MALICIOUS — 4e50eeb39c3607a05829043a7ee92d11fe10b99a957f61ce086851eef42c3f99
MALICIOUS — 4e50eeb39c3607a05829043a7ee92d11fe10b99a957f61ce086851eef42c3f99 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4e50eeb39c3607a05829043a7ee92d11fe10b99a957f61ce086851eef42c3f99 - SHA-1:
ad1243354936da66677fd813ef2bed0a574218a8 - MD5:
7d2c9cdad74b988223bbc3314d7d9820 - ssdeep:
1536:ugLztchS4Z/qAjUSwHNroOMuwS5zIktWaRUlT3k/WxvGWxApf:dcS4Z/qAgDyLS5zJtRM1xvTm - TLSH:
T13C35D0E32157EE4C765DAB43AD7B137A8ACAD78C9162D050408C6B6DA0EC47E7F00A51 - Submitted as: 4e50eeb39c3607a05829043a7ee92d11fe10b99a957f61ce086851eef42c3f99
- File type: pdf · Size: 60982 bytes
- Verdict: malicious (94/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://luatsuavina.com/userfiles/file/68239700433.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=synonym+for+hardworker, http://chrisnoblelaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/16215555292.pdf, https://foursservices.com/nbloom/fckuploads/file/powufarod.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=synonym+for+hardworker
- http://chrisnoblelaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/16215555292.pdf
- https://foursservices.com/nbloom/fckuploads/file/powufarod.pdf
- https://luatsuavina.com/userfiles/file/68239700433.pdf
- https://fengshan-zhennangong.org/upload/ckfinder/files/69203901142.pdf
- http://www.expo-hotel.com/english/wp-content/plugins/formcraft/file-upload/server/content/files/1613f127399468---72843543452.pdf
- http://rayhovietnam.vn/upload/files/zekisema.pdf
- https://aarhuskortet.dk/images/file/99008703621.pdf
- https://empresa-venta.hr/files/48274973283.pdf
- https://tjpapigroup3.com/contents/files/gukirasanazilitenizabosow.pdf
- https://chinese-wall.tw/upload/files/muxufobememejaset.pdf
- http://iphonedown.com/ckfinder/userfiles/files/xesidevejomisik.pdf
- https://www.autopsrus.com/ckfinder/userfiles/files/mefewed.pdf
- http://mynotary.ca/sites/all/sites/mynotary.ca/files/69792043527.pdf
- http://kvarkeno56.ru/userfiles/file/66993806546.pdf
- http://nhatnguyen.vn/media/ftp/file/rezubevanujemorubedorire.pdf
- http://solo-reisen.com/media/images/file/45974788784.pdf
- http://kasand.com/userfiles/xupijawivuwodiloberos.pdf
- http://aqbnb.com/uploadfile/file/34592777099.pdf
- http://thuexe7cho.vn/upload/files/34045008183.pdf
- http://www.heatandgas.com/EditorImages/file/zikoxonav.pdf
- http://cloverdiamond.com/file/jewenepufe.pdf
- http://eortak.com/img/fck_temp/file/bedole.pdf
- http://phuvuongcorp.com/luutru/files/wixijenerewasuxup.pdf
- http://chinajessie.com/seadata/data/uploads/img/file/16316001511.pdf
Embedded domains
- huntic.ru
- chrisnoblelaw.com
- foursservices.com
- luatsuavina.com
- fengshan-zhennangong.org
- www.expo-hotel.com
- tjpapigroup3.com
- chinese-wall.tw
- iphonedown.com
- www.autopsrus.com
- mynotary.ca
- kvarkeno56.ru
- solo-reisen.com
- kasand.com
- aqbnb.com
- www.heatandgas.com
- cloverdiamond.com
- eortak.com
- phuvuongcorp.com
- chinajessie.com
- rjiminfra.com
- cdseoulps.com
- rayhovietnam.vn
- aarhuskortet.dk
- empresa-venta.hr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report