MALICIOUS — 0e2f04ff86f2eadd1798c8fb81b6d90959794ef93dd9977ba13c15ae40c759c3
MALICIOUS — 0e2f04ff86f2eadd1798c8fb81b6d90959794ef93dd9977ba13c15ae40c759c3 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0e2f04ff86f2eadd1798c8fb81b6d90959794ef93dd9977ba13c15ae40c759c3 - SHA-1:
ac57ab4691dde08beecbc9d7bd504dba277f819e - MD5:
79d1dd7909fc9db0f92d6730062c8b2f - ssdeep:
3072:WUbsOefaiAzWThC1CKF5EtgxLEgdEufHI8ppGFnwrUGvrF:tml6CntSog9fWm - TLSH:
T1433DF1F321A7CC8C77CACB1375FA5168B04ADA8C2193F66404C97A6C847CDBD7A20A51 - Submitted as: 0e2f04ff86f2eadd1798c8fb81b6d90959794ef93dd9977ba13c15ae40c759c3
- File type: pdf · Size: 127665 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://cu-mbc.com/ckfinder/userfiles/files/zotezowufepuvureveke.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://we-plus.tw/ckfinder/userfiles/files/89055702678.pdf, http://constantcontinuity.com/membership/data/files/zifigefix.pdf, http://cu-mbc.com/ckfinder/userfiles/files/zotezowufepuvureveke.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/YTWXjIUwRh0/uplcv?utm_term=let+it+shine+full+movie+from+the+beginning+to+end+download
- https://we-plus.tw/ckfinder/userfiles/files/89055702678.pdf
- http://constantcontinuity.com/membership/data/files/zifigefix.pdf
- http://cu-mbc.com/ckfinder/userfiles/files/zotezowufepuvureveke.pdf
- http://jia-longsofa.com/uploadpic/jialong151126/files/202109100507118391.pdf
- http://baheth24aqari.com/ckfinder/userfiles/files/47804641315.pdf
- http://crisismobile.com/ckfinder/userfiles/files/forotubabovidil.pdf
- http://dok-vo.ru/userfiles/file/mijavudemowa.pdf
- https://apz-arte.com/ckfinder/userfiles/files/xopaxerigibaxofupazure.pdf
- https://funbugs.ie/userfiles/file/49451080547.pdf
- http://tipsclubcr.com/campannas/file/35577291384.pdf
- https://www.medipratik.com/wp-content/plugins/formcraft/file-upload/server/content/files/16141f857d94e6---207239166.pdf
- https://mariapolis.net/ckfinder/userfiles/files/kogemuwuzirumejavonem.pdf
- http://imi.vc/upload/files/xetasun.pdf
- http://investinwielkopolska.pl/application/lib/ckfinder/userfiles/files/ruwomalimumafavax.pdf
- http://atoutslegion.com/userfiles/file/25194999598.pdf
- https://infravoip.com/wp-content/plugins/super-forms/uploads/php/files/08a249d7994e76e7c578ef39195482be/wutubezuwotobupexe.pdf
- http://kindervakantieweekdeurne.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16143ed3b5c205---buxaveniwi.pdf
- https://www.generalutilities.com/wp-content/plugins/formcraft/file-upload/server/content/files/161330f7eb11d5---fezibitepatowuv.pdf
- https://zooiguana.pl/app/webroot/media/files/winigi.pdf
- http://niengrangchuyensau.com/upload/contentFile/file/xibukuxumimimomulilu.pdf
- http://ebonit.light.bg/includes/libs/ckfinder/userfiles/files/41110839490.pdf
- http://ajk-opakowania.eu/upload/fck/file/90178953008.pdf
- https://noursportevents.com/wheelmarine/userfiles/file/55806139374.pdf
- https://abriganature.centralcms.cloud/galeria/files/42166443846.pdf
Embedded domains
- feedproxy.google.com
- we-plus.tw
- constantcontinuity.com
- cu-mbc.com
- jia-longsofa.com
- baheth24aqari.com
- crisismobile.com
- dok-vo.ru
- apz-arte.com
- tipsclubcr.com
- www.medipratik.com
- mariapolis.net
- investinwielkopolska.pl
- atoutslegion.com
- infravoip.com
- kindervakantieweekdeurne.nl
- www.generalutilities.com
- zooiguana.pl
- niengrangchuyensau.com
- ajk-opakowania.eu
- noursportevents.com
- abriganature.centralcms.cloud
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report