MALICIOUS — 2cb56007d99da9fb6d1ad27098747db687b07d6caa31f0ab35bbe357df02d5ff
MALICIOUS — 2cb56007d99da9fb6d1ad27098747db687b07d6caa31f0ab35bbe357df02d5ff is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2cb56007d99da9fb6d1ad27098747db687b07d6caa31f0ab35bbe357df02d5ff - SHA-1:
635291cdb99f3174eda0f8d0eb72796b021d235b - MD5:
1cf91c94355ebd009b4d6092304010ec - ssdeep:
1536:cqnITMqOjowQPtPdZbX7Oooj71EsBi94eWCpOViAKEuWY7OJqm5x4TGMT:9Ib+ePddOoojpEsB7ViA7OOUmT4r - TLSH:
T15B39D1F3109BDD8C765A4F47BAFB2128218DE3986132DE9050887A3C89786FDAF04951 - Submitted as: 2cb56007d99da9fb6d1ad27098747db687b07d6caa31f0ab35bbe357df02d5ff
- File type: pdf · Size: 88254 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.theflightfest.com/wp-content/plugins/formcraft/file-upload/server/content/files/16164b1e95b329---36719167025.pdf - network signal, weight 0.70, confidence 0.80
- Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://afslab.asia/upload/files/43955296041.pdf, https://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/161515d1ba43f5---fivobudewolivutakefugif.pdf, http://www.theflightfest.com/wp-content/plugins/formcraft/file-upload/server/content/files/16164b1e95b329---36719167025.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Gsjc/~3/EqozwcbAC44/uplcv?utm_term=chopin+best+piano+pieces
- http://afslab.asia/upload/files/43955296041.pdf
- https://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/161515d1ba43f5---fivobudewolivutakefugif.pdf
- http://www.theflightfest.com/wp-content/plugins/formcraft/file-upload/server/content/files/16164b1e95b329---36719167025.pdf
- http://www.ecrivains-consult.fr/easyonline/ckfinder/userfiles/files/nojojoxubeparolowasisofa.pdf
- http://bizwd.com/wp-content/plugins/formcraft/file-upload/server/content/files/16156276564edc---89074763616.pdf
- http://tartak-monis.pl/tartak/images/file/7011622298.pdf
- http://manuale.aziendasulweb.it/userfiles/files/63834374410.pdf
- https://honkakuji.jp/honkakuji/images/ckfinder/files/11839583776.pdf
- http://abwlondonblvd.com/uploads/files/tisozogepegelefajamu.pdf
- https://rafaela-motores.com/userfiles/file/6141421727.pdf
- http://support-cmu.com/filedata/file/78106324824.pdf
- https://dmddsgn.com/wp-content/plugins/super-forms/uploads/php/files/862b48558258acefcd53b496b52815ac/98715805719.pdf
- http://form4concrete.ru/pics/cont/file/wakosejulux.pdf
- https://floridagreatescape.com/media/file/82878312293.pdf
- https://shotclock.ca/wp-content/plugins/super-forms/uploads/php/files/e2d591273388f0e6329db8fcc1c239ca/tovinakibokinevofu.pdf
- http://skkl.cn/filespath/files/20210929180532.pdf
- https://ls-machinery.com/uploadpic/files/202110032323351432.pdf
- http://upnbkk.com/file_media/file_image/file/pupufoterezikavimi.pdf
- http://aatmicscience.org/asuserfiles/file/lesepaporoza.pdf
- https://bearings.vn/images/ckeditor/files/xokufof.pdf
- https://www.mppoa.cloudlinesystems.com/assets/ckfinder/userfiles/files/35326291602.pdf
- http://hondatayho.top/img-ngocbao/files/40508937962.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- afslab.asia
- klingende-zeder.de
- www.theflightfest.com
- www.ecrivains-consult.fr
- bizwd.com
- tartak-monis.pl
- manuale.aziendasulweb.it
- honkakuji.jp
- abwlondonblvd.com
- rafaela-motores.com
- support-cmu.com
- dmddsgn.com
- form4concrete.ru
- floridagreatescape.com
- shotclock.ca
- skkl.cn
- ls-machinery.com
- upnbkk.com
- aatmicscience.org
- www.mppoa.cloudlinesystems.com
- hondatayho.top
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report