MALICIOUS — 92516ba320df4682582b430cd66abb2130fcc05f79d7393df090ab4c0004dfc1
MALICIOUS — 92516ba320df4682582b430cd66abb2130fcc05f79d7393df090ab4c0004dfc1 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
92516ba320df4682582b430cd66abb2130fcc05f79d7393df090ab4c0004dfc1 - SHA-1:
f3222733fcdec086834026d53fe708582ec3919f - MD5:
35f05fbda094ec1f9cca05469a52a5e7 - ssdeep:
1536:se5h2YIqzEtIkMgt3RZxopJ/i7/3yqOL/vWM8hXWL0L5cWQpOCvPC23y:tDqqzEtIpmRzopJ/FhK5bC3I - TLSH:
T11738CFF321D7ED8C7B8ADF0369F511986089D34871A2DA9520C87A7CD57C9FEAE04A01 - Submitted as: 92516ba320df4682582b430cd66abb2130fcc05f79d7393df090ab4c0004dfc1
- File type: pdf · Size: 83203 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ukrainski-rosyjski.pl/userfiles/file/88660265765.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://jr-bang.com/uploadfiles/20210913224554.pdf, https://masterok-kovka.ru/wp-content/plugins/super-forms/uploads/php/files/a6968ea4b029145a962f63078a6799d9/60092409483.pdf, http://larrysiegellaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/20673007776.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1KS0DP0cxss/uplcv?utm_term=black+screen+apk
- http://jr-bang.com/uploadfiles/20210913224554.pdf
- https://masterok-kovka.ru/wp-content/plugins/super-forms/uploads/php/files/a6968ea4b029145a962f63078a6799d9/60092409483.pdf
- http://larrysiegellaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/20673007776.pdf
- https://www.dynasil.com/wp-content/plugins/super-forms/uploads/php/files/e14c0951000e0ed59111a7375be219af/82911738111.pdf
- https://barcelonamedicalcenter.com/files/galeria/files/91746469503.pdf
- https://fwstc.in/userfiles/file/36560330115.pdf
- https://hamayeshniroo.com/shop/file/40801072728.pdf
- http://ukrainski-rosyjski.pl/userfiles/file/88660265765.pdf
- http://80tner.netsociality.com/upload/files/nulokopizowefad.pdf
- https://bokaichenyu.com/upload/files/vujekefokejadagerewop.pdf
- http://www.agrosystem.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1613c89fab1a6b---36852547516.pdf
- https://vayamcs.com/content_files/files/16682263647.pdf
- http://jj-metals.com/userfiles/file/2021091221521173499.pdf
- http://aotwresort.net/ckfinder/userfiles/files/74670713457.pdf
- http://garage-ys.info/js/upload/files/nanikerugilop.pdf
- http://ysmenmidwestindia.org/uploads/userfiles/file/file/68990645856.pdf
- http://fishngrill.iorderfoods.com/uploads/files/58087199471.pdf
- https://mattweidnerlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613f3aa82e369---juzenotewakofatewubalana.pdf
- http://www.fred-robin.com/ckfinder/userfiles/files/wijotutonosizidoz.pdf
- http://grandwatergatehotel.com/upfile_hotel/files/kowigixavoto.pdf
- https://linhngapt.vn/upload/files/fekutomajudovusipinimow.pdf
- http://donkaew-furniture.com/ckfinder/userfiles/files/sopevewenemibozazeka.pdf
- https://pankajplast.com/ckfinder/userfiles/files/nawonuw.pdf
- http://hanasushimenifee.com/uploads/files/lalotirin.pdf
Embedded domains
- feedproxy.google.com
- jr-bang.com
- masterok-kovka.ru
- larrysiegellaw.com
- www.dynasil.com
- barcelonamedicalcenter.com
- fwstc.in
- hamayeshniroo.com
- ukrainski-rosyjski.pl
- 80tner.netsociality.com
- bokaichenyu.com
- vayamcs.com
- jj-metals.com
- aotwresort.net
- garage-ys.info
- ysmenmidwestindia.org
- fishngrill.iorderfoods.com
- mattweidnerlaw.com
- www.fred-robin.com
- grandwatergatehotel.com
- donkaew-furniture.com
- pankajplast.com
- hanasushimenifee.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report