MALICIOUS — 0fdd5eb6e9cb1cbb33b28d7e7f0635c61b9d5193b288d26f1f6481ce13210f29
MALICIOUS — 0fdd5eb6e9cb1cbb33b28d7e7f0635c61b9d5193b288d26f1f6481ce13210f29 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0fdd5eb6e9cb1cbb33b28d7e7f0635c61b9d5193b288d26f1f6481ce13210f29 - SHA-1:
a16e032c4de3c463dfe38cc6ce0cf77025d53961 - MD5:
0479dcf7a60c996d1b9e4a62f1e031a2 - ssdeep:
1536:MPY+GB0td17mvr1RbJ+vNOqeRGG6WxUsGKbkEFUTKWE6f1VHCT0TWOpOZRLFuW0R:D+GB9vHsl/eRfUsGKbv+fPBsZ1FQTb - TLSH:
T1953AC0F36297DD0D775BEF5369A6016C244ADB846162EE6040C8771CD4BCABEAF10D02 - Submitted as: 0fdd5eb6e9cb1cbb33b28d7e7f0635c61b9d5193b288d26f1f6481ce13210f29
- File type: pdf · Size: 98144 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/503247572c955cad22d59707d1f47247/34342194605.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://birzebbugastpetersfc.com/files/file/pozopu.pdf, http://nc2e.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160b9071530144---dudareboregidapipififev.pdf, http://business-plan-capalpha.eu/mbp/upload/images/images/upload/ckfinder/muvosa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=philippines+general+knowledge+quiz+with+answers+pdf
- http://birzebbugastpetersfc.com/files/file/pozopu.pdf
- http://nc2e.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160b9071530144---dudareboregidapipififev.pdf
- http://business-plan-capalpha.eu/mbp/upload/images/images/upload/ckfinder/muvosa.pdf
- https://www.marthatrotts.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16071c81ab7629---57989920727.pdf
- https://newshieldinsurance.com/demo/gsa/final/images/file/ruluragoxozekadizig.pdf
- http://ventmetal.ru/userfiles/files/2267491701.pdf
- http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/503247572c955cad22d59707d1f47247/34342194605.pdf
- https://biodent.ro/m4fm_files/m4news/ck-uploads-files/sudozugodowijigeni.pdf
- http://www.xpresswedding.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ac060d833a1---vojofaxejobevoroweweso.pdf
- http://mtntoproyalshihtzus.com/clients/4/42/42f4769cb4f2467af64fea76c5682520/File/48867487397.pdf
- http://nmglyxx.com/userfiles/file/85170071857.pdf
- http://rufullthrottle.com/wp-content/plugins/formcraft/file-upload/server/content/files/160881f02b335f---54013958573.pdf
- https://alfa-clining.ru/wp-content/plugins/super-forms/uploads/php/files/4b9582c87fa3db2b33c29a88c50ab274/buwowaxegezogujiv.pdf
- https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/ff942edd635fe8d01ca1b757706bb38e/xiviwamekeruwadujulokeg.pdf
- http://bielle-srl.com/userfiles/files/finibiresid.pdf
- http://akekaluck.com/ckfinder/userfiles/files/tejugejorowu.pdf
- http://tuzvedo.hu/elemek/file/lubisalevogobugemapuli.pdf
- https://www.audifonosdoshoydos.com/wp-content/plugins/formcraft/file-upload/server/content/files/16091832c8a90a---91149460481.pdf
- https://angelsstaff.com/uploads/file/jixuse.pdf
- https://f1com.ge/wp-content/plugins/super-forms/uploads/php/files/e50e51190efd768e7d35ee55eff70fb9/xumilukowumepaf.pdf
- http://shinex-auto.com/userfiles/file/28517647652.pdf
- https://beaufortbond.com/wp-content/plugins/super-forms/uploads/php/files/c64ef5f4ee432ba501df66e744850cc1/40124373081.pdf
- http://aylincinarli.com/fckfiles/file/22519184539.pdf
- http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609fa9b2f306b---pifapekodemigoseno.pdf
Embedded domains
- feedproxy.google.com
- birzebbugastpetersfc.com
- nc2e.fr
- business-plan-capalpha.eu
- www.marthatrotts.ca
- newshieldinsurance.com
- ventmetal.ru
- chagatea.ru
- www.xpresswedding.com
- mtntoproyalshihtzus.com
- nmglyxx.com
- rufullthrottle.com
- alfa-clining.ru
- adbadog.com
- bielle-srl.com
- akekaluck.com
- www.audifonosdoshoydos.com
- angelsstaff.com
- shinex-auto.com
- beaufortbond.com
- aylincinarli.com
- leap-egypt.com
- www.darrellstuckey.com
- smartickgroup.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report