MALICIOUS — 572cb387f5ce1786437df1ed733246b34e15e33699f44a820fc8792c7c20a61c
MALICIOUS — 572cb387f5ce1786437df1ed733246b34e15e33699f44a820fc8792c7c20a61c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
572cb387f5ce1786437df1ed733246b34e15e33699f44a820fc8792c7c20a61c - SHA-1:
c9576960533a8134b94541625272992dbe67ffe7 - MD5:
4dd91509ded50224aec32242f6f1a2c8 - ssdeep:
1536:WEl1uwJkuX7xe2SJVIZuf/K8tclVza8fEkEW6pOu20zoWZSG24gNo3t:3l4Iku6zsufC8tgVzp9u2OJLg4 - TLSH:
T1F639C0F321DBEE9C7B878B035DEA11AC6049DB8C1163EA8044487A7CC97C5BE7E04961 - Submitted as: 572cb387f5ce1786437df1ed733246b34e15e33699f44a820fc8792c7c20a61c
- File type: pdf · Size: 85755 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://salman-is.com/userfiles/file/88368489931.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=download+media+creation+tool+for+windows+7, https://swimproject.eu/wp-content/plugins/super-forms/uploads/php/files/db76f0ba058c3d01d310f0d29dc6c729/ginavexozuse.pdf, https://stop-remont.ru/ckfinder/userfiles/files/pusigibeguwufakexofos.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pistant.ru/uplcv?utm_term=download+media+creation+tool+for+windows+7
- https://swimproject.eu/wp-content/plugins/super-forms/uploads/php/files/db76f0ba058c3d01d310f0d29dc6c729/ginavexozuse.pdf
- https://stop-remont.ru/ckfinder/userfiles/files/pusigibeguwufakexofos.pdf
- https://at2-turbo-j3t.com/contents/files/gatiterifad.pdf
- http://salman-is.com/userfiles/file/88368489931.pdf
- http://capthepcongtrinh.com/uploads/news/files/29356254442.pdf
- https://chinese-wall.tw/upload/files/lejalazofolidezatu.pdf
- http://bachtungcompany.com/upload/files/jilamatisimorixoxanum.pdf
- http://bacvietexpress.com/upload/userfiles/files/98968657033.pdf
- http://locnuocvietmy.com/Images_upload/files/98566210301.pdf
- https://makenie.com/upload/files/tamel.pdf
- https://makenie.com/upload/files/86703397731.pdf
- http://quickfix-poland.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614155ddb1954---junegolalaganajoredused.pdf
- http://ttmplus.com/userfiles/files/bujizabulilomonuvag.pdf
- https://prosaison.fr/userfiles/files/80164267031.pdf
- http://cw-cut.com/uploads/file/nolimosavapepono.pdf
- http://hueide.com/upload/files/viseduvamogejotozit.pdf
- https://milliondollardesiclub.com/upload_files/featured/files/50086986243.pdf
- http://harasim.cz/uploaded/files/73279955200.pdf
- http://aardbeienfeesten.nl/uploadimages/files/59858301701.pdf
- http://photopuzzle.net/userData/board/file/lowuzurul.pdf
- http://kaizenlife.com/ckfinder/userfiles/files/78266325541.pdf
- https://frontivo.ro/userfiles/file/907475144.pdf
- http://ranjitabiswas.com/userfiles/files/13999311762.pdf
- https://inprovitperu.com/ckfinder/userfiles/files/wonuvitafiwewojosi.pdf
Embedded domains
- pistant.ru
- swimproject.eu
- stop-remont.ru
- at2-turbo-j3t.com
- salman-is.com
- capthepcongtrinh.com
- chinese-wall.tw
- bachtungcompany.com
- bacvietexpress.com
- locnuocvietmy.com
- makenie.com
- quickfix-poland.com
- ttmplus.com
- prosaison.fr
- cw-cut.com
- hueide.com
- milliondollardesiclub.com
- aardbeienfeesten.nl
- photopuzzle.net
- kaizenlife.com
- ranjitabiswas.com
- inprovitperu.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report