MALICIOUS — 1f59f3bdac534315a9dbda395e70b31db694dab46b940c8591a04e374cf6bd79
MALICIOUS — 1f59f3bdac534315a9dbda395e70b31db694dab46b940c8591a04e374cf6bd79 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1f59f3bdac534315a9dbda395e70b31db694dab46b940c8591a04e374cf6bd79 - SHA-1:
1be7ce23af89a5eae91d0d9a51dd6bef05144a41 - MD5:
05d07a38c91a937c439142ef95a28f5e - ssdeep:
3072:6d1qr1Mt5B7ZSTvyFRE7Ea4bNgFQN1LiWlFS0T:m1icn7uDtjQN1LigFN - TLSH:
T1863BD0F321D7CD5CB79B8B0768A611EDB09AD78836A2D710418CAA3CC5BC9BD7E04950 - Submitted as: 1f59f3bdac534315a9dbda395e70b31db694dab46b940c8591a04e374cf6bd79
- File type: pdf · Size: 111853 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://fullgame.hu/uploads/files/gogomonetomixolirajuwu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://www.totspotdaynursery.co.uk/ckfinder/userfiles/files/53919053091.pdf, https://fullgame.hu/uploads/files/gogomonetomixolirajuwu.pdf, https://idroilektriki.gr/files/file/28757343982.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/S30rS-6n6vg/uplcv?utm_term=p10+lite+firmware
- https://www.totspotdaynursery.co.uk/ckfinder/userfiles/files/53919053091.pdf
- https://fullgame.hu/uploads/files/gogomonetomixolirajuwu.pdf
- https://idroilektriki.gr/files/file/28757343982.pdf
- http://www.lifestaralberta.com/wp-content/plugins/formcraft/file-upload/server/content/files/161382b46c59d4---51703678360.pdf
- http://klaaswester.nl/img/file/91264472854.pdf
- http://klhl.com/userfiles/file/vozoti.pdf
- http://bennett-legal.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/76725386352.pdf
- http://debten.net/UserFiles/File/49056958522.pdf
- https://gallerylingard.com/uploads/file/selunazotelizuv.pdf
- http://healingtown.org/userData/board/file/70954461345.pdf
- https://automatisme-portail-bordazzi.fr/userfiles/fichiers/50011834462.pdf
- http://ain.proximeo.com/ckfinder/userfiles/files/32405467591.pdf
- http://mishor-uvk.com/uploads/files/bemugolizupamokiretux.pdf
- https://healthlantern.com/ckeditor/ckfinder/userfiles/files/88210195552.pdf
- http://www.guaitoli.eng.br/wp-content/plugins/formcraft/file-upload/server/content/files/1613862df8721c---zitasidi.pdf
- https://searchkar.com/ci/userfiles/files/14722740450.pdf
- http://dogomanhnghia.com/uploads/files/32635931844.pdf
- http://nebovsem.ru/app/webroot/files/files/lepubejidig.pdf
- http://phupmirpol.pl/userfiles/file/94616456758.pdf
- http://adhunikjewellers.com/ckfinder/userfiles/files/39382493894.pdf
- https://wamsconference.com/wp-content/plugins/super-forms/uploads/php/files/101de83d104deae2a958a8483c8a12f3/22719583101.pdf
- https://peoplesmodelinternational.com/ckfinder/userfiles/files/jiwutelebutef.pdf
- http://ivelinabozilova.com/userfiles/file/wuwuzuwiv.pdf
- https://tierlistei.ch/downloads/92737052146.pdf
Embedded domains
- feedproxy.google.com
- www.totspotdaynursery.co.uk
- www.lifestaralberta.com
- klaaswester.nl
- klhl.com
- bennett-legal.com
- debten.net
- gallerylingard.com
- healingtown.org
- automatisme-portail-bordazzi.fr
- ain.proximeo.com
- mishor-uvk.com
- healthlantern.com
- www.guaitoli.eng.br
- searchkar.com
- dogomanhnghia.com
- nebovsem.ru
- phupmirpol.pl
- adhunikjewellers.com
- wamsconference.com
- peoplesmodelinternational.com
- ivelinabozilova.com
- tierlistei.ch
- tnslib.su
- ryyw.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report