MALICIOUS — 42927da83b99fee652e9058eb44df10e5a0fd330cc2a4ab6a22c13aaff88529b
MALICIOUS — 42927da83b99fee652e9058eb44df10e5a0fd330cc2a4ab6a22c13aaff88529b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
42927da83b99fee652e9058eb44df10e5a0fd330cc2a4ab6a22c13aaff88529b - SHA-1:
000e2b705a1781de1b0a25964490ed1da1c19149 - MD5:
ac56d8fa04a40d297cd0293d3080bafd - ssdeep:
1536:Xz7V2bDkW1jTvMcLq3W+RkdA7M8hYtcEbmZwFWHpOvktu1vn2W8VaXZuVrAmv4ph:vkjz3LKr+dAYuYtcEbmSvksnGGorfEj1 - TLSH:
T1CE38CFF3219BDE9C3587DF0369A312A97009D7846232F661518C7A6CCA7C9BDBF04512 - Submitted as: 42927da83b99fee652e9058eb44df10e5a0fd330cc2a4ab6a22c13aaff88529b
- File type: pdf · Size: 84142 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://zit-tech.com/userfiles/files/8449809213.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=duplex+play+apk+mod, https://banderlogclub.ru/Files/file/satanemofudorizozurow.pdf, https://infiniteprospects.com/FCKeditor/file/xolijufafotoli.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=duplex+play+apk+mod
- https://banderlogclub.ru/Files/file/satanemofudorizozurow.pdf
- https://infiniteprospects.com/FCKeditor/file/xolijufafotoli.pdf
- http://cateringkieuan.com/uploads/userfiles/file/15962838721.pdf
- http://njuhome.pl/ckfinder/userfiles/files/murixewutegeranese.pdf
- http://zit-tech.com/userfiles/files/8449809213.pdf
- http://kondicionery-vidnoe.ru/upload_picture/file/57506836492.pdf
- http://abw10thstreetne.com/uploads/files/15490329215.pdf
- http://le-bouquet.be/userfiles/files/ruketapewegezomasufew.pdf
- https://feldmann-spedition.de/pics/userfiles/file/lolurudizen.pdf
- https://heureka-cz.eu/files/99891073266.pdf
- http://brenderup.ro/mm/file/77814954040.pdf
- http://wish-pharma.com/upload/files/repefit.pdf
- https://cheeselicious.net/UserFiles/file/wigekizaxavok.pdf
- http://lesen-und-schenken.de/userfiles/files/delikugixozutajunerafita.pdf
- http://fredericjean.net/oplusco/file/40782168710.pdf
- http://tinhdauvietnam.vn/upload/files/pazawajidudakufovanisasu.pdf
- http://fortlauderdalelimorental.net/wp-content/plugins/formcraft/file-upload/server/content/files/16130200dd4e36---xolivuwevepamotadan.pdf
- https://joyfool.art/wp-content/plugins/super-forms/uploads/php/files/4acc47084e9932911e8182ae5a852d85/mumegon.pdf
- http://jplus-ag.com/upload/files/BodyFile__61354500A0400.pdf
- http://www.feniuniversity.edu.bd/app/webroot/ckfinder/userfiles/files/masadonaxeri.pdf
- http://umbabox.com/userfiles/file/34712282723.pdf
- http://eastcity.hu/ufiles/file/zixim.pdf
- https://www.golddustdental.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f5d45c792e---migosatedusejuluropu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- huntic.ru
- banderlogclub.ru
- infiniteprospects.com
- cateringkieuan.com
- njuhome.pl
- zit-tech.com
- kondicionery-vidnoe.ru
- abw10thstreetne.com
- le-bouquet.be
- feldmann-spedition.de
- heureka-cz.eu
- wish-pharma.com
- cheeselicious.net
- lesen-und-schenken.de
- fredericjean.net
- fortlauderdalelimorental.net
- jplus-ag.com
- umbabox.com
- www.golddustdental.com
- www.w3.org
- purl.org
- ns.adobe.com
- brenderup.ro
- tinhdauvietnam.vn
- joyfool.art
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report