MALICIOUS — 2852ba7fd3a8edbb825b661fa82b57488441491f7d29d61ad71bcac032ab23e1
MALICIOUS — 2852ba7fd3a8edbb825b661fa82b57488441491f7d29d61ad71bcac032ab23e1 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2852ba7fd3a8edbb825b661fa82b57488441491f7d29d61ad71bcac032ab23e1 - SHA-1:
a1d24c2d2f04e99a2cdd875043ae39a6597f7ea8 - MD5:
13389be58ee2fbc8f5d3f882ad630769 - ssdeep:
1536:CfMNnGPNC/ELK/r/9dtle8jJH5HOWkNpOPl:9NnGlT2r/3tle8jJHNzPl - TLSH:
T18933C0D721F7DD0CBB8B9B43AE5F269E80CED38482A6F244514C875C909D9BE3E05A41 - Submitted as: 2852ba7fd3a8edbb825b661fa82b57488441491f7d29d61ad71bcac032ab23e1
- File type: pdf · Size: 50936 bytes
- Verdict: malicious (96/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://autavrabek.cz/obrazky/file/43142888895.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://shining4u.com/wp-content/plugins/super-forms/uploads/php/files/8b7e25b55e0e62388ea3fe8ee7a5ff36/robevutaxa.pdf, http://hide-bo.com/img/tmp/file/5980004949.pdf, http://agcslohian.com/userfiles/file/15215822418.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/YTWXjIUwRh0/uplcv?utm_term=good+fast+cars+under+5k
- https://shining4u.com/wp-content/plugins/super-forms/uploads/php/files/8b7e25b55e0e62388ea3fe8ee7a5ff36/robevutaxa.pdf
- http://hide-bo.com/img/tmp/file/5980004949.pdf
- http://agcslohian.com/userfiles/file/15215822418.pdf
- http://fashionflutters.com/ckfinder/userfiles/files/rudumugefotatusekim.pdf
- https://orangcar.com/app/webroot/upload/files/80951230855.pdf
- https://kes-stv.ru/wp-content/plugins/super-forms/uploads/php/files/67582caf9c7336a3fb71b0372190dc86/bitokokuro.pdf
- http://stylekd.ru/files/13846909090.pdf
- http://designgaleria.hu/userfiles/file/tujurogibazudu.pdf
- http://finsura-lifedirect.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16150a421caa13---nifefuvuvewot.pdf
- http://autavrabek.cz/obrazky/file/43142888895.pdf
- http://bobhendrix-law.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/sesuti.pdf
- https://dlt-nkp.com/fileupload/file/faxewugazeg.pdf
- https://gtsonline.nl/wp-content/plugins/super-forms/uploads/php/files/dgq68u55kp4tp02b6l2tt9uoje/vepiliviletufofo.pdf
- http://bacvietexpress.com/upload/userfiles/files/tobadam.pdf
- https://associazionemusicaviva.it/uploads/file/puzepozusavi.pdf
- http://dogoxuavanay.vn/uploads/files/wowivosipexiduze.pdf
- https://em.heephong.org/ethnicminorities/cmsadmin/ckfinder/files/93490521559.pdf
- http://bike-aholic.com/UserFiles/file/44638998694.pdf
- http://parejalecaros.com/adjunto/upload/fck/files/42066617137.pdf
- https://www.18fire.com/wp-content/plugins/super-forms/uploads/php/files/edcd2db88eece43a9af3a99c327c7fe6/jalukija.pdf
- http://homeloanz.net/images/e/file/74683187940.pdf
- https://x-software.cz/data/file/lutedosawosukiz.pdf
- http://aliancegroup.su/wp-content/plugins/formcraft/file-upload/server/content/files/1613fab9d72b9c---tiwusabizekesevalevujexon.pdf
- https://lorus.rs/files/rasokapijimowidam.pdf
Embedded domains
- feedproxy.google.com
- shining4u.com
- hide-bo.com
- agcslohian.com
- fashionflutters.com
- orangcar.com
- kes-stv.ru
- stylekd.ru
- finsura-lifedirect.com.au
- bobhendrix-law.com
- dlt-nkp.com
- gtsonline.nl
- bacvietexpress.com
- associazionemusicaviva.it
- em.heephong.org
- bike-aholic.com
- parejalecaros.com
- www.18fire.com
- homeloanz.net
- aliancegroup.su
- designgaleria.hu
- autavrabek.cz
- dogoxuavanay.vn
- x-software.cz
- lorus.rs
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report