MALICIOUS — 5bb6a08db21bb20a5fb1262419200dc09ea9252f005c8a7340f51b05dc9af57b
MALICIOUS — 5bb6a08db21bb20a5fb1262419200dc09ea9252f005c8a7340f51b05dc9af57b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5bb6a08db21bb20a5fb1262419200dc09ea9252f005c8a7340f51b05dc9af57b - SHA-1:
7c8dc0e43caee1ed451728ef294470ecfe5c4d95 - MD5:
82b8c6b27c42a8bced5d3ae22a31520f - ssdeep:
1536:44SyXBjEUt1LjIWgvm07t2n8ZJt5mWfjHyCDYFYZaWUpO7ozBabowcKGX:EyXy816vn0n8ZJt3jHyYZ17O8boFKO - TLSH:
T13338AFF320AFDD5C774BCB43B9EB159C9087E2481162FA704188B66CD8BCABDAE14451 - Submitted as: 5bb6a08db21bb20a5fb1262419200dc09ea9252f005c8a7340f51b05dc9af57b
- File type: pdf · Size: 78786 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://maekuangudomthara.com/ckfinder/userfiles/files/wosukemofozesifed.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://mariellatriolo.it/public/file/ragadetenizuxadalasi.pdf, http://fk-fudosan.1nino3.com/app/webroot/img/userfiles/files/29526198338.pdf, https://www.mobytec.com.br/mobytec/wp-content/plugins/formcraft/file-upload/server/content/files/1613baec714610---12129997492.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/zMnd8XtcwSM/uplcv?utm_term=thop+tv+download+apk
- https://mariellatriolo.it/public/file/ragadetenizuxadalasi.pdf
- http://fk-fudosan.1nino3.com/app/webroot/img/userfiles/files/29526198338.pdf
- https://www.mobytec.com.br/mobytec/wp-content/plugins/formcraft/file-upload/server/content/files/1613baec714610---12129997492.pdf
- https://flims.atelierleuthold.ch/userfiles/files/wasuroxu.pdf
- https://esperidiaogomes.com/userfiles/files/zadewufefusej.pdf
- http://maekuangudomthara.com/ckfinder/userfiles/files/wosukemofozesifed.pdf
- http://solarhomepage.ch/fckeditor/editor/images/file/zapemiwuvimojis.pdf
- http://findmealocalpainter.com/insurazon/admin/userfiles/file/47003512497.pdf
- http://jurabos.nl/include/editor/file/nulovajufewuvizulawuvumo.pdf
- http://simonkuehner.de/gfx/userfiles/files/19948489587.pdf
- http://libertyquad72.fr/userfiles/file/4707456835.pdf
- http://wskinbody.com/data/boardData/files/fikavoramofuvobebowavux.pdf
- http://lifeline-sports.com/files/file/xidoxizelisuwipebagiforaj.pdf
- http://phukhoabacninh.com/images/files/85102452971.pdf
- http://www.lbf-cosmetics.com/website/wp-content/plugins/formcraft/file-upload/server/content/files/16133efc1cc7e4---4536748381.pdf
- http://dominopark.pl/public/upload/ckfinder/userfiles/files/1705952730.pdf
- http://indcms.testingmachines.com/images/file/rirerikinazolumowukuj.pdf
- http://akcjonariusz.com/UserFiles/file/xizukemepulizitudowabupex.pdf
- https://dellrein.ru/content/file/44700422965.pdf
- http://architectureanddesign.it/userfiles/files/bifezizovotogoramuxalij.pdf
- http://www.leads-bd.org/app/webroot/js/ckfinder/userfiles/files/deropimarepob.pdf
- http://samwha.com/upload/userfiles/file/71332903678.pdf
- https://inchirierielicopter.ro/wp-content/plugins/formcraft/file-upload/server/content/files/161343d9841540---68562692584.pdf
- http://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613dbc6a3312e---87264195920.pdf
Embedded domains
- feedproxy.google.com
- mariellatriolo.it
- fk-fudosan.1nino3.com
- www.mobytec.com.br
- flims.atelierleuthold.ch
- esperidiaogomes.com
- maekuangudomthara.com
- solarhomepage.ch
- findmealocalpainter.com
- jurabos.nl
- simonkuehner.de
- libertyquad72.fr
- wskinbody.com
- lifeline-sports.com
- phukhoabacninh.com
- www.lbf-cosmetics.com
- dominopark.pl
- indcms.testingmachines.com
- akcjonariusz.com
- dellrein.ru
- architectureanddesign.it
- www.leads-bd.org
- samwha.com
- www.holderit.com
- poltinka.ru
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report