MALICIOUS — 1d3392d4ec4f413233ed87fc5051775c6cb5a451fd229ed76e7bc00a346031d1
MALICIOUS — 1d3392d4ec4f413233ed87fc5051775c6cb5a451fd229ed76e7bc00a346031d1 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1d3392d4ec4f413233ed87fc5051775c6cb5a451fd229ed76e7bc00a346031d1 - SHA-1:
d96ebab4b25ab84e370004f9ddf9c91c31857f26 - MD5:
289cacbeba2f2817e960a6e81d92840f - ssdeep:
1536:FHUWAtP7iG3AO0t34uhVk5VSM5PGhp6WBs7Kgmlr49ySrrqdW8pO7Es9:+WkPyk5VSC+hpXHgmlrEy8rqc7P - TLSH:
T18A37AFF36097CF8DB74B9B436EAB119D6086D3486132E7904088BBADC57C67D6F10A50 - Submitted as: 1d3392d4ec4f413233ed87fc5051775c6cb5a451fd229ed76e7bc00a346031d1
- File type: pdf · Size: 70314 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://ctyrkolky-gamax.cz/data/dokumenty/93370389907.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://bjavc.com/filespath/files/20210910105635.pdf, https://retentionstudentexperience.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614a1f3cb491e---zozefibitodasi.pdf, https://tkbhanna.com/ckfinder/userfiles/files/xunusevibatilif.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=omnisd+apk+download+for+jio+phone
- http://bjavc.com/filespath/files/20210910105635.pdf
- https://retentionstudentexperience.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614a1f3cb491e---zozefibitodasi.pdf
- https://tkbhanna.com/ckfinder/userfiles/files/xunusevibatilif.pdf
- https://9ja-bet.com/userfiles/file/xusobuxewubasudemuxiva.pdf
- http://myapartment.de/web/editor/files/378927209.pdf
- http://gs-metals.com/filespath/files/20210911093755.pdf
- https://thehouseproduction.net/file/rekatinexizidefogodus.pdf
- http://ctyrkolky-gamax.cz/data/dokumenty/93370389907.pdf
- http://ngnjl.com/userfiles/files/pamoma.pdf
- http://www.solarwindependence.com/ckfinder/userfiles/files/xulazeboruzekepasipip.pdf
- http://cuathepvangohaiduong.com/images/ckeditor/files/71209701950.pdf
- http://laserbeautymachine.net/d/files/8712842905.pdf
- http://toszegisuli.hu/userfiles/file/suxojoru.pdf
- http://cresapumc.org/files/file/lupenuxebojonazele.pdf
- http://tomgiongvip.com/uploads/files/file/begusaj.pdf
- http://for-rent-antwerp.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613ff05e87e66---47036155332.pdf
- http://kooijobs.in/ckfinder/userfiles/files/baralusofiwadibax.pdf
- http://vinag7furniture.com/app/webroot/files/editor_upload/files/boladidetokilejif.pdf
- http://firewaterdamagedfw.com/test/fckeditor/uploadfiles/file/luxevagefatemevagabaleg.pdf
- http://trongtinpc.com/luutru/files/38714481929.pdf
- http://slsnn.ru/content/files/47817500213.pdf
- http://boxerdapolenta.com/cmsimple/images/file/89984425578.pdf
- http://bn-biz.com/userData/board/file/javakedajalonisagupu.pdf
- https://amgaa.org/temp/files/49861376791.pdf
Embedded domains
- feedproxy.google.com
- bjavc.com
- retentionstudentexperience.com
- tkbhanna.com
- 9ja-bet.com
- myapartment.de
- gs-metals.com
- thehouseproduction.net
- ngnjl.com
- www.solarwindependence.com
- cuathepvangohaiduong.com
- laserbeautymachine.net
- cresapumc.org
- tomgiongvip.com
- for-rent-antwerp.com
- kooijobs.in
- vinag7furniture.com
- firewaterdamagedfw.com
- trongtinpc.com
- slsnn.ru
- boxerdapolenta.com
- bn-biz.com
- amgaa.org
- topopentertainment.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report