MALICIOUS — 72ffb404edf5e7048fab777722d8df5db84230cac91716138fc1c6d9d5824c35
MALICIOUS — 72ffb404edf5e7048fab777722d8df5db84230cac91716138fc1c6d9d5824c35 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
72ffb404edf5e7048fab777722d8df5db84230cac91716138fc1c6d9d5824c35 - SHA-1:
c5eaeba652c18a35226a054045912d2651454ca1 - MD5:
5901fba6e4cefefaac4c3c2dfd3b27d7 - ssdeep:
1536:VdGQYh6gmxuP6ERfB9WdXey2cgBK1u4lWZEypF0A8W6pOu2PfAYV0EBqk:DG9h84P6ER3eXeyZgBKpq0A1u2PfAYZz - TLSH:
T12738CFF3619BED4C76CB9F03AAF641983089D6C861729A50008CB66CD86C6FDFF50A54 - Submitted as: 72ffb404edf5e7048fab777722d8df5db84230cac91716138fc1c6d9d5824c35
- File type: pdf · Size: 79994 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://pavaniautismschools.com/wp-content/plugins/super-forms/uploads/php/files/k3kofu5slish8sjok48ja8rp8o/tewamiletesatejologoku.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://oniceh.ru/uplcv?utm_term=pokemon+gold+pokemon+cheats, http://ufcnagykanizsa.hu/userfiles/file/38224914101.pdf, https://fablab808.com/nbloom/fckuploads/file/1206455132.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oniceh.ru/uplcv?utm_term=pokemon+gold+pokemon+cheats
- http://ufcnagykanizsa.hu/userfiles/file/38224914101.pdf
- https://fablab808.com/nbloom/fckuploads/file/1206455132.pdf
- http://www.iamgoingto1996.com/wp-content/plugins/formcraft/file-upload/server/content/files/161360e63784f5---seledipafupoxitem.pdf
- https://pavaniautismschools.com/wp-content/plugins/super-forms/uploads/php/files/k3kofu5slish8sjok48ja8rp8o/tewamiletesatejologoku.pdf
- http://luijkzonwering.nl/image/file/nimejux.pdf
- https://binarbaidfabrication.com/public_html/userfiles/file/62453276254.pdf
- http://zoo-foto.cz/userfiles/file/kuzogokus.pdf
- http://lisaarkin.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/56644268128.pdf
- http://tatishev.ru/admin/ckfinder/userfiles/files/89310342641.pdf
- http://www.danvillern.com/wp-content/plugins/super-forms/uploads/php/files/3750354a61ce41da70a3f01c48d7dc17/kasidotemojaf.pdf
- http://espwireless.net/uploads/file/fukuxazilenigig.pdf
- http://dichvugiayphep.net/hinhanh_fckeditor/file/30714178278.pdf
- https://moma-restaurant.com/wp-content/plugins/formcraft/file-upload/server/content/files/16141a5c591034---52940868047.pdf
- http://school15-tyumen.ru/f/85335921999.pdf
- https://serka.com/serka/upload/files/47212453260.pdf
- https://mcq-exambd.com/app/webroot/ckfinder/userfiles/files/kanovaxokotuj.pdf
- https://fu-ko-property-agency.com/webroot/editor-uploads/files/jubivepuwovumomo.pdf
- http://wjvanderheidedienstverlening.nl/uploads/file/5936657729.pdf
- http://effektfilm.de/files/file/94179186504.pdf
- http://hicoweld.com/shop/fck_file/file/gujesibogonidalikokenof.pdf
- https://quangcaonoithatgiahung.com/admin/webroot/upload/image/files/58083052728.pdf
- https://syteq-pro.com/userfiles/file/78974988985.pdf
- http://maginsaatmetal.com/resimlerfiles/84321790690.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- oniceh.ru
- fablab808.com
- www.iamgoingto1996.com
- pavaniautismschools.com
- luijkzonwering.nl
- binarbaidfabrication.com
- lisaarkin.com
- tatishev.ru
- www.danvillern.com
- espwireless.net
- dichvugiayphep.net
- moma-restaurant.com
- school15-tyumen.ru
- serka.com
- mcq-exambd.com
- fu-ko-property-agency.com
- wjvanderheidedienstverlening.nl
- effektfilm.de
- hicoweld.com
- quangcaonoithatgiahung.com
- syteq-pro.com
- maginsaatmetal.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report