MALICIOUS — 2a53ee8f431e8f64f45d35d7b079b4f769c6837f1c53089e949a07d74f27456c
MALICIOUS — 2a53ee8f431e8f64f45d35d7b079b4f769c6837f1c53089e949a07d74f27456c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2a53ee8f431e8f64f45d35d7b079b4f769c6837f1c53089e949a07d74f27456c - SHA-1:
8ea021f7f770aaa479a50723df6a5a1ab2ae4a5b - MD5:
5cdbc20a2e3221a9ae388655237d16d5 - ssdeep:
1536:V7aio2bEBs6BGYj/dT5kkhFR6zwzG9ETIQhLDkEBWw1PW70WOpOwrP:Rc2oBzjdTx60zaETIcLDbPcRwrP - TLSH:
T11F37C0F300E7DD5CBECB6A076BAF25A9948AD2C821A3E04110CCB7AD946D5BF3D11941 - Submitted as: 2a53ee8f431e8f64f45d35d7b079b4f769c6837f1c53089e949a07d74f27456c
- File type: pdf · Size: 71200 bytes
- Verdict: malicious (96/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/2c351e8fb9b8a05f36902a0ce71be1f5/baximo.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=past+simple+and+continuous+exercises+with+answers+pdf, http://jsushibrea.com/uploads/files/danozomaditarikiwovuf.pdf, http://salonlomi.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1608f80775745a---34820380477.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=past+simple+and+continuous+exercises+with+answers+pdf
- http://jsushibrea.com/uploads/files/danozomaditarikiwovuf.pdf
- http://salonlomi.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1608f80775745a---34820380477.pdf
- http://www.fullmooneye.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ba9b6da4c14---30500639336.pdf
- https://lescourailleurs.com/upload/editor/file/sumenekado.pdf
- https://danielfelber.ch/userfiles/file/67827866939.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160fa854bc61af---gufili.pdf
- http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/2c351e8fb9b8a05f36902a0ce71be1f5/baximo.pdf
- http://www.viksexteriors.com/wp-content/plugins/formcraft/file-upload/server/content/files/16117043d1e251---sizuwataled.pdf
- http://younewstoday.com/task/userimages/file/bijix.pdf
- http://be1971.com/clients/a/a1/a19be2fc4cf8b198b52f296748481ce5/File/bugivivowutuda.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d1986462672---menetupurerosuneroje.pdf
- https://connect.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/38c9b1e72c231dd7a3267c8f7d567c06/rafomawipo.pdf
- https://nada70.org/userfiles/file/22771930223.pdf
- https://foulardfotografando.it/file/98727887597.pdf
- http://www.webtony.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16130d9bb7bc78---47572800616.pdf
- http://www.onegelha.com/wp-content/plugins/super-forms/uploads/php/files/48f002f2d5ffebeabf86c6e1dff8e11a/77903135877.pdf
- https://pmeds.us/userfiles/file/tokafajud.pdf
- https://webgirls-studio.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b479557e2a9---38628739147.pdf
- http://basyapiemlak.com/yukleme_klasoru/userfiles/file/8443165821.pdf
- https://master.plus/wp-content/plugins/super-forms/uploads/php/files/1556e36cae9944d1a659207bd78c9a59/12283572769.pdf
- http://www.olympussverige.se/wp-content/plugins/super-forms/uploads/php/files/k5853i7ss1kb0m479tjon95dvb/xofabefezanunigibezuw.pdf
- https://ohligschlaeger-berger.de/wp-content/plugins/formcraft/file-upload/server/content/files/16078a868e35d9---gumadexigeg.pdf
- http://krakowska98.com/zdjecia/fck/file/50794486937.pdf
- https://microfocus-realize2020mea.com/wp-content/plugins/super-forms/uploads/php/files/3acf1b0764dbb0fd9444cf060771fbdc/81958424658.pdf
Embedded domains
- crysiq.ru
- jsushibrea.com
- salonlomi.pl
- www.fullmooneye.com
- lescourailleurs.com
- danielfelber.ch
- www.1000ena.com
- chagatea.ru
- www.viksexteriors.com
- younewstoday.com
- be1971.com
- connect.allianceflooring.net
- nada70.org
- foulardfotografando.it
- www.webtony.com.br
- www.onegelha.com
- pmeds.us
- webgirls-studio.com
- basyapiemlak.com
- www.olympussverige.se
- ohligschlaeger-berger.de
- krakowska98.com
- microfocus-realize2020mea.com
- master.plus
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report