MALICIOUS — 8fefee5322de750e14b588425ebd933cf944297c9050e6159fc7b831132495c2
MALICIOUS — 8fefee5322de750e14b588425ebd933cf944297c9050e6159fc7b831132495c2 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8fefee5322de750e14b588425ebd933cf944297c9050e6159fc7b831132495c2 - SHA-1:
6f228f2a534ba03c0bec4e549ed924ed69be4c5e - MD5:
41cc84bc86c59f0779c08d7e5f428d27 - ssdeep:
1536:05+5vi+5A7KKMFWijuDK9PYkbfiLWu1LOpasWcpOmJ1l:HvD4eWiiQPYsibqpa3md - TLSH:
T10037BFF360EBDD0C779B87436CA72258A186E7481673EB100588776CD47C67E7B20A91 - Submitted as: 8fefee5322de750e14b588425ebd933cf944297c9050e6159fc7b831132495c2
- File type: pdf · Size: 72547 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://forglory.cz/ckfinder/userfiles/files/71360150250.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://freewest.at/sirajexonejunirej.pdf, http://www.tecs4.com/intranet/ckfinder/userfiles/files/84434699036.pdf, https://shoppe.everybodyisnotdoingit.org/gift/userfiles/files/93937118958.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/PmAiG5ZyT-k/uplcv?utm_term=game+of+thrones+season+1+episode+2+free
- http://freewest.at/sirajexonejunirej.pdf
- http://www.tecs4.com/intranet/ckfinder/userfiles/files/84434699036.pdf
- https://shoppe.everybodyisnotdoingit.org/gift/userfiles/files/93937118958.pdf
- http://hopkim.vn/upload/files/12827214805.pdf
- http://forglory.cz/ckfinder/userfiles/files/71360150250.pdf
- https://heritagecambodiatravel.com/userfiles/file/39655644914.pdf
- http://archiwum.wyryki.eu/admin/ckfinder/userfiles/files/93486177987.pdf
- https://kaptenhoki.org/contents/files/jawaxozeg.pdf
- https://polenhosting.com/calisma2/files/uploads/dotusagelubetitubizofupuz.pdf
- https://cradlegold.com/wp-content/plugins/super-forms/uploads/php/files/3mnt3bqj9agak2nj41g237ou3f/6000497074.pdf
- http://homeopathyhk.com/files/59360326702.pdf
- http://partner-support.net/user_data/userfiles/files/buveruz.pdf
- http://dopuskvsro.ru/UserFiles/gizerin.pdf
- https://trakyasoftavukatwebsitesi.demowebsiteleri.com/upload/files/gogerijinirawanefituwi.pdf
- https://artsketch.ru/wp-content/plugins/super-forms/uploads/php/files/65d486b6379ff3d522c79d4b14d643dd/sosizolifeze.pdf
- https://vresponse.net/userfiles/file/zabipoloxuvu.pdf
- http://opersan.com/file/31646289797.pdf
- http://whipitleather.com/userfiles/file/kufitapo.pdf
- http://neonatal-surgery.ru/userfiles/files/vazanibovib.pdf
- http://cerritos.songhakbbq.com/uploads/files/vulatoxurasasumowivig.pdf
- http://holdemigny.fr/ckfinder/userfiles/files/15748627293.pdf
- http://yhbinternational.com/userfiles/file/23312826541.pdf
- http://zadonskiy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/161326da46e46d---98187225282.pdf
- http://personal.sut.ac.th/chantira/port/ckfinder/userfiles/files/42400932130.pdf
Embedded domains
- feedproxy.google.com
- www.tecs4.com
- shoppe.everybodyisnotdoingit.org
- heritagecambodiatravel.com
- archiwum.wyryki.eu
- kaptenhoki.org
- polenhosting.com
- cradlegold.com
- homeopathyhk.com
- partner-support.net
- dopuskvsro.ru
- trakyasoftavukatwebsitesi.demowebsiteleri.com
- artsketch.ru
- vresponse.net
- opersan.com
- whipitleather.com
- neonatal-surgery.ru
- cerritos.songhakbbq.com
- holdemigny.fr
- yhbinternational.com
- zadonskiy.ru
- mosoptagro.ru
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report