MALICIOUS — 7ef6353c7a078ebaeb659dbed8b96143ea81251ca9324bd6c62beb23db37a26c
MALICIOUS — 7ef6353c7a078ebaeb659dbed8b96143ea81251ca9324bd6c62beb23db37a26c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7ef6353c7a078ebaeb659dbed8b96143ea81251ca9324bd6c62beb23db37a26c - SHA-1:
e9751d4497a8c78e7f96f9095193c5b078f6f755 - MD5:
1dc47f9651fbec60780d9f28259e896d - ssdeep:
1536:QMk6PhK/XJ1oThi4VX5u47rItsOVsuI5fLxHsTrWxApOGzWIeNHrPGHW:vVsr2hXVX5ctsOVI5hsg3GINTz - TLSH:
T10338CFF311E7DD4C7B8ECF5359EB2169A14AE78C6122EB909088765C947CABCBF00910 - Submitted as: 7ef6353c7a078ebaeb659dbed8b96143ea81251ca9324bd6c62beb23db37a26c
- File type: pdf · Size: 76693 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://phucatgarment.com.vn/ckfinder/userfiles/files/simotesawinopena.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://handientu.vn/userfiles/file/tajizitoxidinabodamibuwog.pdf, https://phucatgarment.com.vn/ckfinder/userfiles/files/simotesawinopena.pdf, https://fishboat.hr/files/97599377490.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/DOqCt-cVA4I/uplcv?utm_term=best+paying+jobs+on+gta+5+online
- https://handientu.vn/userfiles/file/tajizitoxidinabodamibuwog.pdf
- https://phucatgarment.com.vn/ckfinder/userfiles/files/simotesawinopena.pdf
- https://fishboat.hr/files/97599377490.pdf
- https://ladychief.com/wp-content/plugins/super-forms/uploads/php/files/1593d3a9fb860890b5aa199fa4d3091a/27924614414.pdf
- http://dlshixiang.com.cn/ckfinder/userfiles/files/50339015085.pdf
- http://dobre-jaja.com/Upload/file/56666810345.pdf
- http://www.florentmaussion.net/userfiles/File/gabelodezebimutifubilevo.pdf
- http://www.pattyn360.com/upload/forum/files/368195697.pdf
- http://fkm-lux.by/var/upload/file/lugabigeribuzuzawelufef.pdf
- https://imapcb.org/wp-content/plugins/super-forms/uploads/php/files/7cfff0a4108988e9c914759d9d9c0a38/divelakukurujo.pdf
- http://liavanhaeringen.nl/userfiles/files/38578607725.pdf
- http://ukicda.com/admin/fckeditor_upfiles/file/2021090901573580554.pdf
- http://clubselectionvoyages.net/images/file/nifip.pdf
- https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/702c0a529282b54954461f6a611a0c37/levonupigukinifon.pdf
- http://yourtruck.be/upload/ckeditor/file/bonekadolimevaganiw.pdf
- http://materialdeestudo.top/userfiles/files/22400630774.pdf
- https://tarsiman.ee/files/file/gididematinijibururozofox.pdf
- https://bettergraph.rockeit.com/userfiles/file/mebekamekeso.pdf
- http://bagandpack.ru/wp-content/plugins/super-forms/uploads/php/files/c621d772e54e80ef0fb81f9ce6579ab4/supefasad.pdf
- https://www.peltonfell.org.uk/ckfinder/userfiles/files/92320688344.pdf
- http://na3.it/misc/file/49548572859.pdf
- https://ncsccalgary.com/userfiles/files/10263301053.pdf
- http://biplano.eu/userfiles/files/fuxige.pdf
- http://ustunongel.com/image/files/65389529163.pdf
Embedded domains
- feedproxy.google.com
- ladychief.com
- dlshixiang.com.cn
- dobre-jaja.com
- www.florentmaussion.net
- www.pattyn360.com
- imapcb.org
- liavanhaeringen.nl
- ukicda.com
- clubselectionvoyages.net
- amartzon.store
- yourtruck.be
- materialdeestudo.top
- bettergraph.rockeit.com
- bagandpack.ru
- www.peltonfell.org.uk
- na3.it
- ncsccalgary.com
- biplano.eu
- ustunongel.com
- mallorcaboom.com
- mutitar.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report