MALICIOUS — 6b1a1a0b746698e221ddda4e40260289a9b7b37cbf009a7421ddf750b0c4eb0b
MALICIOUS — 6b1a1a0b746698e221ddda4e40260289a9b7b37cbf009a7421ddf750b0c4eb0b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6b1a1a0b746698e221ddda4e40260289a9b7b37cbf009a7421ddf750b0c4eb0b - SHA-1:
5c52fc6ec0cc6416f79d0987ef9e74394e12de3f - MD5:
603455953a60b88abe0451e80088f7aa - ssdeep:
1536:S7NFT/4DcbWqhPEIpHOvYnEr+K8ceoK3kzpwcJdJczajloWapOtQHW58hc5cmuDQ:6NJ/NFhPluvnhveoK3kqkdCzajftQK88 - TLSH:
T1F539D0F76097CE5C768B9B036DE71298E106D2847262D96044CCB63C99BC6FEBF40621 - Submitted as: 6b1a1a0b746698e221ddda4e40260289a9b7b37cbf009a7421ddf750b0c4eb0b
- File type: pdf · Size: 87078 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://skuplaptop.pl/wp-content/plugins/formcraft/file-upload/server/content/files/16144216387719---kelinugunakatada.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://coretry.ru/uplcv?utm_term=chi+jack+russell+mix, https://tigapilar.com/upload/files/15578139261.pdf, http://stjconsulting.it/userfiles/files/bugawaw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://coretry.ru/uplcv?utm_term=chi+jack+russell+mix
- https://tigapilar.com/upload/files/15578139261.pdf
- http://stjconsulting.it/userfiles/files/bugawaw.pdf
- https://redfortfireworks.com/ckfinder/userfiles/files/49919049276.pdf
- https://atlas-consulting.ro/fckeditor/fisiere/file/nadegaketo.pdf
- http://skuplaptop.pl/wp-content/plugins/formcraft/file-upload/server/content/files/16144216387719---kelinugunakatada.pdf
- https://houstoncoinclub.org/FCKeditor/file/paderelerelisadilitagux.pdf
- http://inphilong.com/upload/files/titevewazitebokuguvove.pdf
- http://ventss.ru/userfiles/files/72579957667.pdf
- https://dunakanyarfesto.hu/ckfinder/userfiles/files/89836246074.pdf
- http://kozszemle.hu/uploads/files/95925768075.pdf
- http://naoshima-tours.com/images/blog/file/tekuvimamatuposezitipob.pdf
- http://veganogle.es/uploads/ckfinder/files/72941477341.pdf
- https://www.campacinter.com/image/upload/File/sesobajefizozikavo.pdf
- https://creteservices.com/FCKeditor/userimages/file/fepesatenugulofa.pdf
- http://spzpoz-zdunskawola.pl/upload/file/bovezovobotul.pdf
- http://bhartiyambeohari.in/userfiles/file/venivubatazenixekiruv.pdf
- http://euskararenginkana.eus/files/galeria/files/tevupidonika.pdf
- http://labuchedeberce.fr/userfiles/file/28792781973.pdf
- http://att-na.com/upload/savifilitorafitoxemaro.pdf
- http://gzcil.com/uploadfile/files/84847276133.pdf
- https://rrr71.ru/upload_picture/lamifolixo.pdf
- https://techlan.pl/files/file/9584121479.pdf
- http://lavera.it/wp-content/plugins/formcraft/file-upload/server/content/files/1614e71fe1c88b---jeredajagubolebigimatabew.pdf
- http://www.valaisconsulting.ch/file/81748498742.pdf
Embedded domains
- coretry.ru
- tigapilar.com
- stjconsulting.it
- redfortfireworks.com
- skuplaptop.pl
- houstoncoinclub.org
- inphilong.com
- ventss.ru
- naoshima-tours.com
- veganogle.es
- www.campacinter.com
- creteservices.com
- spzpoz-zdunskawola.pl
- bhartiyambeohari.in
- labuchedeberce.fr
- att-na.com
- gzcil.com
- rrr71.ru
- techlan.pl
- lavera.it
- www.valaisconsulting.ch
- hv2barrier.com
- noble-program.site
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report