MALICIOUS — 341155bdfb00160a031f352a64fb3fcf442ca928a6af55e9cd107b54d52cc04c
MALICIOUS — 341155bdfb00160a031f352a64fb3fcf442ca928a6af55e9cd107b54d52cc04c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
341155bdfb00160a031f352a64fb3fcf442ca928a6af55e9cd107b54d52cc04c - SHA-1:
480b08f355694852f264be010a67aa66ed4b9031 - MD5:
97aa9c3e51cd977e11d70ccdc335385b - ssdeep:
1536:ZwhtnEAgVEvnVNV/Df6q8RxMPl+sM55DJaxPPbZPY4K6Wd7s5GmZWOpOZByDZ:UtngVynVP+qQxc+sK3aRFKfs5GmyZA - TLSH:
T1E439D0F37293DD5CB29BCB0369F90198244EE3886166EA944588B77CD9BC5BD7F00A01 - Submitted as: 341155bdfb00160a031f352a64fb3fcf442ca928a6af55e9cd107b54d52cc04c
- File type: pdf · Size: 87298 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ukrainski-rosyjski.pl/userfiles/file/vapumasogivilozawodaxe.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://nepalmicrofinancesummit.org/userfiles/files/kixixeweribibaxenobem.pdf, https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/f3554722e444ada98d13eabdb569c51f/34633814126.pdf, http://sarljarry.fr/userfiles/file/73708593362.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/ngfLrbzwjls/uplcv?utm_term=increase+pdf+size+in+mb
- https://nepalmicrofinancesummit.org/userfiles/files/kixixeweribibaxenobem.pdf
- https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/f3554722e444ada98d13eabdb569c51f/34633814126.pdf
- http://sarljarry.fr/userfiles/file/73708593362.pdf
- http://e1pl2.nazwa.pl/busy/fotki/file/kenamefaj.pdf
- http://ukrainski-rosyjski.pl/userfiles/file/vapumasogivilozawodaxe.pdf
- https://noursportevents.com/wheelmarine/userfiles/file/36726013853.pdf
- http://kdwatch.net/upload/files/2021090103072667.pdf
- http://assisdrive.pt/userfiles/file/55787777829.pdf
- https://www.conkite.com/wp-content/plugins/super-forms/uploads/php/files/63fece2b400d87280a40012de83bf22c/37179032203.pdf
- http://aiswaryamatrimonials.com/fck_uploads/file/fetifade.pdf
- https://kuechentreff-schmid.de/wp-content/plugins/super-forms/uploads/php/files/ahul2tb3a6surmt222kij6qdh4/zedowa.pdf
- http://ampletrekking.com/userfiles/file/94823611081.pdf
- http://pb-book.com/user_file/file/30315954665.pdf
- http://discoveryenglish.org/wp-content/plugins/formcraft/file-upload/server/content/files/160710136069fa---pagupivakinazep.pdf
- https://hantverksakuten.se/ckfinder/userfiles/files/40612535730.pdf
- http://saokienviet.com/uploads/image/files/fotepoposugunew.pdf
- https://www.lavishlook.se/wp-content/plugins/super-forms/uploads/php/files/0b610fdc9e09d63c2cd5119b3cec986b/80186875295.pdf
- http://www.putnamtaxi.net/wp-content/plugins/formcraft/file-upload/server/content/files/16084b56d1f489---22587992710.pdf
- https://maribon.net/app/webroot/files/userfiles/files/mubabofinefokaxufuz.pdf
- https://sellos-mecanicos.com/wp-content/plugins/super-forms/uploads/php/files/a21fa4fa5d9c939508b29263e1f5e949/zugetipuzasiwotomowib.pdf
- http://thomas-zigon.de/images/file/72370720555.pdf
- https://amesmedicalservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a6b2d9afc3a---peloritowajodagovokusade.pdf
- https://nationalcardsolutions.com/wp-content/plugins/formcraft/file-upload/server/content/files/161246bde1779b---sijefizavonusafanujepo.pdf
- https://unitedcardsolutions.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e2cc352fd63---tepeporexidisumes.pdf
Embedded domains
- feedproxy.google.com
- nepalmicrofinancesummit.org
- ahi.com.ua
- sarljarry.fr
- e1pl2.nazwa.pl
- ukrainski-rosyjski.pl
- noursportevents.com
- kdwatch.net
- www.conkite.com
- aiswaryamatrimonials.com
- kuechentreff-schmid.de
- ampletrekking.com
- pb-book.com
- discoveryenglish.org
- hantverksakuten.se
- saokienviet.com
- www.lavishlook.se
- www.putnamtaxi.net
- maribon.net
- sellos-mecanicos.com
- thomas-zigon.de
- amesmedicalservices.com
- nationalcardsolutions.com
- unitedcardsolutions.com
- www.w3.org
File paths
- u:\L
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report