MALICIOUS — 52bbee9ebce2dde84274aa59151f45c3b58aea4b3a619c39a664eaef2eefce13
MALICIOUS — 52bbee9ebce2dde84274aa59151f45c3b58aea4b3a619c39a664eaef2eefce13 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
52bbee9ebce2dde84274aa59151f45c3b58aea4b3a619c39a664eaef2eefce13 - SHA-1:
36981721ec4d845a56196a0c74994b4c5f3488f9 - MD5:
5122f59c5fa45fc7a6ebeaf001946173 - ssdeep:
768:lBU3sPTGwlM1+KDbYO9Oo194WZa/8E1f3DjNXfWopk5RoDN09SXr3vj:lByQMo+bVr4W28E1vdXeJ5P9Szj - TLSH:
T1EF31BFF755B7FD6C7B9F3E831ABB129C84CEE38442A6E552554C4718B0AC4BE3A01806 - Submitted as: 52bbee9ebce2dde84274aa59151f45c3b58aea4b3a619c39a664eaef2eefce13
- File type: pdf · Size: 40980 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Microsoft Defender: Trojan:PDF/Phish.HAG!MTB
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://diagnosticaedilizia.com/userfiles/files/30207828862.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=terraria+free+download+apk+full+version, http://embeddedhr.com/ckfinder/userfiles/files/wajuwoxujabawitaraxuzope.pdf, https://eternalbliss.net/file/2308562926.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=terraria+free+download+apk+full+version
- http://embeddedhr.com/ckfinder/userfiles/files/wajuwoxujabawitaraxuzope.pdf
- https://eternalbliss.net/file/2308562926.pdf
- https://uaqbakery.com/wp-content/plugins/formcraft/file-upload/server/content/files/161426708e596f---56803359000.pdf
- https://kawanmto.net/contents/files/fukoxoxumoruxomil.pdf
- http://odnoklassniki-files.ru/images/uploads/files/fugubejevamosumotimujol.pdf
- https://rjpexport.com/files/maxibodagapubinafaxanolo.pdf
- http://polyacer-ecp.com/userfiles/files/20210914_090725.pdf
- http://diagnosticaedilizia.com/userfiles/files/30207828862.pdf
- https://kiptep.ru/file/fiwukavojotuzusu.pdf
- http://capitaldanceacademy.com/userfiles/files/32425225330.pdf
- http://dajuicebarus.com/uploads/files/9375487970.pdf
- http://architettipassarinmarzotto.com/userfiles/files/rebatu.pdf
- https://gabconstruction.com/ckfinder/userfiles/files/49925678841.pdf
- http://355353.ru/userfiles/file/zokowukodek.pdf
- http://ghefootmassage.com/fckeditor_userfiles/file/zujemogejitapegusun.pdf
- https://invision.buzyhub.com/files/74074700752.pdf
- http://sendedianqi.com/upload_fck/file/2021-9-4/20210904235401613642.pdf
- https://www.liftechforklifts.com.au/application/third_party/ckfinder/userfiles/files/76168454130.pdf
- https://banderlogclub.ru/Files/file/31002596478.pdf
- https://wct.goldcrownresort.com/magazine_files/files/mobarisa.pdf
- https://iringmalaysia.com/ckfinder/userfiles/files/74003391287.pdf
- http://aguito.madteam.net/ckfinder/userfiles/files/870510050.pdf
Embedded domains
- crysiq.ru
- embeddedhr.com
- eternalbliss.net
- uaqbakery.com
- kawanmto.net
- odnoklassniki-files.ru
- rjpexport.com
- polyacer-ecp.com
- diagnosticaedilizia.com
- kiptep.ru
- capitaldanceacademy.com
- dajuicebarus.com
- architettipassarinmarzotto.com
- gabconstruction.com
- 355353.ru
- ghefootmassage.com
- invision.buzyhub.com
- sendedianqi.com
- www.liftechforklifts.com.au
- banderlogclub.ru
- wct.goldcrownresort.com
- iringmalaysia.com
- aguito.madteam.net
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report