MALICIOUS — 14773b85d00eb54f46b8b2519b327e957364e291d0cd781b0d008ec092a5f0ed
MALICIOUS — 14773b85d00eb54f46b8b2519b327e957364e291d0cd781b0d008ec092a5f0ed is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
14773b85d00eb54f46b8b2519b327e957364e291d0cd781b0d008ec092a5f0ed - SHA-1:
67ad997cb23f794bf1233ab0fad7f83a19aa22d6 - MD5:
1e40397198766840158798d1f4c21a7d - ssdeep:
1536:KkCKPLwzNEuyqdkjsMoGCIXbq0aAFHvf7LgtTTtrkpUM0ZWbpONiWmjs6X/D6FYZ:mvzNeCI1aAFPDLCTT2b0bNUjs6OSz9 - TLSH:
T13C39D0F761E7DD0C768B8F8315EB1169A098EB8D3172AA5450C9B66CC27C8BDBF00950 - Submitted as: 14773b85d00eb54f46b8b2519b327e957364e291d0cd781b0d008ec092a5f0ed
- File type: pdf · Size: 89239 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://kazenergy.kz/wp-content/plugins/formcraft/file-upload/server/content/files/161653566152c5---74884346647.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://www.lucaslobker.com/minor/ckfinder/userfiles/files/41872375793.pdf, http://residenceraffaellotorino.com/userfiles/files/6717330723.pdf, http://ppp220.com/Upload/file/35446162460.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/MbOu/~3/TSvcnjQ06Jg/uplcv?utm_term=for+the+love+of+nigel+the+dogs+in+my+life
- https://www.lucaslobker.com/minor/ckfinder/userfiles/files/41872375793.pdf
- http://residenceraffaellotorino.com/userfiles/files/6717330723.pdf
- http://ppp220.com/Upload/file/35446162460.pdf
- http://sictombbi.fr/ckfinder/userfiles/files/palomazilufugomufogin.pdf
- http://phuwangnam.com/user_file/file/ronetaxisumuxibadipezazef.pdf
- https://www.adom.biz.pl/ckfinder/userfiles/files/kurus.pdf
- https://izharfoster.com/wp-content/plugins/formcraft/file-upload/server/content/files/16168ab433e3e3---44553214165.pdf
- http://spellenindex.nl/images/uploads/palaxa.pdf
- http://kazenergy.kz/wp-content/plugins/formcraft/file-upload/server/content/files/161653566152c5---74884346647.pdf
- http://belgium-ex.com/images/blog/file/vuzurepikutiwoxepofab.pdf
- http://ibarugi.com/fckeditor/userfiles/file/wimuvusejavekovajur.pdf
- http://erfanekeshmiri.ir/userfiles/file/76733604874.pdf
- http://chinastom.ru/userfiles/file/19534399223.pdf
- http://www.next-conseil.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1615671a0eda1a---tepoperadotodomasu.pdf
- http://shrlie.com/upload_fck/file/2021-10-13/20211013221215547341.pdf
- http://tzsunup.com/upload/kumutuwajumikonefore.pdf
- https://cobrawire.com/userfiles/files/ranojavujuxakolabonatewil.pdf
- https://rajatotogroup3.com/contents/files/54434590288.pdf
- https://www.rt9.rspo.org/ckfinder/userfiles/files/64089316742.pdf
- https://larrialdiak.es/files/galeria/files/54979097791.pdf
- http://ptk-astana.kz/wp-content/plugins/super-forms/uploads/php/files/eabbb82851badde6ee0a074d4088ba24/83194319506.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- www.lucaslobker.com
- residenceraffaellotorino.com
- ppp220.com
- sictombbi.fr
- phuwangnam.com
- www.adom.biz.pl
- izharfoster.com
- spellenindex.nl
- belgium-ex.com
- ibarugi.com
- erfanekeshmiri.ir
- chinastom.ru
- www.next-conseil.fr
- shrlie.com
- tzsunup.com
- cobrawire.com
- rajatotogroup3.com
- www.rt9.rspo.org
- larrialdiak.es
- www.w3.org
- purl.org
- ns.adobe.com
- kazenergy.kz
- ptk-astana.kz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report