MALICIOUS — how_to_start_my_own_baking_business_from_home.pdf
MALICIOUS — how_to_start_my_own_baking_business_from_home.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f80553883623b15b7858c4ebf9b616344bffe9c3a58a0935e4083238b34b765d - SHA-1:
e4fa13548f7618dd603e9f5fe67abc285b95af6f - MD5:
44ee79655e29628d1784c8fe5e3aee63 - ssdeep:
1536:VKH0Jiu/TtQPg6alizqHG2nPjZ6qjnR5764/7Hdwu286ZIc:wyLtQ2Az10LZ6qd5m4jHek6B - TLSH:
T18638D0B35087CC8DBB8B9B8B9D9A55AC75CEC38C76329EA145C8F61DC17C29E6D10800 - Submitted as: how_to_start_my_own_baking_business_from_home.pdf
- File type: pdf · Size: 76826 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!44EE79655E29
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://6f81cef9-66a2-447d-9e1d-4c0427ef15c5.filesusr.com/ugd/4d935e_e00a14eb5b904a2fb2b6d2946a9767b7.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://nipisod.ru/strik?utm_term=how+to+start+my+own+baking+business+from+home, http://sewukagazub.mypressonline.com/jelipitujumelegamivomi.pdf, http://neletaparufo.scienceontheweb.net/cavalier_poetry.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nipisod.ru/strik?utm_term=how+to+start+my+own+baking+business+from+home
- http://sewukagazub.mypressonline.com/jelipitujumelegamivomi.pdf
- http://neletaparufo.scienceontheweb.net/cavalier_poetry.pdf
- https://cdn-cms.f-static.net/uploads/4366351/normal_6065256a7a920.pdf
- http://teluroluxeterez.myartsonline.com/input_buffering_in_lexical_analysis.pdf
- https://kivalake.weebly.com/uploads/1/3/4/8/134885121/fumupel.pdf
- https://naketutetan.weebly.com/uploads/1/3/4/6/134660231/nomivesenexe_dugemelixuj_kerela_dadujem.pdf
- https://cdn-cms.f-static.net/uploads/4368964/normal_6034431c83fc6.pdf
- http://fojupejededoto.epizy.com/38094217813.pdf
- https://6f81cef9-66a2-447d-9e1d-4c0427ef15c5.filesusr.com/ugd/4d935e_e00a14eb5b904a2fb2b6d2946a9767b7.pdf?index=true
- http://mopepuveg.epizy.com/35326542859.pdf
- http://vegofejolafud.mygamesonline.org/65516249922.pdf
- https://7d6e376e-1ee3-4df5-88c1-8d1511d419f8.filesusr.com/ugd/7dd30d_ba76493bb78743aa86eb35d8d4af9d03.pdf?index=true
- http://gateguka.epizy.com/24566718981.pdf
- http://sewemira.atwebpages.com/dibob.pdf
- http://tufigeburevizi.epizy.com/fiwulezor.pdf
- https://vizexetu.weebly.com/uploads/1/3/4/8/134864552/kusali.pdf
- http://fejiximodanu.mygamesonline.org/bbc_compacta_class_11_english_answers.pdf
- https://6a24fdd2-d4a5-4c4b-882b-0f3115751bcf.filesusr.com/ugd/04e6f9_7be36b3d557b422a95eea273e6d87be3.pdf?index=true
- http://turojupa.epizy.com/nist_risk_management_framework.pdf
- http://vozajomaralamer.mygamesonline.org/ain_t_them_bodies_saints_script.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- nipisod.ru
- sewukagazub.mypressonline.com
- neletaparufo.scienceontheweb.net
- cdn-cms.f-static.net
- teluroluxeterez.myartsonline.com
- kivalake.weebly.com
- naketutetan.weebly.com
- fojupejededoto.epizy.com
- 6f81cef9-66a2-447d-9e1d-4c0427ef15c5.filesusr.com
- mopepuveg.epizy.com
- vegofejolafud.mygamesonline.org
- 7d6e376e-1ee3-4df5-88c1-8d1511d419f8.filesusr.com
- gateguka.epizy.com
- sewemira.atwebpages.com
- tufigeburevizi.epizy.com
- vizexetu.weebly.com
- fejiximodanu.mygamesonline.org
- 6a24fdd2-d4a5-4c4b-882b-0f3115751bcf.filesusr.com
- turojupa.epizy.com
- vozajomaralamer.mygamesonline.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report