MALICIOUS — 60b559297d5aff04619674350b3f82864e9bf2db37f5be5d96f7441dfd208ac6
MALICIOUS — 60b559297d5aff04619674350b3f82864e9bf2db37f5be5d96f7441dfd208ac6 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
60b559297d5aff04619674350b3f82864e9bf2db37f5be5d96f7441dfd208ac6 - SHA-1:
212e35f7b96a8b05dc50e6c404a9e852acb4a0d7 - MD5:
bf3f3ebd9de7866ed1f8d70a21cf5b23 - ssdeep:
1536:679H8/7t2mNg/fsl7/nbmvkhtB9OcnrlsR6c8lKHtn3z4WQpOCoWN5a2:UHW0m2HsxbmsHB9OcruR7qebCu2 - TLSH:
T1D13AF1F7512BDE4C739F9B83ABA712A8649FF3485651EC65054C126C948C83FBE04A0A - Submitted as: 60b559297d5aff04619674350b3f82864e9bf2db37f5be5d96f7441dfd208ac6
- File type: pdf · Size: 93667 bytes
- Verdict: malicious (94/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://tnshoppingbag.com/upfiles/file/40728429671.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://eatatrudy.com/uploads/files/zilamonudezamab.pdf, https://3rproject.eu/ckfinder/userfiles/files/84327575842.pdf, https://vietcuongcorp.com/uploads/news/files/84567263088.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/MbOu/~3/2I9n2o-U8HI/uplcv?utm_term=pure+obligation+example
- http://eatatrudy.com/uploads/files/zilamonudezamab.pdf
- https://3rproject.eu/ckfinder/userfiles/files/84327575842.pdf
- https://vietcuongcorp.com/uploads/news/files/84567263088.pdf
- https://greenturtleproductions.com.au/wp-content/plugins/super-forms/uploads/php/files/a4c0b59b5369bdf39245b6815f27feee/sadogabizivejozifitiba.pdf
- https://naves.cz/res/file/mekenizaludokaxuzuweni.pdf
- https://unitjaya.com/contents/files/29875789031.pdf
- http://tnshoppingbag.com/upfiles/file/40728429671.pdf
- https://eliteswimmingpoolsinc.com/wp-content/plugins/super-forms/uploads/php/files/mg1cnvlb0i1m13s53biksa6c21/desavozixox.pdf
- https://superlitefan.com/uploads/files/60278771238.pdf
- http://cdio.vn/uploads/userfiles/file/mazefazajoxapupagun.pdf
- http://ampletrekking.com/userfiles/file/banisaripevawatusekakowat.pdf
- http://fleshlight-tw.com/userfiles/file/sevobabesufasuzevi.pdf
- https://www.novet.de/wp-content/plugins/formcraft/file-upload/server/content/files/16147a28fe78ac---xokakir.pdf
- http://qianxish.com/ckfind_image/files/xapojezer.pdf
- https://hamasataccessories.com/userfiles/files/54983581349.pdf
- http://quartierdete.fr/uploads/fckeditor/file/15868212182.pdf
- https://macleanpinesdrivingschool.com.au/wp-content/plugins/super-forms/uploads/php/files/1712459a09da62d54fb3d96de930238a/mobojutegobemoxenige.pdf
- http://nonstopsushi.com/uploads/files/xutepijevame.pdf
- http://pass38.com/images/contentimages/files/4313535177.pdf
- https://alubiasdetolosa.com/files/galeria/files/14816776398.pdf
- http://easyliveconstruction.com/ci/userfiles/files/niwikoviwajuwadogop.pdf
- http://elistaprezentow.pl/userfiles/file/47964349632.pdf
- https://bbensonmft.com/wp-content/plugins/super-forms/uploads/php/files/3baecc97cbe009cba4634ac5ec57198e/lilerofilobilaku.pdf
- https://blugarden.eu/file/pozelenokedolafofuzox.pdf
Embedded domains
- feedproxy.google.com
- eatatrudy.com
- 3rproject.eu
- vietcuongcorp.com
- greenturtleproductions.com.au
- unitjaya.com
- tnshoppingbag.com
- eliteswimmingpoolsinc.com
- superlitefan.com
- ampletrekking.com
- fleshlight-tw.com
- www.novet.de
- qianxish.com
- hamasataccessories.com
- quartierdete.fr
- macleanpinesdrivingschool.com.au
- nonstopsushi.com
- pass38.com
- alubiasdetolosa.com
- easyliveconstruction.com
- elistaprezentow.pl
- bbensonmft.com
- blugarden.eu
- pasted-radio.de
- naves.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report