MALICIOUS — 4f6768ee90fd214be6ff8ae952c86b8e4017eed35f6344e210eacc3eb4d8c147
MALICIOUS — 4f6768ee90fd214be6ff8ae952c86b8e4017eed35f6344e210eacc3eb4d8c147 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4f6768ee90fd214be6ff8ae952c86b8e4017eed35f6344e210eacc3eb4d8c147 - SHA-1:
3450d2b4209001e8f11cb4571a122ba559534469 - MD5:
573940c903dbe14753b597cd80ae762d - ssdeep:
768:2w+Knpl/2KGhiijw/aK2Di9TRiGd7STAedAIVCjuteI2:2wT/YoiQaM9wGoXdAIVCjW12 - TLSH:
T1E631BFE624A3EF5D7E8D5B52BA6F067DA489E38456B6E340800C4F4CA1BCD3D2D28445 - Submitted as: 4f6768ee90fd214be6ff8ae952c86b8e4017eed35f6344e210eacc3eb4d8c147
- File type: pdf · Size: 39631 bytes
- Verdict: malicious (96/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ovartec.com/wp-content/plugins/formcraft/file-upload/server/content/files/16108e66295283---30316596995.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://chcial.ru/uplcv?utm_term=importance+of+filipino+values+pdf, http://feynburg-uhren.de/uploads/71625469065.pdf, https://www.democratum.com/wp-content/plugins/super-forms/uploads/php/files/068b7ff176632a00fd63e018d5c738fa/951130521.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://chcial.ru/uplcv?utm_term=importance+of+filipino+values+pdf
- http://feynburg-uhren.de/uploads/71625469065.pdf
- https://www.democratum.com/wp-content/plugins/super-forms/uploads/php/files/068b7ff176632a00fd63e018d5c738fa/951130521.pdf
- https://agsposure.org/wp-content/plugins/super-forms/uploads/php/files/d801928241f9f2c69c0db36cb4d6946d/80901186661.pdf
- http://ovartec.com/wp-content/plugins/formcraft/file-upload/server/content/files/16108e66295283---30316596995.pdf
- https://arch.ua/ckfinder/userfiles/files/jokematanuje.pdf
- https://baxsporthorses.com/userfiles/file/momesukuwudonomeror.pdf
- https://felicityokolo.com/file/jogofidajetewinefonigeri.pdf
- https://marciasmithconsulting.com/wp-content/plugins/super-forms/uploads/php/files/5b00369134cf9a569cd1d6f39ac26a5b/68583648194.pdf
- http://allasclub.com/campannas/file/makuvatusifokusaxukexo.pdf
- http://n2nnetworks.com/files/others/86586963712.pdf
- http://westernmaki.com/uploads/files/dutuwusudekemitubidis.pdf
- http://philippinesroadshow.com/wp-content/plugins/super-forms/uploads/php/files/61cc416094f6d5ae28ca8dff6d77bb58/12549658504.pdf
- http://espacioschillout.es/images/admin/file/fapepilolagugadejape.pdf
- https://www.democratum.com/wp-content/plugins/super-forms/uploads/php/files/c91a0eb0349d7724f01561854494c
Embedded domains
- chcial.ru
- feynburg-uhren.de
- www.democratum.com
- agsposure.org
- ovartec.com
- arch.ua
- baxsporthorses.com
- felicityokolo.com
- marciasmithconsulting.com
- allasclub.com
- n2nnetworks.com
- westernmaki.com
- philippinesroadshow.com
- espacioschillout.es
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report