.amazonaws.com/mejawiwomak/69109304049.pdf
- https://votorivoxezi.weebly.com/uploads/1/3/4/0/134095847/1194419.pdf
- https://s3.amazonaws.com/xamapebonijos/83234883010.pdf
- https://s3.amazonaws.com/degagaziv/weather_report_bolingbrook_il.pdf
- http://rezexepenoma.scienceontheweb.net/as_1200.pdf
- https://4bf641bf-117a-4913-931f-55e49063997f.filesusr.com/ugd/5befcb_0a971a27d32d4f0589d65d13177cc880.pdf?index=true
- https://s3.amazonaws.com/nonabafat/essentials_of_cardiopulmonary_physical_therapy_hillegass.pdf
- https://933527c5-e005-4225-a3aa-05fee46c7696.filesusr.com/ugd/b51dd5_61de1685c9614271bae44d3681b39afe.pdf?index=true
- https://s3.amazonaws.com/zarelusipofox/carfax_damage_reported_to_front.pdf
- https://cdn-cms.f-static.net/uploads/4484169/normal_6032e12a1366a.pdf
- https://static.s123-cdn-static.com/uploads/4460946/normal_5fc7752d5f84a.pdf
- https://s3.amazonaws.com/tokafanawa/cctv_camera_installation_guide_in_tamil.pdf
- https://d04c2b29-3777-4fe6-aaa9-ab96f87c3324.filesusr.com/ugd/43eb95_e0e7e4b8bab84d169235356a58bcf36c.pdf?index=true
- http://leparitupoxow.onlinewebshop.net/32162312721.pdf
- https://cdn-cms.f-static.net/uploads/4416493/normal_5fdb7d1a510a0.pdf
- https://norotenivepele.weebly.com/uploads/1/3/4/0/134042349/zuderazizip.pdf
- https://6998e30b-c911-4113-ab34-4c15204891c7.filesusr.com/ugd/429b25_eee3620adaf44c40a90f05e780e5433e.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4379231/normal_60297daeaef93.pdf
- https://watuluvijigu.weebly.com/uploads/1/3/3/9/133997483/92f0922033860e3.pdf
- https://s3.amazonaws.com/zufaxepixiguxax/vabuzowulo.pdf
Embedded domains
- ponafet.ru
- s3.amazonaws.com
- 2386e270-bd20-42c1-b3e5-1ba7eaa1d68d.filesusr.com
- siwosupegejolop.medianewsonline.com
- xaroduzorosu.weebly.com
- votorivoxezi.weebly.com
- rezexepenoma.scienceontheweb.net
- 4bf641bf-117a-4913-931f-55e49063997f.filesusr.com
- 933527c5-e005-4225-a3aa-05fee46c7696.filesusr.com
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- d04c2b29-3777-4fe6-aaa9-ab96f87c3324.filesusr.com
- leparitupoxow.onlinewebshop.net
- norotenivepele.weebly.com
- 6998e30b-c911-4113-ab34-4c15204891c7.filesusr.com
- watuluvijigu.weebly.com
- jedunifoxawixe.weebly.com
- www.aakash.ac.in
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- f:\nw
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report