MALICIOUS — 42071edca06a60d672d2c3349260bf0e83642daf454b1f3719c86f17f9ee71d2
MALICIOUS — 42071edca06a60d672d2c3349260bf0e83642daf454b1f3719c86f17f9ee71d2 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
42071edca06a60d672d2c3349260bf0e83642daf454b1f3719c86f17f9ee71d2 - SHA-1:
9a787794fd630093a9f1ad447465dba2a65789f5 - MD5:
316de8ba73146d84752df1327994a681 - ssdeep:
1536:Oi9zUGPKVdPP77FrEdRXPf2LjHFVDWXxaRV0WUpO7sEEHCd:WVlBWWjPRV37sZY - TLSH:
T19037BEF3219BDC8CBB4A9F031DDA1198A18AE7892172EB604485B76CC4BC9BDBF10511 - Submitted as: 42071edca06a60d672d2c3349260bf0e83642daf454b1f3719c86f17f9ee71d2
- File type: pdf · Size: 75965 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://iamluno.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613b3ab6a4308---puxiwababu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cructi.ru/uplcv?utm_term=android+get+my+ip, https://iamluno.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613b3ab6a4308---puxiwababu.pdf, http://househouse.it/userfiles/files/70288841625.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cructi.ru/uplcv?utm_term=android+get+my+ip
- https://iamluno.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613b3ab6a4308---puxiwababu.pdf
- http://househouse.it/userfiles/files/70288841625.pdf
- http://duoctruongxuan.vn/userfiles/image/file/92162979298.pdf
- http://sanarina-coaching.de/ckfinder/userfiles/files/48339825813.pdf
- https://fuoriscena.eu/file/zetajivotuwawemoxadekuku.pdf
- http://chulatutoracademy.com/chulatutor/ckfinder/userfiles/files/jilezogakewosidimurafive.pdf
- http://alacartedesign.de/userfiles/file/34951097001.pdf
- http://tnslib.net/userfiles/files/vedaworazuvoteliz.pdf
- http://sicompk.com/survey/userfiles/files/10323800544.pdf
- https://portsidestrategies.com/wp-content/plugins/super-forms/uploads/php/files/bb63a19a95bf5e1be30ee2723e94a0db/60602915037.pdf
- http://sspvjd.com/FileData/ckfinder/files/20210912_1851F112485463BA.pdf
- https://textmakareknutsson.se/upload/image/93856364580.pdf
- http://zssadkowice.pl/pliki/79646806292.pdf
- http://aeronautike.com/userfiles/file/janapukufasipa.pdf
- https://asiquim.com/ckfinder/userfiles/files/jejavorexamupakikor.pdf
- http://bularz-auto.pl/images/userfiles/file/78754118031.pdf
- https://psychotherapie-dr-albrecht.de/wp-content/plugins/formcraft/file-upload/server/content/files/16141f6f646790---zizenalaxupajijesixepi.pdf
- http://weiken-rc.com/upload/files/gudofefazagosole.pdf
- http://sarahscupcakery.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614716a86b5d1---75235008800.pdf
- https://darshanam.com/ckfinder/userfiles/files/sezorepewi.pdf
- http://angelofthewinds.net/ckfinder/userfiles/files/goriruzimuteregimemeg.pdf
- http://bobas24.pl/Upload/file/zofezebagomodozunaraduz.pdf
- http://zulassung4you.de/bilder/file/siremaxojisu.pdf
- http://health-bridge.in/upload/file/levog.pdf
Embedded domains
- cructi.ru
- iamluno.com
- househouse.it
- sanarina-coaching.de
- fuoriscena.eu
- chulatutoracademy.com
- alacartedesign.de
- tnslib.net
- sicompk.com
- portsidestrategies.com
- sspvjd.com
- textmakareknutsson.se
- zssadkowice.pl
- aeronautike.com
- asiquim.com
- bularz-auto.pl
- psychotherapie-dr-albrecht.de
- weiken-rc.com
- sarahscupcakery.com
- darshanam.com
- angelofthewinds.net
- bobas24.pl
- zulassung4you.de
- health-bridge.in
- parc-hotel.info
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report