MALICIOUS — 795825039af20d35baff57f326019f87a9f37eb97c8ca8ac713abe7db1646157
MALICIOUS — 795825039af20d35baff57f326019f87a9f37eb97c8ca8ac713abe7db1646157 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
795825039af20d35baff57f326019f87a9f37eb97c8ca8ac713abe7db1646157 - SHA-1:
32e0ba049864051215075c0bf0c6c4294d6cac7d - MD5:
0454dbb76f738181e92c968270931847 - ssdeep:
1536:lJHvlN2aVwIi3pRnBYejUfyo/yYDIyMe3XX6n5LRW6pOu2BioFxkBWjQEwGbxv4S:PlAkOB9jUao/yYDIyMuoyu2BiOQNS - TLSH:
T11239C0F3228BDD4C769BDB03A9E711B89046E68C5111FB910588776CC1BCABDBF18A40 - Submitted as: 795825039af20d35baff57f326019f87a9f37eb97c8ca8ac713abe7db1646157
- File type: pdf · Size: 84602 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://skulpt.in/admin/uploads/file/48090347247.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://hftyby.com/upload_fck/file/2021-9-12/20210912064443162297.pdf, https://www.breastcancerfoundation.in/wp-content/plugins/super-forms/uploads/php/files/00b0b5e14c57f85d3eb9c3516ed1eecb/61515399141.pdf, http://ban-dong-ban-mat.theonejsc.com/userfiles/file/40233449661.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/MbOu/~3/BGAemAmcdTc/uplcv?utm_term=how+many+tea+bags+do+i+use+in+mr+coffee+iced+tea+maker
- http://hftyby.com/upload_fck/file/2021-9-12/20210912064443162297.pdf
- https://www.breastcancerfoundation.in/wp-content/plugins/super-forms/uploads/php/files/00b0b5e14c57f85d3eb9c3516ed1eecb/61515399141.pdf
- http://ban-dong-ban-mat.theonejsc.com/userfiles/file/40233449661.pdf
- http://citra.cl/userfiles/file/41653835167.pdf
- http://skulpt.in/admin/uploads/file/48090347247.pdf
- https://www.dekleinewerf.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1612f5317021cc---lefosutawubo.pdf
- https://siltri.com/fck_upload/file/72716540713.pdf
- http://topup-fight.com/ckfinder/userfiles/files/38540277603.pdf
- http://www.videocopilot.net/assets/public/ckfinder/userfiles/files/tetamazokana.pdf
- https://banifatemehmashhad.ir/userfiles/file/pamato.pdf
- https://nicemexico.net/wp-content/plugins/formcraft/file-upload/server/content/files/161410e2c857c3---dodiv.pdf
- https://www.antoniopopolizio.it/ckfinder/userfiles/files/54441226561.pdf
- https://aneri12.eu/res/file/nanosasikezudonexagu.pdf
- http://kanchanaspa.com/ckfinder/userfiles/files/99743434112.pdf
- http://sluchatka-shop.cz/files/upload/files/286172091.pdf
- https://megashina24.ru/files/files/59756554197.pdf
- https://studiogreenwich.ru/wp-content/plugins/super-forms/uploads/php/files/ddbafca5b1e61d68534d4b2b7e0293ad/97087383067.pdf
- http://aucontecnologia.com/userfiles/files/74330256581.pdf
- https://iwistw.com/upload/files/63392599039.pdf
- http://aweibel.com/Photo/file/99993230170.pdf
- http://www.oschouston.com/osc/wp-content/plugins/formcraft/file-upload/server/content/files/1615d9030c1e38---84329400945.pdf
- http://aotwcasino.com/ckfinder/userfiles/files/bazodo.pdf
- https://fresh-cherries.com/ckfinder/userfiles/files/34321972914.pdf
- https://fototipia.hu/files/files/48535218403.pdf
Embedded domains
- feedproxy.google.com
- hftyby.com
- www.breastcancerfoundation.in
- ban-dong-ban-mat.theonejsc.com
- skulpt.in
- www.dekleinewerf.nl
- siltri.com
- topup-fight.com
- www.videocopilot.net
- banifatemehmashhad.ir
- nicemexico.net
- www.antoniopopolizio.it
- aneri12.eu
- kanchanaspa.com
- megashina24.ru
- studiogreenwich.ru
- aucontecnologia.com
- iwistw.com
- aweibel.com
- www.oschouston.com
- aotwcasino.com
- fresh-cherries.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report