MALICIOUS — 68eb4d1e9d63996528e6a5cbb96883258203be5626b151c1b483eb790e99a3cb
MALICIOUS — 68eb4d1e9d63996528e6a5cbb96883258203be5626b151c1b483eb790e99a3cb is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
68eb4d1e9d63996528e6a5cbb96883258203be5626b151c1b483eb790e99a3cb - SHA-1:
ac81637f7683b1b2b2c60f74c8495f8d73d39273 - MD5:
210120fd15b7b809ea5e9d541d15e1af - ssdeep:
1536:3NiC31WFCeQUlV7AVdjI0wKwKJFKw7vsT2M1DqtPvmZMz0HzRCvhVWTB8TQdNs1N:9n1CCrUP61GKJEw7gT1D8vz0HcvDTQdg - TLSH:
T15A3AE0F360A7CD9C3B5BAF032AFB0268A549D7582037AA90448CB77C95BC5BE7E45500 - Submitted as: 68eb4d1e9d63996528e6a5cbb96883258203be5626b151c1b483eb790e99a3cb
- File type: pdf · Size: 93663 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://energo-winstal.pl/userfiles/file/sukenapofuf.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://drafthe.ru/uplcv?utm_term=as+soon+as+questions, http://energo-winstal.pl/userfiles/file/sukenapofuf.pdf, http://asu.com.vn/wp-content/plugins/super-forms/uploads/php/files/6id0d2i72002cuea2o52nmp3q9/nefogozegegudegafizowufuf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://drafthe.ru/uplcv?utm_term=as+soon+as+questions
- http://energo-winstal.pl/userfiles/file/sukenapofuf.pdf
- http://asu.com.vn/wp-content/plugins/super-forms/uploads/php/files/6id0d2i72002cuea2o52nmp3q9/nefogozegegudegafizowufuf.pdf
- https://www.lang-mayer.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609cef33c2e8e---19906433836.pdf
- https://keralatemples.info/ckfinder/userfiles/files/pewifofejegulezufoseke.pdf
- http://www.webtony.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160962aff18fc8---jilagunemudefuzebiful.pdf
- http://structurecreative.com/wp-content/plugins/formcraft/file-upload/server/content/files/160805f39f1623---25010118643.pdf
- https://www.chauffeur-prive-nice.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160bc876ef3d64---68629575777.pdf
- https://centrobrands.com/wp-content/plugins/super-forms/uploads/php/files/a78c0bd23704bbcef8c7eb10ce5573c1/funuzajefaxalizivino.pdf
- https://minipowerpack.net/upload/files/wifopezawojira.pdf
- https://directorvincentchow.com/fck_filemanager_upload/file/giforijekawemevi.pdf
- https://ph2020.org/FCKeditor/file/tuvox.pdf
- https://kozhikodedeaf.org/admin/my_files/file/88107034104.pdf
- http://lawyerstitleescrow.com/clients/9/9b/9b7cfcecb5e5abb6b877b2b1d59b4eb1/File/62913325819.pdf
- http://pcccmiennam.com/media/ftp/file/72969736298.pdf
- http://diamond6ranch.com/userfiles/file/bonenofabomimimegilefiw.pdf
- http://bjaimama.com/data/upload/2021/05/file/202105171012445734.pdf
- http://steclotildehorton.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16079a0d5b89bf---novemuxolevizosimer.pdf
- https://bestofbucerias.com/upload/file/94319584253.pdf
- https://nationalshield-uae.com/userfiles/files/33705526184.pdf
- https://www.duffylighting.com/wp-content/plugins/super-forms/uploads/php/files/fd9fd0a1f221db28f7335eedf48aa395/miletaduruwimabexedinenad.pdf
Embedded domains
- drafthe.ru
- energo-winstal.pl
- www.lang-mayer.de
- keralatemples.info
- www.webtony.com.br
- structurecreative.com
- www.chauffeur-prive-nice.fr
- centrobrands.com
- minipowerpack.net
- directorvincentchow.com
- ph2020.org
- kozhikodedeaf.org
- lawyerstitleescrow.com
- pcccmiennam.com
- diamond6ranch.com
- paoladebenedetti.eu
- bjaimama.com
- steclotildehorton.ca
- bestofbucerias.com
- nationalshield-uae.com
- www.duffylighting.com
- asu.com.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report