MALICIOUS — 58918607ab5ba7f08d12d62bd79da466f93c6c5e51edfd68e76287b4710c7d88
MALICIOUS — 58918607ab5ba7f08d12d62bd79da466f93c6c5e51edfd68e76287b4710c7d88 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
58918607ab5ba7f08d12d62bd79da466f93c6c5e51edfd68e76287b4710c7d88 - SHA-1:
901d653c0412a18fcd7f991218a44edd1d8cab12 - MD5:
f1d68f73b34bf5ee7a1c15d03812ed28 - ssdeep:
1536:D4ku1KBqDRqEGorKHPUDhAPPw4PCJwWypOlWWxsZTYKTOreQH:XSKBqkEGLHPIhloCJRlDsZTYKTOx - TLSH:
T13037CFF3216BDE5C768B9B0768E712AC60DAD78C5162EF50048CB67C856C6FEBB00540 - Submitted as: 58918607ab5ba7f08d12d62bd79da466f93c6c5e51edfd68e76287b4710c7d88
- File type: pdf · Size: 70332 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://aviafond.ru/userfiles/file/44038353999.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://www.hangmandigital.com/files/file/gixufezeludexe.pdf, http://aviafond.ru/userfiles/file/44038353999.pdf, http://amblesidewindermere.ca/fckuploads/images/file/93956183936.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/ngfLrbzwjls/uplcv?utm_term=mass+of+1+amu+in+grams
- http://www.hangmandigital.com/files/file/gixufezeludexe.pdf
- http://aviafond.ru/userfiles/file/44038353999.pdf
- http://amblesidewindermere.ca/fckuploads/images/file/93956183936.pdf
- https://asiantms.com/ckfinder/userfiles/files/siwamufepa.pdf
- http://pusheng168.com/uploadfiles/20210913142451.pdf
- http://fujavietnam.com/images/Download/xonukexixupuxosatovofofis.pdf
- http://yugang360.com/upload_fck/file/2021-9-6/20210906034832518531.pdf
- http://crabandclaw.com/uploads/files/fakofidaxamewotudagi.pdf
- http://hyunsin.net/userfiles/file/29480860941.pdf
- https://livnica-metalurg.com/images/pages/file/95179395528.pdf
- https://hbfilm.ca/resimler/files/24956737193.pdf
- http://eegbiofeedback-leszno.pl/userfiles/file/bidevik.pdf
- https://paulogomeslda.com/userfiles/file/9965526760.pdf
- https://deverfgrossiercms.deindrukdemo.nl/upload/files/97110275559.pdf
- http://sevvalturizm.com/rsm/files/jedapatiper.pdf
- http://ahzycw.com/upload_fck/file/2021-9-28/20210928190437563742.pdf
- http://ctm.it/userfiles/file/673003411.pdf
- https://systematix.pl/userfiles/file/nonosikewovumifenevika.pdf
- http://sualpturizm.com/userfiles/file/45685366414.pdf
- http://guowangcable.com/d/files/labevixerujowe.pdf
- http://buffagiuseppeinfissi.com/userfiles/files/limazirugogusexelaw.pdf
- https://abriganature.centralcms.cloud/galeria/files/bebifonupip.pdf
- http://termosystem.pl/userfiles/file/totaxidopinomemes.pdf
- http://festivaldeliteraturadepereira.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614822e6bffb3---dezutefo.pdf
Embedded domains
- feedproxy.google.com
- www.hangmandigital.com
- aviafond.ru
- amblesidewindermere.ca
- asiantms.com
- pusheng168.com
- fujavietnam.com
- yugang360.com
- crabandclaw.com
- hyunsin.net
- livnica-metalurg.com
- hbfilm.ca
- eegbiofeedback-leszno.pl
- paulogomeslda.com
- deverfgrossiercms.deindrukdemo.nl
- sevvalturizm.com
- ahzycw.com
- ctm.it
- systematix.pl
- sualpturizm.com
- guowangcable.com
- buffagiuseppeinfissi.com
- abriganature.centralcms.cloud
- termosystem.pl
- festivaldeliteraturadepereira.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report