MALICIOUS — lego_mindstorms_ev4_building_instructions.pdf
MALICIOUS — lego_mindstorms_ev4_building_instructions.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
f4972d56b991a99b8247e3be85c46fd63351d71fb4fb0014e09b3b0ebbf74f6f - SHA-1:
a93f8edc1c10f1c94aa1a280cba3129029771869 - MD5:
222d16330592f1466830187958d4266e - ssdeep:
1536:xAsP5S40SgtR07PY7KCA605i2Um2rmeE8S12C1AS0NZH7XcsppcI8VbFh/:CyS1Fc76WZ77R1AJZH7b8Vbf - TLSH:
T1003AD0F320D7EE4DBEC6AF03B9A6256D748CC349213657A045A8A34DC4FC5AE7E10990 - Submitted as: lego_mindstorms_ev4_building_instructions.pdf
- File type: pdf · Size: 101608 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://pelibifir.ru/strik?utm_term=lego+mindstorms+ev4+building+instructions, https://xisuludibu.weebly.com/uploads/1/3/5/3/135300694/1d8586e451327aa.pdf, https://bogigusojuvifu.weebly.com/uploads/1/3/4/3/134316749/b5fb93afe58de3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://pelibifir.ru/strik?utm_term=lego+mindstorms+ev4+building+instructions
- https://xisuludibu.weebly.com/uploads/1/3/5/3/135300694/1d8586e451327aa.pdf
- https://s3.amazonaws.com/farowug/xemipefelelekatetodiboma.pdf
- https://bogigusojuvifu.weebly.com/uploads/1/3/4/3/134316749/b5fb93afe58de3.pdf
- https://cdn-cms.f-static.net/uploads/4415756/normal_6046ef6286e2e.pdf
- https://uploads.strikinglycdn.com/files/57c90ab7-eb6b-47f9-853d-610776716a40/wineluf.pdf
- https://static.s123-cdn-static.com/uploads/4365642/normal_5fcf4a5390118.pdf
- https://mepogazab.weebly.com/uploads/1/3/4/5/134501519/niwep-mokegusapiwawa-lomexida.pdf
- https://uploads.strikinglycdn.com/files/e941a3ee-f8e1-4168-8b9c-ab1272082ea5/what_country_has_maze_runner_on_netflix.pdf
- https://s3.amazonaws.com/lezerawe/punctuation_test_multiple_choice.pdf
- https://s3.amazonaws.com/wujanozo/shunt_resistor_datasheet.pdf
- https://uploads.strikinglycdn.com/files/190092fd-8746-4b2f-abdf-745b8e759e82/88838702396.pdf
- https://fegibaja.weebly.com/uploads/1/3/4/3/134305779/53df9cb.pdf
- https://cdn-cms.f-static.net/uploads/4388041/normal_5fd90a923b8f5.pdf
- https://static.s123-cdn-static.com/uploads/4501791/normal_600123df93c62.pdf
- https://uploads.strikinglycdn.com/files/338e0402-ad2d-4397-bd22-56a4a7022381/95758671638.pdf
- https://uploads.strikinglycdn.com/files/3dab590a-a57f-4492-9414-b4110820c44b/figiselix.pdf
- https://uploads.strikinglycdn.com/files/bce41122-05c1-48fd-a38b-f43a43642666/henry_is_learning_how_to_swing_a_baseball_bat_properly.pdf
- https://cdn-cms.f-static.net/uploads/4379500/normal_602073c7891e4.pdf
- https://cdn-cms.f-static.net/uploads/4370996/normal_600c8c5d99a55.pdf
- https://s3.amazonaws.com/lososimap/lugukawawejitugaxosituzu.pdf
- https://uploads.strikinglycdn.com/files/2ba62b01-40ed-4677-a320-1c9faf2c32c3/ludikafeloxez.pdf
- https://uploads.strikinglycdn.com/files/81f13526-0496-454e-bafc-0042598f45b1/first_aid_cpr_aed_participants_manual_2019.pdf
- https://uploads.strikinglycdn.com/files/f0c8bfa5-b133-4ebd-aeda-5429b2a58c5b/cirque_du_freak_2_book.pdf
- https://static.s123-cdn-static.com/uploads/4385011/normal_5ff79c0602094.pdf
Embedded domains
- pelibifir.ru
- xisuludibu.weebly.com
- s3.amazonaws.com
- bogigusojuvifu.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- static.s123-cdn-static.com
- mepogazab.weebly.com
- fegibaja.weebly.com
- jesasifewom.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- U:\D
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report