MALICIOUS — 6a3b21ea729966a52fb4cc16a408d8a3ed42b2b340b6eb2d4993c9f4ed550e46
MALICIOUS — 6a3b21ea729966a52fb4cc16a408d8a3ed42b2b340b6eb2d4993c9f4ed550e46 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6a3b21ea729966a52fb4cc16a408d8a3ed42b2b340b6eb2d4993c9f4ed550e46 - SHA-1:
596a47677d6c39d4ba849691ef97331b20fa81a6 - MD5:
5b997d3c54ca555d05db77d02ab7bd4a - ssdeep:
1536:UFv9JYa2e7TLL3BiDlPpxdxJZYq8gwznDWwpOS9WnFByfPEO7SGv5mz:8IabPLxipBxdxJZYPgsnGS0f+EO7Sqg - TLSH:
T1D339DFF3458BDC0CAB5BAF4769EA116D614EE7885172EA90018CB63CD4BC6BDBF01811 - Submitted as: 6a3b21ea729966a52fb4cc16a408d8a3ed42b2b340b6eb2d4993c9f4ed550e46
- File type: pdf · Size: 87600 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://hotechike.com/files/files/28585716257.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://neavocats.com/wp-content/plugins/super-forms/uploads/php/files/2c96bb44c28698be405727449034cb51/12571954619.pdf, http://nappsa.org/userfiles/file/napidupizeb.pdf, https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/c53e4e50a55099ae324db42fb6d0f215/90093484926.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/cv9VXjIrmdE/uplcv?utm_term=how+much+does+car+air+conditioning+repair+cost
- https://neavocats.com/wp-content/plugins/super-forms/uploads/php/files/2c96bb44c28698be405727449034cb51/12571954619.pdf
- http://nappsa.org/userfiles/file/napidupizeb.pdf
- https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/c53e4e50a55099ae324db42fb6d0f215/90093484926.pdf
- https://nailseasupportgroup.com/wp-content/plugins/super-forms/uploads/php/files/7beaa334d3729e3ce5f834215d8cada8/96028605635.pdf
- http://aklond.com/UploadFilesfile///2021050517200172.pdf
- http://hotechike.com/files/files/28585716257.pdf
- https://perfecthospital.org/ckfinder/userfiles/files/93341755632.pdf
- http://zadonskiy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1608db24aeec75---gibokiravogijanoxebozen.pdf
- https://alignerco.com/wp-content/plugins/super-forms/uploads/php/files/09306fa5945178df3c115e7118a1ac95/raxuvivepija.pdf
- https://sketchup360.vn/wp-content/plugins/super-forms/uploads/php/files/7lhoj1ugpa9hoik3tnkhhrgbg0/raribifuzowinofawoxovu.pdf
- http://chokmanee.com/userfiles/file/21617646688.pdf
- https://www.hit-education.com/wp-content/plugins/super-forms/uploads/php/files/d57g3dmodgrl2n6ohk4928g0vq/rapafetejar.pdf
- http://dmscsmartlifeblog.com/userfiles/files/fopun.pdf
- http://cadeco.com/testingsites/advantage_aviation/assets/media/file/89058351986.pdf
- http://kino-profi.com/wp-content/plugins/super-forms/uploads/php/files/6424442a1f2ec455c2ca5edf1a435666/51066203927.pdf
- http://portalcom-b2b.es/img/user///file/_0581713001619940630.pdf
- https://audreyheselmans.com/_files/file/tabatuwujokubabesawi.pdf
- http://bkbflooringusa.com/userfile/abbey/file/bivumezexijujakisame.pdf
- http://shop-cartuning.pl/userfiles/file/dubuxijegoloxojedabujiwe.pdf
- http://skiflogistics.ru/userfiles/file/72706655459.pdf
- http://xn--szabowski-tub.pl/userfiles/file/9255681186.pdf
- https://yingzhaoliuart.com/upload/file/feremizoga.pdf
- https://www.kngroup.com/wp-content/plugins/formcraft/file-upload/server/content/files/160abee0b2d637---vujipevanujadadedukezan.pdf
- https://www.avenueroadadvertising.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c585bbe2bf7---gifiduwurejilopotutefumas.pdf
Embedded domains
- feedproxy.google.com
- neavocats.com
- nappsa.org
- adbadog.com
- nailseasupportgroup.com
- aklond.com
- hotechike.com
- perfecthospital.org
- zadonskiy.ru
- alignerco.com
- chokmanee.com
- www.hit-education.com
- dmscsmartlifeblog.com
- cadeco.com
- kino-profi.com
- portalcom-b2b.es
- audreyheselmans.com
- bkbflooringusa.com
- shop-cartuning.pl
- skiflogistics.ru
- xn--szabowski-tub.pl
- yingzhaoliuart.com
- www.kngroup.com
- www.avenueroadadvertising.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report