MALICIOUS — 61f4db87f27ae24de12af5bb86dfd6fa5c58f82ec83fb477fbd11d74cf5bd152
MALICIOUS — 61f4db87f27ae24de12af5bb86dfd6fa5c58f82ec83fb477fbd11d74cf5bd152 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
61f4db87f27ae24de12af5bb86dfd6fa5c58f82ec83fb477fbd11d74cf5bd152 - SHA-1:
405fe40d9127a2bbbfafb330a52a89f596ff9956 - MD5:
1f8e2bd3b83cc386bac60bd045d625eb - ssdeep:
1536:4IBxtkmxDy6B3iQA6AhQt+YiZlzQfAbng3CMDrWQK1F7VnReLacK7Q6W/pomU/3b:TfxDy6B3iQA676ZlzQfAwrWQK1TRNckJ - TLSH:
T1C23AD0F36197DE5C739B9B1369A7608CB445E3CC6222EAA085CCA22CC5BC57EBF10541 - Submitted as: 61f4db87f27ae24de12af5bb86dfd6fa5c58f82ec83fb477fbd11d74cf5bd152
- File type: pdf · Size: 93317 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://kiuanai.com/userfiles/file/30630624118.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://drahmetbostanci.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615a45a8ec93e---10144188558.pdf, http://automsystem.com/UploadFile/file/20210902074855126.pdf, http://kiuanai.com/userfiles/file/30630624118.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=water+pollution+act+1974
- https://drahmetbostanci.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615a45a8ec93e---10144188558.pdf
- http://automsystem.com/UploadFile/file/20210902074855126.pdf
- http://kiuanai.com/userfiles/file/30630624118.pdf
- https://ostrichpharmaceuticals.com/userfiles/file/15475690452.pdf
- https://www.sahabatkeluargahomecare.com/wp-content/plugins/formcraft/file-upload/server/content/files/16133a909d0c5e---60123511923.pdf
- http://sun-marche.com/app/webroot/js/ckfinder/userfiles/files/legidobitozawageside.pdf
- https://gameclub.by/uploads/files/xitenexadodidem.pdf
- https://textosolutionslinguistiques.ca/upload/editor/file/341313873.pdf
- http://dobryremont.pl/ebobas/portal/app/webroot/img/tmp/file/16325067197219.pdf
- https://familienbilstrup.dk/userfiles/file/76835253466.pdf
- https://0800-707-808.com/upload/ckfinder_temp/files/20210925190816.pdf
- http://3colorjazz.com/fckeditor/userfiles/image/81493260494.pdf
- http://www.celso.org/download/nadefojakamuxudig.pdf
- http://gomientrung.vn/uploads/image/files/misovijizejojeresego.pdf
- https://taiwan-tiaya.com/upload/tiaya_official/files/53718905497.pdf
- http://www.corazondelsol.es/ckfinder/userfiles/files/14940574187.pdf
- https://hantverksakuten.se/ckfinder/userfiles/files/17798821144.pdf
- https://gujaratisamajparis.org/upload/files/betuzabezusi.pdf
- https://cope.lk/assets/media/file/fatup.pdf
- http://lifestyleufa.ru/wp-content/plugins/super-forms/uploads/php/files/8b69499a444d9e6a0092334a401260b0/18593288115.pdf
- https://culturasiapamplona.com/guiarte_userfiles/files/44393777863.pdf
- https://52fantasies.com/home/holly/public_html/ckfinder/userfiles/files/kivafugevek.pdf
- https://schachverein-marchhoefe.ch/fcsr/news/upload/file/zopenepeparujaporunoj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- drahmetbostanci.com
- automsystem.com
- kiuanai.com
- ostrichpharmaceuticals.com
- www.sahabatkeluargahomecare.com
- sun-marche.com
- textosolutionslinguistiques.ca
- dobryremont.pl
- 0800-707-808.com
- 3colorjazz.com
- www.celso.org
- taiwan-tiaya.com
- www.corazondelsol.es
- hantverksakuten.se
- gujaratisamajparis.org
- lifestyleufa.ru
- culturasiapamplona.com
- 52fantasies.com
- schachverein-marchhoefe.ch
- www.w3.org
- purl.org
- ns.adobe.com
- gameclub.by
- familienbilstrup.dk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report