MALICIOUS — 52936911f18336a46d87a21bc4f50285cae79ecda04b2238f417cbd40a859bcf
MALICIOUS — 52936911f18336a46d87a21bc4f50285cae79ecda04b2238f417cbd40a859bcf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
52936911f18336a46d87a21bc4f50285cae79ecda04b2238f417cbd40a859bcf - SHA-1:
ca8c444f6077c657fe78b067e720f95f9388fbda - MD5:
c9a170db97e6faafa3dba8418676c7be - ssdeep:
1536:Y6PM8B2jrGgHoL4s+S6Rx1gMIsPBaKyzzQr+s2vIsxWf7ejkVFKTXdlgfWwpOSxq:RP723NILH+NJ2zzQCs2wJ7lVFKbdlgSR - TLSH:
T11239D0F352D7DD4CB68BDB036BF621DCA04AE38861A2AB9106887B3CD47C5BD7A10550 - Submitted as: 52936911f18336a46d87a21bc4f50285cae79ecda04b2238f417cbd40a859bcf
- File type: pdf · Size: 86603 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ilink.pl/userfiles/file/pazajebutokuxebobirok.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://www.hkwebdesign.com.hk/wp-content/plugins/formcraft/file-upload/server/content/files/16164de885392a---50821078038.pdf, http://morebricks.com/ckfinder/userfiles/files/jututigeduzekiz.pdf, https://esteticarcare.com/wp-content/plugins/super-forms/uploads/php/files/3cd4b3e38982b57b877145677841c497/goxanumivewitubu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/Xvkpad/~3/HKUGBsJGI0E/uplcv?utm_term=are+we+there+yeti+classic
- http://www.hkwebdesign.com.hk/wp-content/plugins/formcraft/file-upload/server/content/files/16164de885392a---50821078038.pdf
- http://morebricks.com/ckfinder/userfiles/files/jututigeduzekiz.pdf
- https://esteticarcare.com/wp-content/plugins/super-forms/uploads/php/files/3cd4b3e38982b57b877145677841c497/goxanumivewitubu.pdf
- http://nsk-nalogov.net/upload/files/34952216428.pdf
- https://moyaexpresss.com/ckfinder/userfiles/files/xukezofifik.pdf
- https://agentcctv.com/userfiles/file/99751477957.pdf
- http://blueyee.com/upload/file/211004009514.pdf
- https://bomberosdenavarra.com/userfiles_nexo/files/konipakofitubugemov.pdf
- https://thietkewebseo.com/webroot/img/files/xewesomewijazulejop.pdf
- http://ilink.pl/userfiles/file/pazajebutokuxebobirok.pdf
- http://poney-club-romilly-aigre28.fr/userfiles/file/pabodagebesasapi.pdf
- https://latgalesamatnieki.lv/files/file/19833279216.pdf
- http://www.yoko-ono.be/images/userfiles/file/guziferuxirasema.pdf
- https://rheinfurth.de/userfiles/file/sisosakup.pdf
- http://matchonusa.com/uploads/files/buzodebimefeg.pdf
- https://parkettworld.com/upload/files/45521489382.pdf
- https://grandiosieventinuziali.it/filesUploads/file/39379738276.pdf
- http://jobsandhi.com/uploaded_files/userfiles/files/luwaxepifefizosisilekazer.pdf
- http://daotaoyduoc.org/wp-content/plugins/super-forms/uploads/php/files/6c889151d17c2b3a97f95d72a0b19245/tujuliwijijedanod.pdf
- http://www.chp.pl/ckfinder/userfiles/files/78888074956.pdf
- http://prvugkh.ru/uploads/files/todiba.pdf
- https://granitnet.hu/editor_up/29949702148.pdf
- http://pyramidplaster.com/file_media/file_image/file/rumupifaf.pdf
- http://kingsfci.com/userfiles/file/32503631357.pdf
Embedded domains
- feedproxy.google.com
- www.hkwebdesign.com.hk
- morebricks.com
- esteticarcare.com
- nsk-nalogov.net
- moyaexpresss.com
- agentcctv.com
- blueyee.com
- bomberosdenavarra.com
- thietkewebseo.com
- ilink.pl
- poney-club-romilly-aigre28.fr
- www.yoko-ono.be
- rheinfurth.de
- matchonusa.com
- parkettworld.com
- grandiosieventinuziali.it
- jobsandhi.com
- daotaoyduoc.org
- www.chp.pl
- prvugkh.ru
- pyramidplaster.com
- kingsfci.com
- betsin.org
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report