MALICIOUS — 3ef6b4e7a0a89658cfd9cdbcc5e62563fe4d059d7e2bcf4f17324834e47ff55b
MALICIOUS — 3ef6b4e7a0a89658cfd9cdbcc5e62563fe4d059d7e2bcf4f17324834e47ff55b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3ef6b4e7a0a89658cfd9cdbcc5e62563fe4d059d7e2bcf4f17324834e47ff55b - SHA-1:
e2cd761bfd780569a692be013e1739cd8dc24c6d - MD5:
7f03df818da7ac22a93cc831ae4a348e - ssdeep:
3072:BPdFnN+bUDDM+F5tDfKjd31ST4DOTIP0IuUv6I4zYQBmV8o:BFFnN4iM+TdGs4DOTIsIFhtJR - TLSH:
T13A3BE1F3219BED5C7B47DF4369EA029CB08AE7C811A1EB548488A66CC57C67D7D00E90 - Submitted as: 3ef6b4e7a0a89658cfd9cdbcc5e62563fe4d059d7e2bcf4f17324834e47ff55b
- File type: pdf · Size: 109372 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://luxartparquet.com/wp-content/plugins/super-forms/uploads/php/files/b49b29e1b99863c559e99829e683c7a4/77820428523.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://chcial.ru/uplcv?utm_term=best+video+editor+for+windows+10+2020, http://mpu-beratung-brendle.de/userfiles/file/zugekebogap.pdf, https://luxartparquet.com/wp-content/plugins/super-forms/uploads/php/files/b49b29e1b99863c559e99829e683c7a4/77820428523.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://chcial.ru/uplcv?utm_term=best+video+editor+for+windows+10+2020
- http://mpu-beratung-brendle.de/userfiles/file/zugekebogap.pdf
- https://luxartparquet.com/wp-content/plugins/super-forms/uploads/php/files/b49b29e1b99863c559e99829e683c7a4/77820428523.pdf
- http://witnesstherealist.com/wp-content/plugins/super-forms/uploads/php/files/402c654164d86a4b9333d58d6047341d/betesowisapoxo.pdf
- http://bigpictureresources.com/userfilesbigpicture/file/67555998372.pdf
- http://carlaschroyen.com/content_docs/tevabudisigap.pdf
- http://www.lbf-cosmetics.com/website/wp-content/plugins/formcraft/file-upload/server/content/files/1607102c46b4ec---tifotuvikasenuzude.pdf
- http://aliglobshop.com/userfiles/file/kopigatekawugefarofaxa.pdf
- https://avonsteel.com/UserFiles/file/serewivupofepifolakog.pdf
- https://sanidom.pl/img/file/zalawofef.pdf
- http://greatnice.club/updatefiles/file/20778112576.pdf
- https://zivotzaokny.eu/res/file/68252944347.pdf
- http://rioairporttransfer.com/ckfinder/userfiles/files/kozaso.pdf
- https://gccpay.net/wp-content/plugins/super-forms/uploads/php/files/7b5dba4fdb06b6b9c6a9be7d36118cb6/88460687281.pdf
- http://osullivanspressurewashing.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c781ed8ef45---foxeme.pdf
- http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609de85221136---nimeru.pdf
- http://www.psoealora.es/ckfinder/userfiles/files/30244709024.pdf
- https://candbco.com/ckfinder/userfiles/files/70007901353.pdf
- https://www.kiteschule-kiel.de/wp-content/plugins/formcraft/file-upload/server/content/files/160ac6ba648d81---legapebosabej.pdf
- http://minhquoc.vn/ckfinder/userfiles/files/99036479762.pdf
- https://spazmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c19ae0040b4---lolirabadevadolupupi.pdf
- http://ankaser.com/userfiles/file/22974388584.pdf
- https://cashofferoregon.com/wp-content/plugins/formcraft/file-upload/server/content/files/16076088150c99---nekozozebipokexalikoda.pdf
- https://dolnoslaskialarmsmogowy.pl/imgturysta/files/xemujigebipurinavijife.pdf
- https://orkhaconstruction.com/wp-content/plugins/super-forms/uploads/php/files/r56s4n3v1sgctqjdne91asu64t/73675913271.pdf
Embedded domains
- chcial.ru
- mpu-beratung-brendle.de
- luxartparquet.com
- witnesstherealist.com
- bigpictureresources.com
- carlaschroyen.com
- www.lbf-cosmetics.com
- aliglobshop.com
- avonsteel.com
- sanidom.pl
- greatnice.club
- zivotzaokny.eu
- rioairporttransfer.com
- gccpay.net
- osullivanspressurewashing.com
- www.jamesbgriffinlaw.com
- www.psoealora.es
- candbco.com
- www.kiteschule-kiel.de
- spazmedia.com
- ankaser.com
- cashofferoregon.com
- dolnoslaskialarmsmogowy.pl
- orkhaconstruction.com
- yuktiedu.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report