MALICIOUS — 1613ac23046246---88146475097.pdf
MALICIOUS — 1613ac23046246---88146475097.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1c57457c2d7d7d35a65edb85191ff03022c470ca63105c6214d794464aef983d - SHA-1:
793ae99743e19c7a6a6a438157e7f68055ebfc3e - MD5:
5e7faab6d3db76da74fd719f13a6b0b5 - ssdeep:
1536:e+BQ0p5r7/vL5vNNwQC1pyJ0WGpOKVFtOSWzmihQwcNVT5:fBt5rfbNFC1pKKVFtO5Dcx - TLSH:
T17737BFF352A7CD8CBB579F077AAB10A8A44DD3856272DA504088B7BCC07C8BE7E14561 - Submitted as: 1613ac23046246---88146475097.pdf
- File type: pdf · Size: 74264 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.agrosystem.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1613a7f06289c8---tevoridexigirutux.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://laborke.ru/uplcv?utm_term=how+to+download+android+apps+through+pc, http://redemaisfarma.com/userfiles/file/lovevedaxofudovug.pdf, https://rsun.pro/admin/ckfinder/userfiles/files/jopurimowaxeralu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://laborke.ru/uplcv?utm_term=how+to+download+android+apps+through+pc
- http://redemaisfarma.com/userfiles/file/lovevedaxofudovug.pdf
- https://rsun.pro/admin/ckfinder/userfiles/files/jopurimowaxeralu.pdf
- http://websurin.net/UserFiles/File/gapaxunakamaluxuv.pdf
- https://kayakbranson.com/wp-content/plugins/formcraft/file-upload/server/content/files/16133614c2cccc---91936075898.pdf
- http://pazzo.jp/js/upload/files/12310386505.pdf
- http://www.agrosystem.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1613a7f06289c8---tevoridexigirutux.pdf
- https://dmddsgn.com/wp-content/plugins/super-forms/uploads/php/files/1a814a4ba4b04890263c1d5024ac2462/rojet.pdf
- http://proreferee.ru/uploads/ckfinder/files/jirilexupak.pdf
- http://daotaoyduoc.org/wp-content/plugins/super-forms/uploads/php/files/244e653c1ded4a21df1c1cfe1dc8afc4/41215739109.pdf
- http://burbank.kopanramen.com/uploads/files/gaxodubamamemazenoxi.pdf
- http://bantinnhadat.com/users/files/26481651390.pdf
- http://studiotecnicolari.it/userfiles/files/gebulutadebeporogiw.pdf
- http://atek-ent.com/upload/file/getutoxezadovomijixikipiv.pdf
- http://mhinflatable.com/upload/file/movaludixuluvepu.pdf
- http://bonfiremadigan.com/uploads/fckeditor/file/wojivul.pdf
- http://grimastone.ru/files/60696375233.pdf
- https://sayurhijau.com/contents/files/30353009595.pdf
- http://interel-rus.ru/test/sites/default/files/file/46654030138.pdf
- https://on-call-anatomist.org/ckfinder/userfiles/files/masepexizunodupupis.pdf
- https://riverasphotovideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612fffcf19734---tekipilaw.pdf
- http://chongros.com/userData/board/file/7021656276.pdf
- http://ephtour.com/FileData/ckfinder/files/20210908_B7874EFDF68D1AAE.pdf
- https://webmenuplus.com/images/file/gutelunavejesivevuza.pdf
- http://gdfsztal.com/uploadfile/files/70253108072.pdf
Embedded domains
- laborke.ru
- redemaisfarma.com
- rsun.pro
- websurin.net
- kayakbranson.com
- pazzo.jp
- dmddsgn.com
- proreferee.ru
- daotaoyduoc.org
- burbank.kopanramen.com
- bantinnhadat.com
- studiotecnicolari.it
- atek-ent.com
- mhinflatable.com
- bonfiremadigan.com
- grimastone.ru
- sayurhijau.com
- interel-rus.ru
- on-call-anatomist.org
- riverasphotovideo.com
- chongros.com
- ephtour.com
- webmenuplus.com
- gdfsztal.com
- bhk-aindling.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report