MALICIOUS — 88f1fb1eb10a7303a93e5b69797f5528b5590dd2bac7036611420efc7bde40ea
MALICIOUS — 88f1fb1eb10a7303a93e5b69797f5528b5590dd2bac7036611420efc7bde40ea is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
88f1fb1eb10a7303a93e5b69797f5528b5590dd2bac7036611420efc7bde40ea - SHA-1:
79e442fd539f81798eb011fff7586255ccd346f4 - MD5:
c6d6d661d80e6f56745ad8ce8a281340 - ssdeep:
1536:a1XGJykPrgRkEwwe5iHgnHRcPZxWnEjA21kTeS5n3yvPPlWUpO7kMH:q6ySrsjKc3mx52Pg7N - TLSH:
T1D137BEF731DBED5C7BD69B036CAD5069948AD7C89132DA504088B7ACD87C9BEBE10900 - Submitted as: 88f1fb1eb10a7303a93e5b69797f5528b5590dd2bac7036611420efc7bde40ea
- File type: pdf · Size: 70252 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://peter-crooks.com/userfiles/file/56847324034.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://rnralpha.cz/res/file/maduxeravejosuwufinota.pdf, http://peter-crooks.com/userfiles/file/56847324034.pdf, http://theaterbuehne-schwandorf.de/userfiles/file/40294985796.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/3vuEKuznOb8/uplcv?utm_term=bloons+td+5+360
- http://rnralpha.cz/res/file/maduxeravejosuwufinota.pdf
- http://peter-crooks.com/userfiles/file/56847324034.pdf
- http://theaterbuehne-schwandorf.de/userfiles/file/40294985796.pdf
- https://ahreco.com/uploads/news_file/butowagavaronimibogavolu.pdf
- https://hippodrome-compiegne.fr/www/uploads/file/64005299155.pdf
- https://tortugafilms.ca/adminfiles/file/jutoweguzowab.pdf
- https://institut-arabe.org/ckfinder/userfiles/files/dirujude.pdf
- http://managhantasala.net/mailuserfiles/file/wizoribiwetexojefowomexev.pdf
- http://optometrystaprzemysl.pl/userfiles/file/67393381435.pdf
- https://www.zochrot.org/ckfinder/userfiles/files/deden.pdf
- http://mas.vacations/wp-content/plugins/formcraft/file-upload/server/content/files/1614931e7c40f8---26700093327.pdf
- http://rileyillustration.com/images/agency/files/46336006084.pdf
- http://jysfh.com/upload_fck/file/2021-9-13/20210913110218983686.pdf
- https://velvetskin.pl/wp-content/plugins/super-forms/uploads/php/files/b2ba1c9264cf49256008f7f3b91d18de/ribogolorapijirasaxowal.pdf
- http://chiron-ventures.com/chiron/home/img/upload/files/210912090801627145o0wzw.pdf
- http://iwilldoit.ru/uploads/files/files/59360100120.pdf
- http://www.holzbau-hoelzl.at/wp-content/plugins/formcraft/file-upload/server/content/files/1614b9f575b690---96882757414.pdf
- https://projektovanje.info/userfiles/file/99196496049.pdf
- http://btfa.tw/upload/files/wotazovunibififitevafek.pdf
- http://votava2.altrodesign.eu/ckfinder/userfiles/files/nenaneboduri.pdf
- http://daithanhnam.com/upload/files/81653091578.pdf
- http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/dbde23b1c68958508613b8ff8199382d/doruwusumiposibadesave.pdf
- http://cbcom.fr/ressource/site-image/files/47756281820.pdf
- http://changjiujz.com/uploads/files/202109170433087172.pdf
Embedded domains
- feedproxy.google.com
- peter-crooks.com
- theaterbuehne-schwandorf.de
- ahreco.com
- hippodrome-compiegne.fr
- tortugafilms.ca
- institut-arabe.org
- managhantasala.net
- optometrystaprzemysl.pl
- www.zochrot.org
- rileyillustration.com
- jysfh.com
- velvetskin.pl
- chiron-ventures.com
- iwilldoit.ru
- projektovanje.info
- btfa.tw
- votava2.altrodesign.eu
- daithanhnam.com
- nd-58.ru
- cbcom.fr
- changjiujz.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report