MALICIOUS — 1613104aa0c2ac---12640754379.pdf
MALICIOUS — 1613104aa0c2ac---12640754379.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5b918e4589ff7477db42f34a074878744e5fe6f2cb65eb1645abfc5c24df28b2 - SHA-1:
b950182aceaf1f5920f507128bf5eb568d700712 - MD5:
1b0f9f3c0ae44bc577741bc0b16341e7 - ssdeep:
1536:S+t/bu0v/vL9TJlBLZnaCqKN4r1CWxApOGzWTCcfAUJzsrKas:XaGBTJTLZn4n3G8RAssrG - TLSH:
T12739D0F361E7DD8C77479F536BBA21A8904FD3882121DA5004C8B6ACD47C9BEAF04991 - Submitted as: 1613104aa0c2ac---12640754379.pdf
- File type: pdf · Size: 85715 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.mtpartnersfl.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c905713797d---xixunu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://infrive.ru/uplcv?utm_term=tabarrukat+e+ambiya+pdf, https://carthink.org/wp-content/plugins/formcraft/file-upload/server/content/files/160c8d28be286c---77181142134.pdf, https://davebakeragency.com/wp-content/plugins/super-forms/uploads/php/files/13fd808d74e21dd20a3966ad51f53e6d/59572818707.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://infrive.ru/uplcv?utm_term=tabarrukat+e+ambiya+pdf
- https://carthink.org/wp-content/plugins/formcraft/file-upload/server/content/files/160c8d28be286c---77181142134.pdf
- https://davebakeragency.com/wp-content/plugins/super-forms/uploads/php/files/13fd808d74e21dd20a3966ad51f53e6d/59572818707.pdf
- https://aplusadvance.com/naver_editor/data/file/8848240581.pdf
- https://georeno.ca/userfiles/files/kipeperitasofosif.pdf
- http://boulderdivorcelaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a418796f1a9---70851327059.pdf
- https://almuhja.com/ckfinder/userfiles/files/31872792028.pdf
- http://es-umzuege-transporte.de/wp-content/plugins/super-forms/uploads/php/files/600927a1154b565cabc2e1360ec781df/zelagepunilafidabinu.pdf
- http://www.mtpartnersfl.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c905713797d---xixunu.pdf
- https://www.cukoyem.com.tr/wp-content/plugins/super-forms/uploads/php/files/s3483h1ldtbvj35be310huces5/negimipuxavofufizuride.pdf
- https://ita.kru.ac.th/ckfinder/userfiles/files/nekelugukofejaj.pdf
- https://leifs-auto.dk/images/file/10900834540.pdf
- http://sivam.pl/files/file/nomevafiniro.pdf
- https://sellerflows.com/wp-content/plugins/super-forms/uploads/php/files/d2973c0028cedf4d23e8e3d7cfb4a429/99528403778.pdf
- http://diagonal.org.ar/wp-content/plugins/formcraft/file-upload/server/content/files/1606f5f109e477---rasep.pdf
- https://evergreencans.com/userfiles/file/lebowixugifexolij.pdf
- http://gestaocipa.com/public_html/Imagens/file/lofuvimagiweriferubenop.pdf
- https://waelfawzy.com/userfiles/file/
- http://ledspectrumthai.com/ckfinder/userfiles/files/xewawesiwov.pdf
- http://happypalettebnb.com/CKEdit/upload/files/8845013642.pdf
- https://robotics-institute.com/wp-content/plugins/super-forms/uploads/php/files/hhti0jng0datd2phpqipctoi9a/15449810233.pdf
- http://toastwarenhuis.nl/app/webroot/files/userfiles/files/55582431811.pdf
- http://www.communityheroesproject.org/wp-content/plugins/formcraft/file-upload/server/content/files/16073bf1553c14---megurudexetanegojivi.pdf
- http://pressvaluation.net/userfiles/file/simonoreboxapanufijutoz.pdf
- https://ayurvedaemart.com/uploads/file/bimokolalofipipaponadogu.pdf
Embedded domains
- infrive.ru
- carthink.org
- davebakeragency.com
- aplusadvance.com
- georeno.ca
- boulderdivorcelaw.com
- almuhja.com
- es-umzuege-transporte.de
- www.mtpartnersfl.com
- sivam.pl
- sellerflows.com
- evergreencans.com
- gestaocipa.com
- waelfawzy.com
- ledspectrumthai.com
- happypalettebnb.com
- robotics-institute.com
- toastwarenhuis.nl
- www.communityheroesproject.org
- pressvaluation.net
- ayurvedaemart.com
- alnahamgroup.com
- atmaircenter.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report