MALICIOUS — 05a18e719802485a9e4674ae323a3691356c1927f1445b94e9fc48338dcd71b7
MALICIOUS — 05a18e719802485a9e4674ae323a3691356c1927f1445b94e9fc48338dcd71b7 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
05a18e719802485a9e4674ae323a3691356c1927f1445b94e9fc48338dcd71b7 - SHA-1:
8aba3b803fad0524df7f354d5b423f28444fcd4d - MD5:
21432bf345982598ca96db9a5470fa79 - ssdeep:
1536:qUV66/L2F/8hW8ouAoRpruylfWOpOwr7Dum1WrQQpM0l6t7NH9RSNHYSNHGRa:JA6jEsBAoRsylcwrvmh6t7NHXSNHYSND - TLSH:
T1AA37BFE3609BED8C73C79F1369AB515D544BDB4C6232D6908088AA7CC47CABE7F10A41 - Submitted as: 05a18e719802485a9e4674ae323a3691356c1927f1445b94e9fc48338dcd71b7
- File type: pdf · Size: 71944 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://31kouqiang.com/userfiles/file/1632780623.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://gskrem.ru/img/file/vomozuvu.pdf, https://questyme.com/userfiles/file/zurujufegowepapo.pdf, https://turismopontevedra.com/ckfinder/userfiles/files/18460159845.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=simple+present+worksheets+for+beginners
- http://gskrem.ru/img/file/vomozuvu.pdf
- https://questyme.com/userfiles/file/zurujufegowepapo.pdf
- https://turismopontevedra.com/ckfinder/userfiles/files/18460159845.pdf
- https://www.gico.ge/ckfinder/userfiles/files/85604567824.pdf
- http://matrixuniverzum.eu/wp-content/plugins/formcraft/file-upload/server/content/files/16148b4a714199---refugizizaloluge.pdf
- http://rileyillustration.com/images/agency/files/78476158723.pdf
- http://aaexpansionjoint.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614fa6b876caf---womebazugudibadagemaroju.pdf
- http://skyrunarser.com/js/fckeditor/editor/filemanager/connectors/php/connector.php/upfiles/file/210910212309739436cnue3v.pdf
- http://31kouqiang.com/userfiles/file/1632780623.pdf
- http://reiki-roots.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16133b4ae64411---22370938498.pdf
- http://nanoscopy.ru/uploads/files/gavewuniwulado.pdf
- http://queuemanagementsystems.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613912e2c0225---zogikililupuwuditi.pdf
- http://brainbond.ro/userfiles/file/mepewelepokisukogizenuju.pdf
- http://studiocariola.com/userfiles/files/sibisomibofafaki.pdf
- https://sreekanakananda.com/ckfinder/userfiles/files/nilamidunaboxonomanefotiw.pdf
- https://southernwashpros.com/nbloom/fckuploads/file/66250286417.pdf
- https://eecpowerindia.com/codelibrary/ckeditor/ckfinder/userfiles/files/vopurelalotalo.pdf
- http://nhuaduongnhapkhauaz.org/upload/files/lasesifinowexe.pdf
- http://texinpack.com/uploadfile/file///2021091205522780.pdf
- http://sanraimundo.cl/dyn/uploads/file/90714487200.pdf
- http://www.roosprommenschenckelfoundation.nl/ckfinder/files/files/tesiwejoxafoximigepidalu.pdf
- https://www.lang-mayer.de/wp-content/plugins/formcraft/file-upload/server/content/files/16144f4dcc6d72---48149076033.pdf
- https://contabil-fiscal.ro/mm/file/83570398961.pdf
- https://navoloki.mebel18.com/uploads/files/80902156892.pdf
Embedded domains
- feedproxy.google.com
- gskrem.ru
- questyme.com
- turismopontevedra.com
- matrixuniverzum.eu
- rileyillustration.com
- aaexpansionjoint.com
- skyrunarser.com
- 31kouqiang.com
- reiki-roots.co.uk
- nanoscopy.ru
- queuemanagementsystems.com
- studiocariola.com
- sreekanakananda.com
- southernwashpros.com
- eecpowerindia.com
- nhuaduongnhapkhauaz.org
- texinpack.com
- www.roosprommenschenckelfoundation.nl
- www.lang-mayer.de
- navoloki.mebel18.com
- www.dr.schure.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report