MALICIOUS — 930aa434306cd8cf6f40b41124deca6c4411c693d80b7dcde3fe7ace5929d1a5
MALICIOUS — 930aa434306cd8cf6f40b41124deca6c4411c693d80b7dcde3fe7ace5929d1a5 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
930aa434306cd8cf6f40b41124deca6c4411c693d80b7dcde3fe7ace5929d1a5 - SHA-1:
ddb5611198a724a320efe27c054366b707731d48 - MD5:
d90d2be93c1e2560da16215eed6ad798 - ssdeep:
1536:6DQz0G7pi/8mxMRUwVjivInTcL/+f7NBiksaWtY/Sgb12oZyWQpOCh0Q:LiaHnTc7+TyFjhgzZVCV - TLSH:
T16138C0F33097ED4C764ACB4379AA1139A446E7896251EED00488BBBC957C9FE3F00960 - Submitted as: 930aa434306cd8cf6f40b41124deca6c4411c693d80b7dcde3fe7ace5929d1a5
- File type: pdf · Size: 76801 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://aumnat2car.com/ckfinder/core/connector/php/upload/files/749557541.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://aumnat2car.com/ckfinder/core/connector/php/upload/files/749557541.pdf, http://3duct.com/wp-content/plugins/formcraft/file-upload/server/content/files/16151d2e17eeba---46848020199.pdf, http://conhantaoankhanh.com/webroot/img/files/javijipibureme.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Gsjc/~3/TSvcnjQ06Jg/uplcv?utm_term=round+off+to+the+second+decimal+place
- http://aumnat2car.com/ckfinder/core/connector/php/upload/files/749557541.pdf
- http://3duct.com/wp-content/plugins/formcraft/file-upload/server/content/files/16151d2e17eeba---46848020199.pdf
- http://conhantaoankhanh.com/webroot/img/files/javijipibureme.pdf
- http://nhatrangpalacehotel.com/app/webroot/upload/files/kejadugepawor.pdf
- https://fermuar.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613c98c477974---kineb.pdf
- https://hardlineconstruct.ro/app/webroot/files/userfiles/files/zejedanilesukef.pdf
- https://xulynuocphangiathinh.vn/images/pic/file/86297286763.pdf
- https://www.smartfutureexpo.com/ckfinder/userfiles/files/36584126845.pdf
- https://technoarc.net/userfiles/file/fadewup.pdf
- http://mn-print.ru/ckfinder/userfiles/files/newapesunopiro.pdf
- https://bahia-group.com/ckfinder/userfiles/files/topogixuno.pdf
- https://soswzgierz.pl/web/uploads/files/josujabu.pdf
- http://napiarsaigh.com/images/89772290635.pdf
- https://gmnavarra.es/ckeditor/files/kunogozujafurevuxijejok.pdf
- http://minhanh.com/files/binezotutokivogazasiraje.pdf
- http://kindervakantieweekdeurne.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1616575337c35c---93806927018.pdf
- http://z-i-f.ru/userfiles/file/61307560688.pdf
- http://tjsyjdq.com/v15/Upload/file/2021107154334340.pdf
- http://limpiasol.com/wp-content/plugins/formcraft/file-upload/server/content/files/161487654e963b---67558501515.pdf
- http://3dprofi.net/images/uploads/file/zebaxerirudo.pdf
- http://open.ua/uploads/ckeditor/files/mofojonelew.pdf
- http://smenergy.kr/uploaded/file/48103610615c1815d8bc6.pdf
- http://fge-service.com/userfiles/file/dijodotigowawomeropiloxix.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- aumnat2car.com
- 3duct.com
- conhantaoankhanh.com
- nhatrangpalacehotel.com
- fermuar.com
- www.smartfutureexpo.com
- technoarc.net
- mn-print.ru
- bahia-group.com
- soswzgierz.pl
- napiarsaigh.com
- gmnavarra.es
- minhanh.com
- kindervakantieweekdeurne.nl
- z-i-f.ru
- tjsyjdq.com
- limpiasol.com
- 3dprofi.net
- open.ua
- smenergy.kr
- fge-service.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- Z:\v@h
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report