MALICIOUS — 54a835cf14b861e945a48e46bb17ed0fa743534d1d0d12b535cdf755b7d96c06
MALICIOUS — 54a835cf14b861e945a48e46bb17ed0fa743534d1d0d12b535cdf755b7d96c06 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
54a835cf14b861e945a48e46bb17ed0fa743534d1d0d12b535cdf755b7d96c06 - SHA-1:
010bcbef40f9ccb78320464f577d2de127d5cc31 - MD5:
fc5af5aa44cf9bb4ebca42a46a6dd195 - ssdeep:
1536:4AvWxEHGROaTxachr5yut3z4Q+yYgRfyV94CC8WxTMW8pO+hK9:zvWqHGCy0Q+yYx4PdTH+C - TLSH:
T10637BFF36097DD9CB78B8F036AEB119DA156E68C2136E7804088B62DC4BC9BDBF14550 - Submitted as: 54a835cf14b861e945a48e46bb17ed0fa743534d1d0d12b535cdf755b7d96c06
- File type: pdf · Size: 74118 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://renetravel.ro/images/files/24959923256.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://c2r-auto.com/uploadfiles/file/2021092110444473499.pdf, https://apz-arte.com/ckfinder/userfiles/files/71884097916.pdf, http://www.web-globus.de/ckfinder/userfiles/files/6868036786.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/ngfLrbzwjls/uplcv?utm_term=sufna+punjabi+movie+download
- http://c2r-auto.com/uploadfiles/file/2021092110444473499.pdf
- https://apz-arte.com/ckfinder/userfiles/files/71884097916.pdf
- http://www.web-globus.de/ckfinder/userfiles/files/6868036786.pdf
- http://issaproject.com/app/views/panel/ckfinder/userfiles/files/71844763445.pdf
- https://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/16141117534663---59698070402.pdf
- https://bibliotheque-des-arts.ch/ckfinder/userfiles/files/2776151846.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/161471f202948c---laxezuvegigoxuganujuro.pdf
- http://www.dogwoodagility.nl/ckfinder/userfiles/files/xazegigikilubokokoxusule.pdf
- http://foto-preiss.at/upload_files/files/ludavikizevafolosegu.pdf
- https://renetravel.ro/images/files/24959923256.pdf
- https://vonia.mikludava.lt/images/files/golosanubom.pdf
- http://www.hermosabeachbungalows.com/userfiles/files/rududukite.pdf
- https://voicelux.ru/wp-content/plugins/super-forms/uploads/php/files/10f7758692f42b843decbf7d79ccc0c1/19730886556.pdf
- http://www.sunarpazarlama.com/wp-content/plugins/super-forms/uploads/php/files/ukpv96meco1hpuo0jljttafof7/27748797834.pdf
- https://marblobathware.ph/app/webroot/img/files/20929649558.pdf
- https://bushregenerators.net/userfiles/files/fifimolesole.pdf
- https://interconformity.ro/images/file/94682740910.pdf
- https://sodigital.it/wp-content/plugins/formcraft/file-upload/server/content/files/1613a61eaa7980---xedoresonoz.pdf
- http://cerrutistudio.eu/userfiles/files/74813786591.pdf
- http://taigesw.com/upload/files/zokafujidujozuvubeso.pdf
- http://boletos.luzservicos.com/ckfinder/userfiles/files/xujekik.pdf
- https://bilegt.mn/userfiles/files/noxerukuriganevozeniloro.pdf
- https://abril.pe/wp-content/plugins/super-forms/uploads/php/files/455ldv9kbbgua26ns4vd6haut4/40610956370.pdf
- http://atenngo.com/admin/sites/site/documents/94840161447.pdf
Embedded domains
- feedproxy.google.com
- c2r-auto.com
- apz-arte.com
- www.web-globus.de
- issaproject.com
- klingende-zeder.de
- bibliotheque-des-arts.ch
- www.1000ena.com
- www.dogwoodagility.nl
- www.hermosabeachbungalows.com
- voicelux.ru
- www.sunarpazarlama.com
- bushregenerators.net
- sodigital.it
- cerrutistudio.eu
- taigesw.com
- boletos.luzservicos.com
- atenngo.com
- www.phonefixcomo.com
- jshtextile.com
- www.w3.org
- purl.org
- ns.adobe.com
- foto-preiss.at
- renetravel.ro
File paths
- Z:\z&
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report