MALICIOUS — 429b25_7ce31c364824410695110ea3297adade.pdf
MALICIOUS — 429b25_7ce31c364824410695110ea3297adade.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f697c4bd3a7d991ead72032eabe20b5c1a6408bf1a3b969aea7d8d933212e8be - SHA-1:
1375a9b1acd4cb4de087d5e76aac820a49c01f60 - MD5:
c4a8f978aadb257250453484f8308cc5 - ssdeep:
1536:ywVOIsIJJ2+ozfvbPSYqrv51CQDTmZLFlnnPDU6KdR83p4skFufqJP:HcIJ9wWrrv6QY2/R83o4f6 - TLSH:
T17038C0F760D7CC8C7BCFAF439DAB152A9499D7896431DB50448473ACC4AC7AE2E20660 - Submitted as: 429b25_7ce31c364824410695110ea3297adade.pdf
- File type: pdf · Size: 81374 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!C4A8F978AADB
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://c4bedd8b-a3e9-4aa8-9751-a6fde4035b7e.filesusr.com/ugd/037f08_186bde12df0d475ba441f9affead090a.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://dafemum.ru/wix?keyword=knight+orc+assault+hacked+unblocked, https://cdn-cms.f-static.net/uploads/4454984/normal_60304cef5879e.pdf, http://byseles.xyz/autumn_leaves_chet_baker_sheet_music_piano7bjp1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://dafemum.ru/wix?keyword=knight+orc+assault+hacked+unblocked
- https://s3.amazonaws.com/sagotomagin/free_html_templates_for_resume.pdf
- https://cdn-cms.f-static.net/uploads/4454984/normal_60304cef5879e.pdf
- http://byseles.xyz/autumn_leaves_chet_baker_sheet_music_piano7bjp1.pdf
- https://c4bedd8b-a3e9-4aa8-9751-a6fde4035b7e.filesusr.com/ugd/037f08_186bde12df0d475ba441f9affead090a.pdf?index=true
- http://autolombardpro.ru/62948240080a6ffg.pdf
- https://cdn-cms.f-static.net/uploads/4380857/normal_600e05bbe5754.pdf
- http://pomumafa.rf.gd/4496256584.pdf
- http://nekoraxevab.rf.gd/telescope_reviews_consumer_reports.pdf
- http://jetolad.iblogger.org/avid_media_composer_windows_10.pdf
- https://cdn-cms.f-static.net/uploads/4457620/normal_6032e16a73de7.pdf
- https://6d428a25-da86-44fa-8f13-5b0f09742281.filesusr.com/ugd/3649d2_11201842e77e4c589ec2dbdf3e7ca477.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4407729/normal_5fcace216a993.pdf
- https://f770b3d7-c897-40e0-9323-5ad0abd91552.filesusr.com/ugd/1fa6dd_ecaf2eeff2ee4ae88872a000f5170267.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4451045/normal_5fd92ebf9e7ec.pdf
- https://static.s123-cdn-static.com/uploads/4450421/normal_5fe396909f19b.pdf
- https://s3.amazonaws.com/pibajuwi/complete_sentences_worksheets_8th_grade.pdf
- https://static.s123-cdn-static.com/uploads/4501364/normal_6003a861be4d3.pdf
- http://funseeds.site/wikitoretejoxapimalo0tffg.pdf
- http://pavinudoj.epizy.com/how_much_are_howard_miller_clocks_worth.pdf
- http://notdull-eng.online/the_challenger_sale_summary_by_chapternnbxw.pdf
- http://rumapipenuwiwo.rf.gd/labumudig.pdf
- https://s3.amazonaws.com/tazibabebamep/conditional_format_google_sheets_date.pdf
- https://static.s123-cdn-static.com/uploads/4408483/normal_5fe0895133e15.pdf
- https://cdn-cms.f-static.net/uploads/4451021/normal_601a29bf7c965.pdf
Embedded domains
- dafemum.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- byseles.xyz
- c4bedd8b-a3e9-4aa8-9751-a6fde4035b7e.filesusr.com
- autolombardpro.ru
- jetolad.iblogger.org
- 6d428a25-da86-44fa-8f13-5b0f09742281.filesusr.com
- static.s123-cdn-static.com
- f770b3d7-c897-40e0-9323-5ad0abd91552.filesusr.com
- funseeds.site
- pavinudoj.epizy.com
- notdull-eng.online
- www.w3.org
- purl.org
- ns.adobe.com
- pomumafa.rf.gd
- nekoraxevab.rf.gd
- rumapipenuwiwo.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report