MALICIOUS — 592094f2a8f8402d45de280364216945be94d87d65c977c1d489c98d744a27d5
MALICIOUS — 592094f2a8f8402d45de280364216945be94d87d65c977c1d489c98d744a27d5 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
592094f2a8f8402d45de280364216945be94d87d65c977c1d489c98d744a27d5 - SHA-1:
7db743e7aa339d6c0030a5eb99630365f12d28b7 - MD5:
41966a20f17db21e1bd90c03deb4e953 - ssdeep:
1536:8KmpKfOrnnEYmJDegHjA0Ev27k3DS3iuSDKWOpOwrKWPsFk9V3b:+4fOrnRMegHjAvO7kV7D/wrRsG9d - TLSH:
T1E737BFF32097CC9C77199B0329FA11A8B04AD7CC2573EB905188B66C95BCAFDBB10651 - Submitted as: 592094f2a8f8402d45de280364216945be94d87d65c977c1d489c98d744a27d5
- File type: pdf · Size: 71736 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://tonyprins.nl/images/uploads/file/vatesovot.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://tonyprins.nl/images/uploads/file/vatesovot.pdf, http://topflexsports.com/uploads/rogedodaza.pdf, https://hoangmailogistics.com/asset/site/files/22706633336.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/ngfLrbzwjls/uplcv?utm_term=android+video+player+with+zoom
- http://tonyprins.nl/images/uploads/file/vatesovot.pdf
- http://topflexsports.com/uploads/rogedodaza.pdf
- https://hoangmailogistics.com/asset/site/files/22706633336.pdf
- http://www.loicadesacavem.pt/wp-content/plugins/formcraft/file-upload/server/content/files/1614cdc8b84b5b---68750657088.pdf
- http://domgr11.ru/uploads/files/50474132942.pdf
- https://nslogisticservice.com/userfiles/files/jisobavejijujivefosifuxej.pdf
- https://gencatakan.com/upload/file/jamegilibunisebave.pdf
- http://adanateknikservis.web.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16148be23b0cac---mijepuxerobatevo.pdf
- http://www.logomarcanet.com/userfiles/file/xifumuzarajagiposawuw.pdf
- http://www.siposferenc.hu/html/jakuba.pdf
- https://pustelnik-budownictwo.pl/ckfinder/userfiles/files/44993586661.pdf
- http://technology-mp.it/userfiles/files/takisuwipesukolapanuledi.pdf
- http://starinviter.com/ckimagefiles/80945814509.pdf
- http://zygzak.eu/foto_dane/wysiwyg/File/81370285685.pdf
- http://3qbuy.com/CKEdit/upload/files/46086968766.pdf
- https://samirkumarpaul.com/ckfinder/userfiles/files/89566053915.pdf
- https://tumujerrusa.com/userfiles/bogilanakoje.pdf
- https://annekienlen.fr/imagesfile/dumuxu.pdf
- http://nnk.gr/wp-content/plugins/formcraft/file-upload/server/content/files/16134d82b6c5bc---getobumolamatiku.pdf
- https://www.totspotdaynursery.co.uk/ckfinder/userfiles/files/mudowudadinulega.pdf
- http://murzilka.biz/images/uploads/file/rusobafovareku.pdf
- https://hamayeshniroo.com/shop/file/bewudotupoge.pdf
- http://bivalyracing.hu/files/file/88387019214.pdf
- https://karapinarinsaat.net/userfiles/upload/file/42049503362.pdf
Embedded domains
- feedproxy.google.com
- tonyprins.nl
- topflexsports.com
- hoangmailogistics.com
- domgr11.ru
- nslogisticservice.com
- gencatakan.com
- www.logomarcanet.com
- pustelnik-budownictwo.pl
- technology-mp.it
- starinviter.com
- zygzak.eu
- 3qbuy.com
- samirkumarpaul.com
- tumujerrusa.com
- annekienlen.fr
- www.totspotdaynursery.co.uk
- murzilka.biz
- hamayeshniroo.com
- karapinarinsaat.net
- www.w3.org
- purl.org
- ns.adobe.com
- www.loicadesacavem.pt
- adanateknikservis.web.tr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report