MALICIOUS — 77b761d4a81f88f34fcf9ff7ab76587b.pdf
MALICIOUS — 77b761d4a81f88f34fcf9ff7ab76587b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8ac2baf13afd59881d54a70f7a48715a2ceddcd3fc8ca19436ffed785ffcc52f - SHA-1:
f328b80e36e399f44f7de1449939e3bad8d0b36e - MD5:
76189481e3e4cb0b71f1ce7e753aeb5c - ssdeep:
1536:uqVqZuIFbE388QVc3+GKL/l2uqZzVRWrqORvoG2iHOnvTIWXpO/QAV:NIFCHQVcuGKL/l2umVUqORvoG2i0A/7 - TLSH:
T13D39C0F311EBDC5CBBDF8F0374AA019C608AD68861A1EBA44448673CD5BCA7E7E10651 - Submitted as: 77b761d4a81f88f34fcf9ff7ab76587b.pdf
- File type: pdf · Size: 88708 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ildong.org/sa_upload/userfiles/file/20210908232303.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://blesk-stroy.ru/userfiles/files/11073654809.pdf, http://ildong.org/sa_upload/userfiles/file/20210908232303.pdf, http://ergakiland.ru/files/files/56137606259.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/DOqCt-cVA4I/uplcv?utm_term=gta+5+cell+phone+cheats+money
- http://blesk-stroy.ru/userfiles/files/11073654809.pdf
- http://ildong.org/sa_upload/userfiles/file/20210908232303.pdf
- http://ergakiland.ru/files/files/56137606259.pdf
- http://firesecurity.sk/userfiles/file/zisameloxemasabotuxesuk.pdf
- http://wych123.com/upload/files/51207081645.pdf
- https://cvzona.lt/resources/img/files/99408857921.pdf
- http://www.tlo.ntou.edu.tw/ckfinder/userfiles/files/12168422324.pdf
- http://geoplan.su/userfiles/file/lanulavaz.pdf
- http://flathead.herosuite.com/userfiles/file/bogitibasupugetesu.pdf
- https://www.jahnigterbraak.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16140e124dc072---bimoxanipasatimatas.pdf
- https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/967ecda29cd0fce5f88f6f941e256d98/zixumeteguweza.pdf
- http://romengo.com/ckfinder/userfiles/files/22322489930.pdf
- http://factory-01.com/js/upload/files/faporezojesovipowu.pdf
- https://buddingheights.org/wp-content/plugins/formcraft/file-upload/server/content/files/16140b933366d7---3731315265.pdf
- https://k9-warrior.com/wp-content/plugins/super-forms/uploads/php/files/o6ovde0htf0p1uonei96sf9sb6/napewun.pdf
- http://makrostal.pl/user_images/file/48557075965.pdf
- http://dienlanhhuubinh.com/upload/files/18130382854.pdf
- https://machnhaduong.com/images/uploads/files/99149066531.pdf
- http://monthclean.com/uploads/files/202109112202101876.pdf
- https://chuyennhakienvangvn.net/upload/files/gakubitevujaba.pdf
- https://matricula.arendic.cl/files/wakugazu.pdf
- http://dmn.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1612f79d3ece0f---jesafigafozebade.pdf
- http://madiagranitosilano.it/userfiles/files/movosixes.pdf
- http://hzbmsj.com/images/upload/File/nuwofumovukubatelapa.pdf
Embedded domains
- feedproxy.google.com
- blesk-stroy.ru
- ildong.org
- ergakiland.ru
- wych123.com
- www.tlo.ntou.edu.tw
- geoplan.su
- flathead.herosuite.com
- www.jahnigterbraak.nl
- amezdigital.com
- romengo.com
- factory-01.com
- buddingheights.org
- k9-warrior.com
- makrostal.pl
- dienlanhhuubinh.com
- machnhaduong.com
- monthclean.com
- chuyennhakienvangvn.net
- dmn.ca
- madiagranitosilano.it
- hzbmsj.com
- dintek.eu
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report