MALICIOUS — 194b9327522b9d8334251650bd00c4cb05e0fa838c3ae7194fd42482ac5fb2e3
MALICIOUS — 194b9327522b9d8334251650bd00c4cb05e0fa838c3ae7194fd42482ac5fb2e3 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
194b9327522b9d8334251650bd00c4cb05e0fa838c3ae7194fd42482ac5fb2e3 - SHA-1:
1c46fcfc16e5bf93012e626cf9ce51d57d375130 - MD5:
2c32f1c0ac49907a67f1171adb2e1dfb - ssdeep:
1536:XQt0qwbDNdGXxSrONi2yNBNgkoxBLomQgsKfV8QjWuApfEwBWUpO7pf65vTMfO:gt0XbD/KKXgZT6gs0bApswE7Q5H - TLSH:
T17939C0F37197DC4C775B9B436CAE126DA04AC7886222E79085CC796DC1BC2FE6E04A01 - Submitted as: 194b9327522b9d8334251650bd00c4cb05e0fa838c3ae7194fd42482ac5fb2e3
- File type: pdf · Size: 86753 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://gz-theoutfit.com/UploadFiles/FCKeditor/20210901195409.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://donovaly-ubytovanie-safran.sk/web/userfiles/file/pibak.pdf, http://gz-theoutfit.com/UploadFiles/FCKeditor/20210901195409.pdf, http://2990592.ru/ckfinder/userfiles/files/murodupegirodoluwa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/3CAf4wW3hvY/uplcv?utm_term=black+ops+cold+war+zombies+pack+a+punch
- http://donovaly-ubytovanie-safran.sk/web/userfiles/file/pibak.pdf
- http://gz-theoutfit.com/UploadFiles/FCKeditor/20210901195409.pdf
- http://2990592.ru/ckfinder/userfiles/files/murodupegirodoluwa.pdf
- https://marblo.com/app/webroot/img/files/wanawogibogisalijageg.pdf
- http://mnarch.it/userfiles/files/zinevaf.pdf
- http://topopentertainment.com/wp-content/plugins/formcraft/file-upload/server/content/files/161562c6628069---nupurodisirobedixuma.pdf
- http://osoboebludo.com/ckfinder/userfiles/files/berime.pdf
- https://matratva.in/userfiles/file/rowomumuvezirazo.pdf
- https://ceramicasvillaflor.cl/UserFiles/File/tisevisaxozadupigozufasit.pdf
- http://bowlingkillers.com/imgdb/files/20057255376.pdf
- http://vntattoosupply.net/uploads/image/files/42384537757.pdf
- http://zgic.ru/!upload/files/xakowavifule.pdf
- http://muntepa.com/userfiles/files/mofobexokemuxufazij.pdf
- http://gaestehaus-am-erlkoenig.de/img/editor/file/48040239145.pdf
- http://iamsoldierfit.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613ec276a43f7---65791374105.pdf
- https://adiwirawanbali.com/wp-content/plugins/super-forms/uploads/php/files/93b34796cb19af28f5258c385ea33cd2/juxozesovojamenub.pdf
- http://mrs724.ir/basefile/drtiketcom/files/ninebojosasime.pdf
- https://coloreverything.love/wp-content/plugins/super-forms/uploads/php/files/903a379e1f5a2587531e5cca0f169cfb/xadunujut.pdf
- http://matras-devison.ru/upload/file/80843959814.pdf
- http://sushinamu.com/uploads/files/jufapezo.pdf
- https://ismart99.net/upload/files/bajava.pdf
- https://bindazzled.com.au/wp-content/plugins/super-forms/uploads/php/files/377e7e08e3b772cdd8d7fc67ba13fab1/52753218978.pdf
- http://devison-matras.com/upload/file/movafikad.pdf
- http://turbotechnik24.de/userfiles/file/15988099806.pdf
Embedded domains
- feedproxy.google.com
- gz-theoutfit.com
- 2990592.ru
- marblo.com
- mnarch.it
- topopentertainment.com
- osoboebludo.com
- matratva.in
- bowlingkillers.com
- vntattoosupply.net
- zgic.ru
- muntepa.com
- gaestehaus-am-erlkoenig.de
- iamsoldierfit.com
- adiwirawanbali.com
- mrs724.ir
- matras-devison.ru
- sushinamu.com
- ismart99.net
- bindazzled.com.au
- devison-matras.com
- turbotechnik24.de
- kingsshopping.abwingsmd.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report