MALICIOUS — 3bc5877c50826a8be72c052c78482431778314f4ed6fe6e385f3dbb2ee1e4f11
MALICIOUS — 3bc5877c50826a8be72c052c78482431778314f4ed6fe6e385f3dbb2ee1e4f11 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3bc5877c50826a8be72c052c78482431778314f4ed6fe6e385f3dbb2ee1e4f11 - SHA-1:
17733d72cf3f8a5c003210111a95d605de8334d4 - MD5:
1d9fe9dacfc4d443f9740bbc73970051 - ssdeep:
1536:Wd6HGOY9X8gZeHeIcUSsbPzdQatNxlPw3JpIWVFrWbA43XiBaPcORWUpJ:dGOYx8gZe+IZSSLdQaDxlPO/HVFRHBUr - TLSH:
T1EE37D0F7105BED1CBF8F9683AD7B609D644EE388A122F59401C87768D06C4BEBD10A51 - Submitted as: 3bc5877c50826a8be72c052c78482431778314f4ed6fe6e385f3dbb2ee1e4f11
- File type: pdf · Size: 74422 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): Trojan.GenericKD.77366233
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://studiotecnicomartani.eu/userfiles/files/nadimazipasajifi.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged Trojan.GenericKD.77366233 (rule
Trojan.GenericKD.77366233) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://makaifruits.com/wp-content/plugins/formcraft/file-upload/server/content/files/161434b9111239---26419947236.pdf, http://tndgdemo2.com/ckfinder/userfiles/files/42771277366.pdf, http://studiotecnicomartani.eu/userfiles/files/nadimazipasajifi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/S30rS-6n6vg/uplcv?utm_term=android+chrome+password+manager
- http://makaifruits.com/wp-content/plugins/formcraft/file-upload/server/content/files/161434b9111239---26419947236.pdf
- http://tndgdemo2.com/ckfinder/userfiles/files/42771277366.pdf
- http://studiotecnicomartani.eu/userfiles/files/nadimazipasajifi.pdf
- https://vanchuyenduongsat.vn/upload/files/74460308164.pdf
- http://agroanaliz.by/upload/editor/files/japofawumoduxisesiviraj.pdf
- http://elsekmont.eu/userfiles/file/dezikagese.pdf
- http://pospatrans.cz/UserFiles/File/tamavegomepetorivid.pdf
- http://logiccpacma.com/ckfinder/userfiles/files/tiwukopenotabujukutuba.pdf
- https://www.syah.org/wp-content/plugins/super-forms/uploads/php/files/bf12f2984aea5d732584fba04288f3f1/jixulelujezi.pdf
- https://miguktour.com/FileData/ckfinder/files/20210917_83829553597C0E44.pdf
- https://eledigitalpr.it/allegati/file/xasoxesijok.pdf
- http://ziconiavip.com/uploadfck/file/lasadizixonasona.pdf
- http://www.saraviation.com/wp-content/plugins/formcraft/file-upload/server/content/files/161349b95040cf---92369088736.pdf
- http://deforma.it/userfiles/files/lulobajitozegigi.pdf
- https://agros.net/uploads/file/bewipinonad.pdf
- http://danieldesignpro.com/userfiles/97201243997.pdf
- https://mmeasar.com/mmeasarfiles/file/42417333141.pdf
- http://energy-labels.nl/userfiles/file/32550101361.pdf
- https://www.casestilistas.es/ckfinder/userfiles/files/29662190653.pdf
- http://max-metal.pl/gfx/file/lofawozexizilefojisu.pdf
- http://geonatlife.es/ckfinder/userfiles/files/62414721040.pdf
- http://www.afamaresme.org/wp-content/plugins/formcraft/file-upload/server/content/files/1613d9cad2273c---muzubabexeti.pdf
- https://www.lowdoc-loans.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16134c80237e3f---38166527456.pdf
- http://avandcie-energy.com/ckfinder/userfiles/files/18214170214.pdf
Embedded domains
- feedproxy.google.com
- makaifruits.com
- tndgdemo2.com
- studiotecnicomartani.eu
- elsekmont.eu
- logiccpacma.com
- www.syah.org
- miguktour.com
- eledigitalpr.it
- ziconiavip.com
- www.saraviation.com
- deforma.it
- agros.net
- danieldesignpro.com
- mmeasar.com
- energy-labels.nl
- www.casestilistas.es
- max-metal.pl
- geonatlife.es
- www.afamaresme.org
- www.lowdoc-loans.com.au
- avandcie-energy.com
- vanchuyenduongsat.vn
- agroanaliz.by
- pospatrans.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report