MALICIOUS — 6508234f8e26ad4606a64820425f1c972b21f13b22ac15b0875e57c1a7a0cf28
MALICIOUS — 6508234f8e26ad4606a64820425f1c972b21f13b22ac15b0875e57c1a7a0cf28 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6508234f8e26ad4606a64820425f1c972b21f13b22ac15b0875e57c1a7a0cf28 - SHA-1:
e06a6f56829d306326db7920b48bd7eccb506bcb - MD5:
2b7ea1e412f73a8a050606d050c1e158 - ssdeep:
1536:H193lxcKCidOPJUdGhjR4+n4r+2KjEomaWRbnOHBpVrDjRWkNpOPaWIljOyiNo/U:734KCid+RxR4+F20EomFRTOhpVr3aPQ4 - TLSH:
T1D439CFF32097ED4C779B8F836AA70659B089D78C6632EB540548636DD4BC8FDAF40A40 - Submitted as: 6508234f8e26ad4606a64820425f1c972b21f13b22ac15b0875e57c1a7a0cf28
- File type: pdf · Size: 87545 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://fobosgrunt.ru/files/ckfinder/files/nozupefuv.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://smidgel.ru/uplcv?utm_term=top+eleven+gift+card, http://mayjack.com/upload/files/basixabujaxedes.pdf, http://bon-mar.com/fck_user_files/file/jirivebojizajazovezu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://smidgel.ru/uplcv?utm_term=top+eleven+gift+card
- http://mayjack.com/upload/files/basixabujaxedes.pdf
- http://bon-mar.com/fck_user_files/file/jirivebojizajazovezu.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613cb56e097b9---82534060874.pdf
- https://ostrichpharmaceuticals.com/userfiles/file/4765656711.pdf
- https://klcmekatronik.com/ckfinder/userfiles/files/kobabumujumenosaxazi.pdf
- http://aldo-ins.com/userfiles/file/13477885859.pdf
- http://fobosgrunt.ru/files/ckfinder/files/nozupefuv.pdf
- https://gresathouse.com/wp-content/plugins/super-forms/uploads/php/files/48688d822970f310d5264095848ed710/75498983654.pdf
- http://modnyi-buket.ru/uploads/files/22206159254.pdf
- http://trenermichal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/16156230931bd1---44194650865.pdf
- http://fabrikando.com/cmsimple/images/file/favomojevezibitifeme.pdf
- https://www.hdontheroadnapoli.it/wp-content/plugins/formcraft/file-upload/server/content/files/1614d19a2c6a52---74433486446.pdf
- http://karate-talence.com/newsite/userfiles/files/11628043274.pdf
- http://www.addvanceo.info/userfiles/files/getepifemofizumagu.pdf
- https://mgogs.com/mgfiles/file/55120760339.pdf
- http://aristosaigonhotel.vn/uploads/files/joluzerimesopojugulero.pdf
- https://dhesient.com/media/merajelisilizi.pdf
- http://daydreamspin.com/userfiles/file/rajidiwuwejigiganopa.pdf
- https://fsreloading.com/userfiles/files/wejasak.pdf
- https://fotoprint.lv/downloads/file/jusud.pdf
- http://www.appsolutely.sg/wp-content/plugins/formcraft/file-upload/server/content/files/161567fd34808c---60766840048.pdf
- https://faktxeber.com/resimler/files/13420115236.pdf
- http://www.videobezopasnost.ru/ckfinder/userfiles/files/tosozogafaberupujapuno.pdf
- https://stcc-sa.com/motakamel/Ups/files/31822643543.pdf
Embedded domains
- smidgel.ru
- mayjack.com
- bon-mar.com
- www.1000ena.com
- ostrichpharmaceuticals.com
- klcmekatronik.com
- aldo-ins.com
- fobosgrunt.ru
- gresathouse.com
- modnyi-buket.ru
- trenermichal.pl
- fabrikando.com
- www.hdontheroadnapoli.it
- karate-talence.com
- www.addvanceo.info
- mgogs.com
- dhesient.com
- daydreamspin.com
- fsreloading.com
- www.appsolutely.sg
- faktxeber.com
- www.videobezopasnost.ru
- stcc-sa.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report