MALICIOUS — normal_604a495faab14.pdf
MALICIOUS — normal_604a495faab14.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f42a32b5ce1cb3a34c2eb124ce94727acbdbe5afcfcd6147c4f6a0c6ec98278b - SHA-1:
9e61198d9661c5407138477691e7d50d2ffb6d31 - MD5:
54a66f4c24650f9e11241a7125d3f2b9 - ssdeep:
1536:re/8zVrUjJ4A0lT2Qfw+L6ou/vkK9Lk2p+pOirz0flumWQHPtnLHq:l5c4A0h2QoNXh9LkE+0in0ssHP1W - TLSH:
T14A38D0E32087EC5CBA894B636CAA156EA149D7893173D7A260CCBA5DC47C2ED3F10841 - Submitted as: normal_604a495faab14.pdf
- File type: pdf · Size: 80641 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!54A66F4C2465
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://gejilesiwurulu.weebly.com/uploads/1/3/4/3/134374779/xobureremeledonav.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gimoguvi.ru/123?utm_term=codashop+mobile+legends, http://lidzadva.xyz/zutununuduwazuroreri6tbvz.pdf, https://dovasivenumi.weebly.com/uploads/1/3/5/9/135965427/wegarotogug.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gimoguvi.ru/123?utm_term=codashop+mobile+legends
- http://lidzadva.xyz/zutununuduwazuroreri6tbvz.pdf
- https://dovasivenumi.weebly.com/uploads/1/3/5/9/135965427/wegarotogug.pdf
- https://gejilesiwurulu.weebly.com/uploads/1/3/4/3/134374779/xobureremeledonav.pdf
- https://rupimobo.weebly.com/uploads/1/3/4/8/134891389/6227328.pdf
- https://vabuxijipureg.weebly.com/uploads/1/3/4/4/134476882/jibinemo.pdf
- https://roparinupiw.weebly.com/uploads/1/3/5/3/135392621/juvejuvafepob-nijupu-tujiduno-gulejakitur.pdf
- https://cdn-cms.f-static.net/uploads/4447270/normal_603bfada58647.pdf
- https://cdn-cms.f-static.net/uploads/4445866/normal_6018423de719b.pdf
- https://ff06b2c9-6223-4357-b4d5-1bf3807c749f.filesusr.com/ugd/717131_133bdc056f1a4e95a16836e03cc9be3e.pdf?index=true
- https://9907981b-0bc7-4fd3-a434-169f7cdadf42.filesusr.com/ugd/575363_a3bc33af21a940d09272a12fdcc24f1a.pdf?index=true
- https://puvugemamoj.weebly.com/uploads/1/3/0/9/130969199/b327e8df.pdf
- https://cdn-cms.f-static.net/uploads/4380682/normal_6022c2289aabf.pdf
- https://takadoturig.weebly.com/uploads/1/3/4/1/134108809/1293992.pdf
- https://s3.amazonaws.com/janodojivi/zulirawakuluviworesusid.pdf
- http://ideal-it.fun/22718815966597ch.pdf
- https://s3.amazonaws.com/fejenijovekozu/wekoralamodubuvewuxane.pdf
- https://bezujaseda.weebly.com/uploads/1/3/1/4/131437953/liwopaniforivafe.pdf
- https://ef9935f7-a918-44a1-999f-f1d50a45e4a7.filesusr.com/ugd/b463f2_e136a8ec74e04bd28ea2d9c67e80d58e.pdf?index=true
- https://689a2394-1721-4ce0-b6f7-af9f1dc0d621.filesusr.com/ugd/0f5b72_c894b988b2d748fdb9b601542abbaa95.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gimoguvi.ru
- lidzadva.xyz
- dovasivenumi.weebly.com
- gejilesiwurulu.weebly.com
- rupimobo.weebly.com
- vabuxijipureg.weebly.com
- roparinupiw.weebly.com
- cdn-cms.f-static.net
- ff06b2c9-6223-4357-b4d5-1bf3807c749f.filesusr.com
- 9907981b-0bc7-4fd3-a434-169f7cdadf42.filesusr.com
- puvugemamoj.weebly.com
- takadoturig.weebly.com
- s3.amazonaws.com
- ideal-it.fun
- bezujaseda.weebly.com
- ef9935f7-a918-44a1-999f-f1d50a45e4a7.filesusr.com
- 689a2394-1721-4ce0-b6f7-af9f1dc0d621.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report