MALICIOUS — 8e35996470c4ba107d4470c23e661d57f9424dbdc38e89820463c3fc0a93e4b1
MALICIOUS — 8e35996470c4ba107d4470c23e661d57f9424dbdc38e89820463c3fc0a93e4b1 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8e35996470c4ba107d4470c23e661d57f9424dbdc38e89820463c3fc0a93e4b1 - SHA-1:
7f41d3b0eae304368a26743e4677f8c20bd31397 - MD5:
8e505c778546b1d7c88a042617d1d969 - ssdeep:
1536:ZcP7c0aaF/gRAdGIuKxtVxRAsek8T+bJxbSV8V7L/+kWMvaH0uWyWQpOCIdxSypD:AIalgRAdduKxtlAs/8T+bzbrd2AilWV3 - TLSH:
T1E339C0F731D7CD8D33879F03A9AB10ACA886D7986172D75040887A6C94789FDBF20952 - Submitted as: 8e35996470c4ba107d4470c23e661d57f9424dbdc38e89820463c3fc0a93e4b1
- File type: pdf · Size: 87998 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://stroyindustry.com/userfiles/file/niberakopabiluwep.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=depressing+but+true+quotes, http://stroyindustry.com/userfiles/file/niberakopabiluwep.pdf, http://lammermoor.net/imagenes/file/40613967229.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/uplcv?utm_term=depressing+but+true+quotes
- http://stroyindustry.com/userfiles/file/niberakopabiluwep.pdf
- http://lammermoor.net/imagenes/file/40613967229.pdf
- https://savitravel.ro/ckfinder/userfiles/files/pibinefafivanume.pdf
- https://hk-delight.com/UploadFiles/file/xadugowe.pdf
- http://boston.pl/fck_pliki/file/loxivesonejagerodu.pdf
- http://www.ponderosafestival.com/wp-content/plugins/formcraft/file-upload/server/content/files/161407fac4d98e---fuwakuxobonavinasowodebu.pdf
- http://vipforiraq.com/userfiles/files/83609744246.pdf
- http://klhl.com/userfiles/file/wedutaxidi.pdf
- https://taperagi.com/contents/files/lilavenoguwefil.pdf
- http://softwarefactory.nl/images/file/47097803045.pdf
- http://iviltra.lt/images/files/38899285421.pdf
- https://hamzakocakoglu.com/userfiles/file/zazatuwimidelitoxefopalu.pdf
- http://gabinetortodontyczny.eu/userfiles/file/vuseviw.pdf
- http://kiko168.com/UploadFile/file/20210901142437527.pdf
- http://pacemakerpressintl.com/uploads/assets/file/dugag.pdf
- http://petgears.com/app/webroot/files/file/xapeweroradamevilazo.pdf
- https://trsbarriersdirect.com/wp-content/plugins/super-forms/uploads/php/files/btdq7ur32m45mvuuf9ip2p6fin/94616386298.pdf
- http://mynigaoe.com/upload/file/20210910223720.pdf
- http://sungwoo-n.com/userfiles/file/gowuvu.pdf
- https://go2germany.ru/files/file/72653161410.pdf
- https://www.renfrewareahealthvillage.ca/ckfinder/userfiles/files/refevufoxefusav.pdf
- http://abwingsde.com/uploads/files/rolerolobe.pdf
- http://burelomdo.com/ckfinder/userfiles/files/88473587486.pdf
- https://deshpanday.com/ckfinder/userfiles/files/12204356258.pdf
Embedded domains
- medvor.ru
- stroyindustry.com
- lammermoor.net
- hk-delight.com
- boston.pl
- www.ponderosafestival.com
- vipforiraq.com
- klhl.com
- taperagi.com
- softwarefactory.nl
- hamzakocakoglu.com
- gabinetortodontyczny.eu
- kiko168.com
- pacemakerpressintl.com
- petgears.com
- trsbarriersdirect.com
- mynigaoe.com
- sungwoo-n.com
- go2germany.ru
- www.renfrewareahealthvillage.ca
- abwingsde.com
- burelomdo.com
- deshpanday.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report