MALICIOUS — 0ff28c8d727c7329a51ec0564f69a2847477356ab0d5e7dc49bb43ab155ee0f2
MALICIOUS — 0ff28c8d727c7329a51ec0564f69a2847477356ab0d5e7dc49bb43ab155ee0f2 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0ff28c8d727c7329a51ec0564f69a2847477356ab0d5e7dc49bb43ab155ee0f2 - SHA-1:
8a8f3466826f457a1981c36ff06f05b36ed265a0 - MD5:
b1fd5550cb1de0affdcbef2087b94474 - ssdeep:
1536:VL1LB9zqLMi0Vk0VpVotH3HBs54WapOtQHW5nAFa6xE9SwoXbOw:nLbwMi0PX+H3MtQAnAFZKSwk5 - TLSH:
T10239D0F3719BDE9C72DE9B437AA72298644BE38D4132EE604004BA7C597C6BD6F00941 - Submitted as: 0ff28c8d727c7329a51ec0564f69a2847477356ab0d5e7dc49bb43ab155ee0f2
- File type: pdf · Size: 86667 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://ibb-online.ru/f/file/73732252455.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://synerhu.ru/uplcv?utm_term=how+do+i+see+page+breaks+in+word, http://ibb-online.ru/f/file/73732252455.pdf, http://aleeblog.com/wp-content/plugins/super-forms/uploads/php/files/76m7g0mea8tuj5491qeg2ejrd6/92795917518.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://synerhu.ru/uplcv?utm_term=how+do+i+see+page+breaks+in+word
- http://ibb-online.ru/f/file/73732252455.pdf
- http://aleeblog.com/wp-content/plugins/super-forms/uploads/php/files/76m7g0mea8tuj5491qeg2ejrd6/92795917518.pdf
- http://axwelindia.com/uploads/95702303621.pdf
- http://sivam.pl/files/file/622223615.pdf
- https://blokhol.com/upload/files/9062477529.pdf
- https://agilitynd.com/wp-content/plugins/super-forms/uploads/php/files/a50663ed77859e6bd346ef2f8050dbcd/65948700033.pdf
- https://tavio.ru/files/file/15007168809.pdf
- https://asiabiru.com/contents//files/96002837295.pdf
- http://barcelonasixtytwo.com/userfiles/file/24200913838.pdf
- https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/87e4445b40bbd02aea6b8fad1c4cc986/27148213371.pdf
- http://westleyden72reunion.com/clients/4/46/469dc9162705cbff2d1fbe132f144f37/File/befuwoxun.pdf
- https://linhngapt.vn/upload/files/93451384113.pdf
- http://icmasistemas.com/userfiles/files/tijofufi.pdf
- http://vdgairconditioning.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1609a715d762ec---12182652861.pdf
- http://phillipwhiting.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e371eee9ec1---kupexasozixatirixuvev.pdf
- https://lorenzonimmigrationlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/160806214adddd---48939954272.pdf
- https://alkalacarservice.com/public_html/userfiles/file/88678159657.pdf
- https://trucraftsmanship.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a3b0dc457fe---30912791691.pdf
- https://bobecoingatlan.com/uploads/editor/file/42689232934.pdf
- http://discoveryenglish.org/wp-content/plugins/formcraft/file-upload/server/content/files/160a45b93e3db1---53819462052.pdf
- http://tuzvedo.hu/elemek/file/depusemutiganoxaxuwojat.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- synerhu.ru
- ibb-online.ru
- aleeblog.com
- axwelindia.com
- sivam.pl
- blokhol.com
- agilitynd.com
- tavio.ru
- asiabiru.com
- barcelonasixtytwo.com
- ahi.com.ua
- westleyden72reunion.com
- icmasistemas.com
- vdgairconditioning.nl
- phillipwhiting.com
- lorenzonimmigrationlaw.com
- alkalacarservice.com
- trucraftsmanship.com
- bobecoingatlan.com
- discoveryenglish.org
- www.w3.org
- purl.org
- ns.adobe.com
- linhngapt.vn
- tuzvedo.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report