MALICIOUS — 54d20e41318100650ab7bbbfc189e7c35f247fe930a614e0dd5704cd02324042
MALICIOUS — 54d20e41318100650ab7bbbfc189e7c35f247fe930a614e0dd5704cd02324042 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
54d20e41318100650ab7bbbfc189e7c35f247fe930a614e0dd5704cd02324042 - SHA-1:
3c898df929e66969d2f0bf64512f539adf2ac634 - MD5:
559fb600fd3d1f20b7a85d84db66138d - ssdeep:
1536:Ku4SUitKPdWUd2MZKrh/XfI2xWOpOwrKWxNfwxNgoELt2U/po5:l4SUxz5a/Xw2uwrvNIkoutZRy - TLSH:
T17D38CFF37047CE4D778ACF0369EA01ACA18EE3896632EA6004457A6CD57C5FE7E10911 - Submitted as: 54d20e41318100650ab7bbbfc189e7c35f247fe930a614e0dd5704cd02324042
- File type: pdf · Size: 78958 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://lucchetta.net/userfiles/files/tuzosuvogidagiwowujawu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://coretry.ru/uplcv?utm_term=achartengine+android+example, http://gongotour.com/FileData/ckfinder/files/20210912_697B2598360333D3.pdf, https://thic.net/plugin/ce1/ckfinder/userfiles/files/94468826745.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://coretry.ru/uplcv?utm_term=achartengine+android+example
- http://gongotour.com/FileData/ckfinder/files/20210912_697B2598360333D3.pdf
- https://thic.net/plugin/ce1/ckfinder/userfiles/files/94468826745.pdf
- http://grubstreet.ca/ckfinder/userfiles/files/bixoxijosuketisupexaw.pdf
- https://bienenaktuell.com/sites/bienenaktuell.com/files/file/berubakilavipu.pdf
- http://xpeedon.net/userfiles/file/20210920070917.pdf
- https://atlastoursntravels.com/userfiles/file/52329556584.pdf
- http://lucchetta.net/userfiles/files/tuzosuvogidagiwowujawu.pdf
- https://mobilpetrol.olajpark.hu/files/files/58354719969.pdf
- https://macauroommate.com/ckfinder/userfiles/files/wakabalibowilolu.pdf
- http://www.anclupnapoli.it/userfiles/file/29524496005.pdf
- https://ladangmimpi.com/contents/files/xesaxazelodudomuj.pdf
- http://daimarconstrucciones.com/images/admin/file/xosapegozoluradaduzatidev.pdf
- http://www.cemeba.com/uploads/ckfinder/files/53696335072.pdf
- http://argyleliquidations.com/userfiles/files/63016631656.pdf
- http://tuzy.pl/Upload/file/vudoruwofiretudi.pdf
- https://episcopiaoradiei.ro/files/jonigukefeveruwevavas.pdf
- https://mimpishio1.com/contents/files/7923248641.pdf
- https://rjiminfra.com/wp-content/plugins/super-forms/uploads/php/files/e08dd2cf005313dd48c2f857139a6996/25010287476.pdf
- http://chi-kara.net/Upload/files/6296414706.pdf
- https://oncetrabzon.com/resimler/files/43267815545.pdf
- https://vivekanandbawwa.com/userfiles/file/bofotobujozopadubusin.pdf
- https://anukulagrotech.com/ci/userfiles/files/neseso.pdf
- http://medob.org/SITE/files/editor/file/bulosaxikinisakosifilodun.pdf
- http://0851gay.org/userfiles/202109file/2021090313480270554.pdf
Embedded domains
- coretry.ru
- gongotour.com
- thic.net
- grubstreet.ca
- bienenaktuell.com
- xpeedon.net
- atlastoursntravels.com
- lucchetta.net
- macauroommate.com
- www.anclupnapoli.it
- ladangmimpi.com
- daimarconstrucciones.com
- www.cemeba.com
- argyleliquidations.com
- tuzy.pl
- mimpishio1.com
- rjiminfra.com
- chi-kara.net
- oncetrabzon.com
- vivekanandbawwa.com
- anukulagrotech.com
- medob.org
- 0851gay.org
- titishop.co
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report