MALICIOUS — 8b25c7_8d7973eea2934178aab52c0e0ae61521.pdf
MALICIOUS — 8b25c7_8d7973eea2934178aab52c0e0ae61521.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fafe516bc32426b0e47836d6f793f5f12cc41ecc37f76922b9c3e7b5ac3c0e88 - SHA-1:
df4ab5d5b6392838f7e361e12ca0f4abedad982a - MD5:
56af98195eaf573cbbde39bc036b6e37 - ssdeep:
1536:I+Mj3O7C1fcZSWklPUmVjhXiu5fop+zGNlgfV632O7EBwm0kPzpSs8sYmq/vaG:vq3fUZkMmVjhXiSfopKLfVq2M60kdRYZ - TLSH:
T15238C0F311D7CD4DB6879F436EA7196EA08DD38D6436E7A40088AB2C897C65DBF00A41 - Submitted as: 8b25c7_8d7973eea2934178aab52c0e0ae61521.pdf
- File type: pdf · Size: 79389 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!56AF98195EAF
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!56AF98195EAF (rule
PDF/Phish-FAB!56AF98195EAF) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://kokazokurazafan.weebly.com/uploads/1/3/5/3/135348127/ramidotusagonibija.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://xezojetit.ru/wix?keyword=brother+hl-5450dn+driver+windows+xp, https://uploads.strikinglycdn.com/files/f3cf6993-49c8-49a5-ab46-dbfcbbf158fb/chevrolet_s10_repair_manual.pdf, https://uploads.strikinglycdn.com/files/2c82cc78-1f23-42df-a999-b8991d277261/home_interior_design_styles_in_pakistan.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://xezojetit.ru/wix?keyword=brother+hl-5450dn+driver+windows+xp
- https://uploads.strikinglycdn.com/files/f3cf6993-49c8-49a5-ab46-dbfcbbf158fb/chevrolet_s10_repair_manual.pdf
- https://uploads.strikinglycdn.com/files/2c82cc78-1f23-42df-a999-b8991d277261/home_interior_design_styles_in_pakistan.pdf
- https://cdn.sqhk.co/dudugetogi/gihijht/8913500026.pdf
- https://uploads.strikinglycdn.com/files/0ad43e87-ced1-4a0b-8b50-5e16f7454089/bently_nevada_3300_xl_5_mm_proximitor_sensor_manual.pdf
- https://kokazokurazafan.weebly.com/uploads/1/3/5/3/135348127/ramidotusagonibija.pdf
- https://taxufutusa.weebly.com/uploads/1/3/4/5/134514166/sowuwotebepu.pdf
- https://wazurewimi.weebly.com/uploads/1/3/4/5/134598950/nuvunirelu-jalebofexozopid.pdf
- https://37523d11-79cf-4eb3-ada4-f05de57c71ee.filesusr.com/ugd/275374_0c341b18457240d19b31f5ab3b252c17.pdf?index=true
- https://muvanuxeb.weebly.com/uploads/1/3/4/0/134096654/f5cbfd45.pdf
- https://cdn.sqhk.co/gizulakofo/gehejh1/menajenizavujatinutikin.pdf
- https://a1c9bafd-2917-4c1b-b79c-a4b44a941470.filesusr.com/ugd/f0f215_433c6b19297d49489a5df50a6b9adc5e.pdf?index=true
- https://jepibuko.weebly.com/uploads/1/3/0/7/130739686/jepipok.pdf
- https://cdn.sqhk.co/mezutorixo/ibZibhh/how_to_activate_panic_alarm_on_iphone.pdf
- https://cdn.sqhk.co/vibefoparo/hhjihat/real_driving_sim_cars.pdf
- https://rakuwogu.weebly.com/uploads/1/3/4/8/134858672/1356281.pdf
- https://cdn.sqhk.co/letinumi/1Xgdghi/food_wars_season_4_episode_1_release_date.pdf
- https://uploads.strikinglycdn.com/files/17e98963-09c1-4fbe-98ed-914d178dde5c/lelufusiwotaxupusafofo.pdf
- https://zeraxoxuret.weebly.com/uploads/1/3/4/6/134642117/mubulosugiwibiv.pdf
- https://vunidiripoga.weebly.com/uploads/1/3/1/4/131453449/871f69e0581ae.pdf
- https://dibexawalezi.weebly.com/uploads/1/3/4/7/134760597/3894121.pdf
- https://gaxuzuwe.weebly.com/uploads/1/3/1/8/131871814/1464971.pdf
- https://nometiru.weebly.com/uploads/1/3/4/3/134379396/124dd10488bb50.pdf
- https://resivoviwogo.weebly.com/uploads/1/3/3/9/133987135/xonemezavaruren.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- xezojetit.ru
- uploads.strikinglycdn.com
- cdn.sqhk.co
- kokazokurazafan.weebly.com
- taxufutusa.weebly.com
- wazurewimi.weebly.com
- 37523d11-79cf-4eb3-ada4-f05de57c71ee.filesusr.com
- muvanuxeb.weebly.com
- a1c9bafd-2917-4c1b-b79c-a4b44a941470.filesusr.com
- jepibuko.weebly.com
- rakuwogu.weebly.com
- zeraxoxuret.weebly.com
- vunidiripoga.weebly.com
- dibexawalezi.weebly.com
- gaxuzuwe.weebly.com
- nometiru.weebly.com
- resivoviwogo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report