MALICIOUS — 44a80cc2ac8a9db90116ffe3679a06ebc4b57778afeefd7874544ff11258bd39
MALICIOUS — 44a80cc2ac8a9db90116ffe3679a06ebc4b57778afeefd7874544ff11258bd39 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
44a80cc2ac8a9db90116ffe3679a06ebc4b57778afeefd7874544ff11258bd39 - SHA-1:
8c5c03816aaa3a819942e33f42204f2651d1283c - MD5:
7080955b1a1519a8b027224b64751992 - ssdeep:
1536:s+Zpolb1EOBg8rmk5YR/7jG7J7CAjuQWGR22:jZpolb1vrm2YN7jG7J7PI2 - TLSH:
T16235DFE740B3DE4C7A6F9B836FB74769C98EE3885152D1A1004C5769D0EC97E3E11A01 - Submitted as: 44a80cc2ac8a9db90116ffe3679a06ebc4b57778afeefd7874544ff11258bd39
- File type: pdf · Size: 58134 bytes
- Verdict: malicious (94/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://astoraccessories.com/uploads/ckfinder/files/67783399342.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ketchas.ru/uplcv?utm_term=war+full+movie+online, http://imoroz.by/upload/file/20497640408.pdf, https://fmpride.com/wp-content/plugins/super-forms/uploads/php/files/46f8369249d7a16ba37c193326ce27f9/71223576513.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ketchas.ru/uplcv?utm_term=war+full+movie+online
- http://imoroz.by/upload/file/20497640408.pdf
- https://fmpride.com/wp-content/plugins/super-forms/uploads/php/files/46f8369249d7a16ba37c193326ce27f9/71223576513.pdf
- http://mtt-association.fr/upload/file/julowupikurenorijad.pdf
- https://astoraccessories.com/uploads/ckfinder/files/67783399342.pdf
- https://istanajp2.com/contents/files/parepitutobozupokireseto.pdf
- http://krzysztofmalec.pl/gfx/fck/file/94933939719.pdf
- https://www.artikel238.nl/emmwebbit/resources/ckfinder/userfiles/files/tejumisemoxipilasiwusajad.pdf
- http://sgd42.ru/userfiles/file/vuzariritotapubi.pdf
- http://msslink.ru/userfiles/files/51216992961.pdf
- https://www.medicalart.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1612fcc382e42c---gitosumebijijajogipobenim.pdf
- http://arebiatours.com/uploads/files/lirabisupugabomotuxekili.pdf
- https://santa.my/images/users/00000000/files/duxuzovojomu.pdf
- http://divelife.kz/files/file/dujiganowabijupego.pdf
- https://movimientofamiliadejesus.com/images/uploaded/file/72956141816.pdf
- https://www.ftha.org/admin/ckfinder/userfiles/files/28313904523.pdf
- http://arenda-v-novosibirske.ru/ckfinder/userfiles/files/9768602680.pdf
- http://www.miyadenthai.com/image/upload/File/8458073229.pdf
- http://spielundlicht.de/content_provider/documents/files/geluduxaga.pdf
- http://kovofilm.cz/userfiles/file/joguxo.pdf
- http://facilitymanagementassociates.com/survey/userfiles/files/46483866036.pdf
- http://jd6618.com/jd6618/file/2021-9/file/LwpCms2021_09_14_11_43_54_5744.pdf
- https://kindliving.org/wp-content/plugins/super-forms/uploads/php/files/tmp/magegi.pdf
- http://heninrealty.com/userfiles/files/82583823702.pdf
- http://www.520amis.com/upload/files/wusijenovumofu.pdf
Embedded domains
- ketchas.ru
- fmpride.com
- mtt-association.fr
- astoraccessories.com
- istanajp2.com
- krzysztofmalec.pl
- www.artikel238.nl
- sgd42.ru
- msslink.ru
- arebiatours.com
- movimientofamiliadejesus.com
- www.ftha.org
- arenda-v-novosibirske.ru
- www.miyadenthai.com
- spielundlicht.de
- facilitymanagementassociates.com
- jd6618.com
- kindliving.org
- heninrealty.com
- www.520amis.com
- c-amc.com
- imoroz.by
- www.medicalart.com.tr
- santa.my
- divelife.kz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report