MALICIOUS — 8f42134aa90e32929649572494c3053ad8231b107280714eb0d8db39bf1a51d7
MALICIOUS — 8f42134aa90e32929649572494c3053ad8231b107280714eb0d8db39bf1a51d7 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8f42134aa90e32929649572494c3053ad8231b107280714eb0d8db39bf1a51d7 - SHA-1:
3bc294d2f485c74f925c510f2eaa919d168746ec - MD5:
e30cf650c4b87ebed7652c4528e19735 - ssdeep:
3072:uvpTH90i6FLZmhiawTgZxI+/cx7mQ9O7VV5HMfK0SD:uH90ZxZmhvwoxlER9Gf - TLSH:
T18B3AE1F360A7DDCD7B86CF437AEA11056085E6C82096E79044887A5CC7BC6BD7F14622 - Submitted as: 8f42134aa90e32929649572494c3053ad8231b107280714eb0d8db39bf1a51d7
- File type: pdf · Size: 101752 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://aquamedia.cn/ckfinder/userfiles/files/gebaxatesurufasak.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://oniceh.ru/uplcv?utm_term=grey+bird+with+brown+head, http://windcampus.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614b0abcc571f---vefaloleletafazoge.pdf, https://www.seblocation.com/ckfinder/userfiles/files/54012942600.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oniceh.ru/uplcv?utm_term=grey+bird+with+brown+head
- http://windcampus.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614b0abcc571f---vefaloleletafazoge.pdf
- https://www.seblocation.com/ckfinder/userfiles/files/54012942600.pdf
- http://autoscuolavalerio.it/userfiles/files/86891885948.pdf
- http://aquamedia.cn/ckfinder/userfiles/files/gebaxatesurufasak.pdf
- https://peoplesmodelinternational.com/ckfinder/userfiles/files/tosupilop.pdf
- https://www.potterycommercials.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16136c8b15ac8e---75628258870.pdf
- https://hitourkorea.com/FileData/ckfinder/files/20210903_6B3E86F10D1FFFC1.pdf
- https://alpinebadmintonacademy.com/ckfinder/userfiles/files/45735367514.pdf
- https://monarchwinemerchants.com/wp-content/plugins/super-forms/uploads/php/files/439c0b1c1b787f336c519ab645b4d0f6/bofabirarapi.pdf
- http://boatmonies.com/uploads/files/jiwuzumaxeso.pdf
- https://doctmcooper.com/userfiles/files/sovavekukixetapavasu.pdf
- https://feltshoe.com/userfiles/file/pewejopiborobumanig.pdf
- http://inciboya.com/resimler/site/files/daradomota.pdf
- https://aldwalia.com/userfiles/files/64405812034.pdf
- http://scuolascifondocortinadolomiti.it/userfiles/files/dafilajap.pdf
- http://sistersaviopublicschool.com/userfiles/file/duwexusuzok.pdf
- http://tindangnhadat.vn/upload/files/tigofugikexaz.pdf
- http://ozsersogutma.com/upload/files/97013836687.pdf
- http://www.greenfield-sustainability.com/images/files/demokekopefoxijenewaraf.pdf
- https://kemxoithanhhang.vn/app/webroot/files/images/pages/files/rupuxenut.pdf
- http://evolution-dev.com/file_media/file_image/file/36878471423.pdf
- http://myhoteltrip.com/userfiles/file/71432790002.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- oniceh.ru
- windcampus.com
- www.seblocation.com
- autoscuolavalerio.it
- aquamedia.cn
- peoplesmodelinternational.com
- www.potterycommercials.co.uk
- hitourkorea.com
- alpinebadmintonacademy.com
- monarchwinemerchants.com
- boatmonies.com
- doctmcooper.com
- feltshoe.com
- inciboya.com
- aldwalia.com
- scuolascifondocortinadolomiti.it
- sistersaviopublicschool.com
- ozsersogutma.com
- www.greenfield-sustainability.com
- evolution-dev.com
- myhoteltrip.com
- www.w3.org
- purl.org
- ns.adobe.com
- tindangnhadat.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report