MALICIOUS — 3b21d6daee544881390d8328fb2ac7e4e3a7b1fba164719b56b2f4b82bdaf299
MALICIOUS — 3b21d6daee544881390d8328fb2ac7e4e3a7b1fba164719b56b2f4b82bdaf299 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3b21d6daee544881390d8328fb2ac7e4e3a7b1fba164719b56b2f4b82bdaf299 - SHA-1:
692eff26637d1013a190e912437841ba53eeb049 - MD5:
f65e38ae28580fc3679c6f6a0a8e4372 - ssdeep:
1536:UsHT/UX/m2EpvQ/UxIsmRmG284r2Pgkxp9sr8vqAj3tQmy8WUpO7qWCrO4EVNt+x:n/UPHEthx6UrNkxp9sWCmyf71bjIx - TLSH:
T12839C0F731D7DD1CA79A5B036AF711686089E3882272FA90548CBA2CC9BC5FD7E14901 - Submitted as: 3b21d6daee544881390d8328fb2ac7e4e3a7b1fba164719b56b2f4b82bdaf299
- File type: pdf · Size: 89874 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://easyliveconstruction.com/ci/userfiles/files/78586841091.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://reazfarah.com/ckfinder/userfiles/files/duxagobar.pdf, http://haokunchem.cn/upload/files/94064894778.pdf, http://eyela.kr/uploadfile/fckeditor/file/79378412353.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/S30rS-6n6vg/uplcv?utm_term=plants+vs+zombies+hack+all+plants
- https://reazfarah.com/ckfinder/userfiles/files/duxagobar.pdf
- http://haokunchem.cn/upload/files/94064894778.pdf
- http://eyela.kr/uploadfile/fckeditor/file/79378412353.pdf
- https://functionalmovement.gr/wp-content/plugins/super-forms/uploads/php/files/8ffa23713b75860dc3eff819a0d45000/mejibobijebuwadex.pdf
- http://www.musicmaestrodiscos.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/161456c8b1417a---jojalebiv.pdf
- https://vettercycles.ch/userfiles/files/94289272.pdf
- http://frederickfollows.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1613a06924c249---tunogegolewekinozila.pdf
- http://easyliveconstruction.com/ci/userfiles/files/78586841091.pdf
- http://easternhoteljeju.com/FileData/ckfinder/files/20210917_9A2772DA3874F235.pdf
- http://onlinecommerce.bg/uploads/pages/files/47291698441.pdf
- http://sklepjola.pl/userfiles/file/82261299388.pdf
- http://cosmoscm.com/contents/files/73997916255.pdf
- http://cctsw.net/whly/up_files/FCK/file/20210908_095440_142.pdf
- https://www.glasswindowequipment.com/wp-content/plugins/super-forms/uploads/php/files/d1e4dd71b25948f21bb4738d54bee9b2/82010526688.pdf
- https://orig-shop-gsm.ro/ckfinder/userfiles/files/44514979866.pdf
- http://ristorantebiscione.com/userfiles/files/58060599992.pdf
- https://mttrasportisrl.it/dati/upload/file/rizusiwikex.pdf
- http://vagtteam.com/userfiles/Files/56439836014.pdf
- https://yarsan.ru/wp-content/plugins/super-forms/uploads/php/files/7fa3dd6fe92fb959786be631dc7c1aa1/55587320238.pdf
- http://www.taimaobi.com/admin/ckfinder/userfiles/files/46207855912.pdf
- http://mko-yug.ru/wp-content/plugins/super-forms/uploads/php/files/11943a3b3bf69f8311dacadd70c38e38/junozaganerepujas.pdf
- https://henseltech.cz/userfiles/file/84836827723.pdf
- http://tingchucontrol.com/Uploadfiles/files/muxopeti.pdf
- https://tortugafilms.ca/adminfiles/file/1097138541.pdf
Embedded domains
- feedproxy.google.com
- reazfarah.com
- haokunchem.cn
- eyela.kr
- www.musicmaestrodiscos.co.uk
- vettercycles.ch
- frederickfollows.co.uk
- easyliveconstruction.com
- easternhoteljeju.com
- sklepjola.pl
- cosmoscm.com
- cctsw.net
- www.glasswindowequipment.com
- ristorantebiscione.com
- mttrasportisrl.it
- vagtteam.com
- yarsan.ru
- www.taimaobi.com
- mko-yug.ru
- tingchucontrol.com
- tortugafilms.ca
- jobsmarttampabay.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report