MALICIOUS — 1f114c13ed029c5344a265550caf7f751c7a47632af032b0d2e9f55355c490e9
MALICIOUS — 1f114c13ed029c5344a265550caf7f751c7a47632af032b0d2e9f55355c490e9 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1f114c13ed029c5344a265550caf7f751c7a47632af032b0d2e9f55355c490e9 - SHA-1:
72f46924940e9b715e3766f71ae1b533e3d22cd0 - MD5:
09a63324b4b01ba41c46cb43580eb555 - ssdeep:
1536:g41Q4lR2cMM6hKJWnGD/IeQo+5i0QWQVSsYzZvLMaWOpOwrMbN2ndg:X1Q2R2cViCq0IeR+5ifSssxLMPwr4Ui - TLSH:
T1DE37B0F3519BDD9C779B9B0368AA13BCB54EE6852172EBA050C8B62C807C97D7F00650 - Submitted as: 1f114c13ed029c5344a265550caf7f751c7a47632af032b0d2e9f55355c490e9
- File type: pdf · Size: 73285 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://mfcpavpos.ru/file/10708450055.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://laborke.ru/uplcv?utm_term=ld+player+64+bit+android, http://mfcpavpos.ru/file/10708450055.pdf, https://lrsinc.co/userfiles/file/64566429727.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://laborke.ru/uplcv?utm_term=ld+player+64+bit+android
- http://mfcpavpos.ru/file/10708450055.pdf
- https://lrsinc.co/userfiles/file/64566429727.pdf
- https://mountmoriahcamp.com/media/ninidafevagimetumeze.pdf
- http://jj-metals.com/userfiles/file/2021090211563473499.pdf
- https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/81d5a232a7f3f2ed138bc7010724e9b0/32424285752.pdf
- http://reiki-roots.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1614bf9deacea7---gujojowevugej.pdf
- http://cl-metalparts.com/d/files/80417513900.pdf
- http://gorsilawfirm.com/userfiles/file/42881616613.pdf
- http://jafra-com.at/userfiles/file/gemakajasam.pdf
- https://acethamessecurity.co.uk/wp-content/plugins/super-forms/uploads/php/files/b43767191778944c2a623655bc1d289e/31628038214.pdf
- https://hongmao.tw/uploads/files/202109060554475241.pdf
- http://topup-fight.com/ckfinder/userfiles/files/21093792137.pdf
- https://www.booster-p.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614796729feba---vabogeki.pdf
- https://simplehome.ro/ckfinder/userfiles/files/79698136798.pdf
- http://studiomistretta.com/userfiles/files/timoxuwe.pdf
- http://hichipper.com/hichipper/uploadfile/file/2021091819131373499.pdf
- https://vinadesigndanang.vn/uploads/image/files/23428642877.pdf
- http://orenprom.com/img/account/file/10690347045.pdf
- https://iieng.org/editor/ckfinder/userfiles/files/70968236107.pdf
- https://deepex.hu/hirek/files/mejisusuwegu.pdf
- http://camara.acessoainformacao.org/uploads/ckfinder/files/pekawowenadutupoxedilaka.pdf
- http://greenbrier101.com/userimages/bejetasibipojifosafi.pdf
- https://brylka-kfz.de/wp-content/plugins/formcraft/file-upload/server/content/files/16130e635e211a---94604612000.pdf
- http://curry-box-deluxe.de/userfiles/file/jefoxawoxexipubu.pdf
Embedded domains
- laborke.ru
- mfcpavpos.ru
- lrsinc.co
- mountmoriahcamp.com
- jj-metals.com
- alenakovalchuk.ru
- reiki-roots.co.uk
- cl-metalparts.com
- gorsilawfirm.com
- acethamessecurity.co.uk
- hongmao.tw
- topup-fight.com
- www.booster-p.com
- studiomistretta.com
- hichipper.com
- orenprom.com
- iieng.org
- camara.acessoainformacao.org
- greenbrier101.com
- brylka-kfz.de
- curry-box-deluxe.de
- www.w3.org
- purl.org
- ns.adobe.com
- jafra-com.at
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report