MALICIOUS — f986d41f8ce5988125aa95deea7c038c22535a97608bd9baac34e2a4d9e58567
MALICIOUS — f986d41f8ce5988125aa95deea7c038c22535a97608bd9baac34e2a4d9e58567 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f986d41f8ce5988125aa95deea7c038c22535a97608bd9baac34e2a4d9e58567 - SHA-1:
b090322eb15de4b2707d73937f9b1a13b72313e3 - MD5:
9a3c275797266be48e6f5c2da9a75999 - ssdeep:
1536:NxQcZQOk8Y466skLwgzH9LxRAI41wmPG1wHl6iFjfrFxcOu:vQczd4aL51H31msGr3cOu - TLSH:
T11436D0E3404BDE4CBB4F8F037E775796948DC7881A6EA651204CA36994ECA6E7C20D42 - Submitted as: f986d41f8ce5988125aa95deea7c038c22535a97608bd9baac34e2a4d9e58567
- File type: pdf · Size: 65536 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Trellix Stinger (McAfee): PDF/Phish-FAB!9A3C27579726
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://suzoniku.weebly.com/uploads/1/3/4/4/134456843/powugojaliremiso.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://jacksth.ru/123?utm_term=happy+birthday+bhai+status+video, http://wixudes.pbworks.com/f/masajozasos.pdf, https://suzoniku.weebly.com/uploads/1/3/4/4/134456843/powugojaliremiso.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/123?utm_term=happy+birthday+bhai+status+video
- http://wixudes.pbworks.com/f/masajozasos.pdf
- https://suzoniku.weebly.com/uploads/1/3/4/4/134456843/powugojaliremiso.pdf
- http://bulafiko.pbworks.com/w/file/fetch/145249809/sbg6580_bridge_mode.pdf
- https://vibusipapomokij.weebly.com/uploads/1/3/2/6/132682711/xaxagurigufaxebunu.pdf
- http://zizovitunex.pbworks.com/w/file/fetch/144518637/kosajosuzolinurixelun.pdf
- https://cdn-cms.f-static.net/uploads/4483873/normal_60562b0621877.pdf
- https://cdn-cms.f-static.net/uploads/4415081/normal_60634b97b8999.pdf
- https://nonovobuzodeku.weebly.com/uploads/1/3/5/3/135348203/672627.pdf
- https://cdn-cms.f-static.net/uploads/4487413/normal_6028e98f5649b.pdf
- http://lijunew.pbworks.com/w/file/fetch/145025823/48047769413.pdf
- http://fodorafirig.pbworks.com/f/28081975546.pdf
- http://wigonewakil.pbworks.com/w/file/fetch/145195830/firemabasenazipoxusumozez.pdf
- http://togiwuvoze.pbworks.com/f/how_to_fatten_up_a_cow_for_slaughter.pdf
- https://static.s123-cdn-static.com/uploads/4489033/normal_5fec6818df146.pdf
- http://gulisapil.pbworks.com/f/85204739045.pdf
- http://tujelupirobe.pbworks.com/f/zatuwizagej.pdf
- https://lolosovosozo.weebly.com/uploads/1/3/4/8/134882251/votawod.pdf
- http://milatufed.pbworks.com/w/file/fetch/144776352/99284705040.pdf
- https://mabajiluvepe.weebly.com/uploads/1/3/1/4/131409333/f9045913fe0.pdf
- https://wosubazaroden.weebly.com/uploads/1/3/0/8/130813518/bemipogosivufitig.pdf
- http://vogivakazela.pbworks.com/f/nuvabumobi.pdf
- https://cdn-cms.f-static.net/uploads/4493602/normal_6043101565bb1.pdf
- https://sozatugija.weebly.com/uploads/1/3/4/8/134859818/kelobogadod-wanudu-juxubizax-morem.pdf
- https://gevofiku.weebly.com/uploads/1/3/4/7/134759045/febogizug.pdf
Embedded domains
- jacksth.ru
- wixudes.pbworks.com
- suzoniku.weebly.com
- bulafiko.pbworks.com
- vibusipapomokij.weebly.com
- zizovitunex.pbworks.com
- cdn-cms.f-static.net
- nonovobuzodeku.weebly.com
- lijunew.pbworks.com
- fodorafirig.pbworks.com
- wigonewakil.pbworks.com
- togiwuvoze.pbworks.com
- static.s123-cdn-static.com
- gulisapil.pbworks.com
- tujelupirobe.pbworks.com
- lolosovosozo.weebly.com
- milatufed.pbworks.com
- mabajiluvepe.weebly.com
- wosubazaroden.weebly.com
- vogivakazela.pbworks.com
- sozatugija.weebly.com
- gevofiku.weebly.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report