MALICIOUS — 1608d86674549f---80798995569.pdf
MALICIOUS — 1608d86674549f---80798995569.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
946dfa749beaff909f2f88fcd3b5a0b4f5156a2f04b5150efdcfcab3a939b66e - SHA-1:
d05a346ea871f89cac541ae073e47c76e97eadbc - MD5:
e554f86d1f0067e57cc6561a89fd9408 - ssdeep:
1536:tfPtBwncliBgXMEAgjogJg2nZIfjUb6crnNgj++QAXR:J/N4g3Ag0IPZyjiJD4++VR - TLSH:
T1CD36CFF3A14BDE9C7FD62B036AA7042D244FC2843522D7A4849CBA7CC8B86ED3E14551 - Submitted as: 1608d86674549f---80798995569.pdf
- File type: pdf · Size: 69552 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!E554F86D1F00
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.kzhep.in.ua/wp-content/plugins/super-forms/uploads/php/files/1adp1kvc8udnlhks1svhgvno67/3353065854.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://www.kzhep.in.ua/wp-content/plugins/super-forms/uploads/php/files/1adp1kvc8udnlhks1svhgvno67/3353065854.pdf, https://chocoinmobiliario.com/wp-content/plugins/super-forms/uploads/php/files/2185b9aa7160c6488a2aa5803c9f7757/saledigugilotugol.pdf, https://fieldofgreen.com/wp-content/plugins/super-forms/uploads/php/files/7792e263f0bba5403a40b6d8f210f4b3/83256243950.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/cv9VXjIrmdE/uplcv?utm_term=powerpoint+business+model+canvas+template
- http://www.kzhep.in.ua/wp-content/plugins/super-forms/uploads/php/files/1adp1kvc8udnlhks1svhgvno67/3353065854.pdf
- https://chocoinmobiliario.com/wp-content/plugins/super-forms/uploads/php/files/2185b9aa7160c6488a2aa5803c9f7757/saledigugilotugol.pdf
- https://fieldofgreen.com/wp-content/plugins/super-forms/uploads/php/files/7792e263f0bba5403a40b6d8f210f4b3/83256243950.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/621bfhpetj9gfjkbtit5joirh0/57008413892.pdf
- http://www.zulfugar.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160700a63a2fb0---dulag.pdf
- https://sckstone.com/wp-content/plugins/super-forms/uploads/php/files/d60aa32469ad59d775cdc2e991ac6015/xijemupojajepamituf.pdf
- https://agribusiness.pk/wp-content/plugins/formcraft/file-upload/server/content/files/1607402fd67498---37739088047.pdf
- https://lsp.od.ua/wp-content/plugins/super-forms/uploads/php/files/g5utqlq7ffj79vtq1u396u7874/2210155651.pdf
- http://plenaadoracao.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160843206908e5---vegikin.pdf
- https://tkpmission.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608bdfc431ce9---jovudo.pdf
- http://cargo3030.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160762d57266fd---57972833954.pdf
- http://drstevealbrecht.com/wp-content/plugins/super-forms/uploads/php/files/45df53db03d1ae1eecd0bf632da8c8a5/20008890284.pdf
- https://readxyz.org/wp-content/plugins/super-forms/uploads/php/files/8382d03698e4f56c7ffaf5a97132063a/gipopugusowegavumubajovid.pdf
- https://www.abaco-engineering.it/wp-content/plugins/formcraft/file-upload/server/content/files/16084d43c4f19d---46290545968.pdf
- https://www.audifonosdoshoydos.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607f4fb740026---66086796397.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- www.kzhep.in.ua
- chocoinmobiliario.com
- fieldofgreen.com
- www.nuricomuvakfi.org
- www.zulfugar.nl
- sckstone.com
- lsp.od.ua
- plenaadoracao.com.br
- tkpmission.org
- cargo3030.ru
- drstevealbrecht.com
- readxyz.org
- www.abaco-engineering.it
- www.audifonosdoshoydos.com
- www.w3.org
- purl.org
- ns.adobe.com
- agribusiness.pk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report