MALICIOUS — f0f37b3215622451d3a41d60285d5fbaf9a0a1d05d2eca959edadcc19263853b
MALICIOUS — f0f37b3215622451d3a41d60285d5fbaf9a0a1d05d2eca959edadcc19263853b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 6 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f0f37b3215622451d3a41d60285d5fbaf9a0a1d05d2eca959edadcc19263853b - SHA-1:
05c0693b33c0a10861cb5be543056f3c526144ca - MD5:
f863e4fb7267abe5613da0f853196a6e - ssdeep:
1536:dF6cyz0LPYRmsLrlQe3Z+mX54HbymYQRDeNKXe:H6ctLPYrCe3ozbymYYSNz - TLSH:
T1C938D0F361A3EC8C6A8A6B8379B2162D7099C35435366B60548D776CC07C6BD7F20E02 - Submitted as: f0f37b3215622451d3a41d60285d5fbaf9a0a1d05d2eca959edadcc19263853b
- File type: pdf · Size: 78264 bytes
- Verdict: malicious (94/100)
Detections (6 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F863E4FB7267
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://9cf93ecd-64ee-4ad6-afcc-f350577a7522.filesusr.com/ugd/c4dbd3_8f33340f20e343c79948034bdb1f6519.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://seumenha.ru/strik?utm_term=un+curso+de+milagros+leccion+277, http://moneymaya.site/45884877511rksst.pdf, http://tuwozarawipuzi.rf.gd/35010476395.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://seumenha.ru/strik?utm_term=un+curso+de+milagros+leccion+277
- http://moneymaya.site/45884877511rksst.pdf
- http://tuwozarawipuzi.rf.gd/35010476395.pdf
- http://daimontimur.org/rhythm_engineering_chennai8hpn3.pdf
- https://9cf93ecd-64ee-4ad6-afcc-f350577a7522.filesusr.com/ugd/c4dbd3_8f33340f20e343c79948034bdb1f6519.pdf?index=true
- https://f45985d3-969e-4a4b-a16b-f92b7c881388.filesusr.com/ugd/20da2d_d45fd694edfe4304b08c843f3947be97.pdf?index=true
- https://delazodudiz.weebly.com/uploads/1/3/4/5/134591817/vobule.pdf
- http://tojipipawerar.22web.org/karevogasoxofe.pdf
- http://inmyshtangen.xyz/wowosiboxonunomajpb8ff.pdf
- http://casserlabs.xyz/37776798442t6pj6.pdf
- https://8137cd1e-393d-4948-8193-eca935452849.filesusr.com/ugd/756799_b5b055c1eedb4be2842fcff29f1b0487.pdf?index=true
- http://trudogoliya.online/life_and_books_and_everything_season_2b4u20.pdf
- https://3fb740b9-71d8-4183-8edb-de11b68c0a29.filesusr.com/ugd/1fbf8b_5927cb1893fc47829171ebd5eee31787.pdf?index=true
- https://39dd5e1d-a581-41ec-a80f-9e19245c660f.filesusr.com/ugd/c2656d_33e4b127d7aa433daa3050fbb502080c.pdf?index=true
- https://d4f4546a-a836-4b3d-8651-c56b89608eca.filesusr.com/ugd/3e9e83_f80864c75af04a6cae927940970380e5.pdf?index=true
- http://uscreditmonitoring.info/35021372971q3egb.pdf
- https://pizopivawot.weebly.com/uploads/1/3/5/3/135347149/1cefdc7.pdf
- http://inmyshtangen.xyz/student_led_conference_reflection_sheetqos7p.pdf
- https://71a0d42b-91d5-4e94-9338-ff69ca8a624b.filesusr.com/ugd/e5d5e5_9f1f1dc58089472e9280282dded78ab1.pdf?index=true
- https://45b0b119-5f8c-43e7-b437-4e12d17c1c81.filesusr.com/ugd/3826db_6e981ee590674996a530abd00bbe553e.pdf?index=true
- http://idealicaitaly-ufficiale.site/gusezaguskpkv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- seumenha.ru
- moneymaya.site
- daimontimur.org
- 9cf93ecd-64ee-4ad6-afcc-f350577a7522.filesusr.com
- f45985d3-969e-4a4b-a16b-f92b7c881388.filesusr.com
- delazodudiz.weebly.com
- tojipipawerar.22web.org
- inmyshtangen.xyz
- casserlabs.xyz
- 8137cd1e-393d-4948-8193-eca935452849.filesusr.com
- trudogoliya.online
- 3fb740b9-71d8-4183-8edb-de11b68c0a29.filesusr.com
- 39dd5e1d-a581-41ec-a80f-9e19245c660f.filesusr.com
- d4f4546a-a836-4b3d-8651-c56b89608eca.filesusr.com
- uscreditmonitoring.info
- pizopivawot.weebly.com
- 71a0d42b-91d5-4e94-9338-ff69ca8a624b.filesusr.com
- 45b0b119-5f8c-43e7-b437-4e12d17c1c81.filesusr.com
- idealicaitaly-ufficiale.site
- www.w3.org
- purl.org
- ns.adobe.com
- tuwozarawipuzi.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report