MALICIOUS — 952f22f568484ef67c202324cec496f6feee7a59eabbc2143f852c0f66d20b75
MALICIOUS — 952f22f568484ef67c202324cec496f6feee7a59eabbc2143f852c0f66d20b75 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
952f22f568484ef67c202324cec496f6feee7a59eabbc2143f852c0f66d20b75 - SHA-1:
1b7f306fdaef56d12d4d61385edded0f03fe7bc8 - MD5:
e834fc2dbb3f669ce0953f23337a7cd6 - ssdeep:
1536:1nUM5Siqn6Y2Z9SKuQ1gMdmSQldNRWwx3erXErKWK22sZ/UGcRfyqIfAUWcpOmR5:95J82Z9gKmSQldNRxx3egr0HsyRfc4/y - TLSH:
T16D38C0F3108BDD8C7A8B9F435DA752486089D6C86672EBA05088B76CD5BC87DFF10542 - Submitted as: 952f22f568484ef67c202324cec496f6feee7a59eabbc2143f852c0f66d20b75
- File type: pdf · Size: 83188 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://cesishotel.com/res/wysiwyg/file/57126096356.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://inwebjor.ru/uplcv?utm_term=skate+it+apk, http://cukorbetegshop.hu/files/tifuwudefowapevimanolepo.pdf, http://huyminhplastic.com/upload/files/86485743456.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://inwebjor.ru/uplcv?utm_term=skate+it+apk
- http://cukorbetegshop.hu/files/tifuwudefowapevimanolepo.pdf
- http://huyminhplastic.com/upload/files/86485743456.pdf
- https://damsindia.org/admin/uploads/file/87397165595.pdf
- http://www.vljainandco.com/userfiles/files/18173169116.pdf
- https://bravo-hk.com/userfiles/file/21987292727.pdf
- http://www.tecnologycenter.com/admin/uploaded/fck/file/somuwuzusekilemelewegide.pdf
- http://cesishotel.com/res/wysiwyg/file/57126096356.pdf
- http://kronospan-mofa-hungary.hu/editor_up/51686280835.pdf
- http://321eastern-thailand.com/userfiles/files/54294523306.pdf
- http://bjbtrh.com/files/pic/file/32207473591.pdf
- http://dabaizhongxue.com/upload_fck/file/2021-9-7/20210907164612473831.pdf
- http://linhkienhunganh.vn/luutru/files/zagofidaku.pdf
- http://test.uebersetzungen-nesselberger.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613bb0e2e547d---negerizarijuwuf.pdf
- http://www.fsnn.se/wp-content/plugins/formcraft/file-upload/server/content/files/16144ab548664d---vafipugumijexijiwupi.pdf
- http://gjbbang.com/userData/board/file/dopoxidejet.pdf
- https://clarkfamilybuilders.com/home/clark/public_html/ckfinder/userfiles/files/nirudiwif.pdf
- http://biplano.eu/userfiles/files/82371056438.pdf
- http://bacsiha.com/public/ckfinder/userfiles/files/towaxezamimukodetukefozaf.pdf
- http://www.jokilaaksonratsastajat.fi/file/91607000656.pdf
- https://refakatci.net/userfiles/file/27195265837.pdf
- http://nowyhotelik.pl/userfiles/file/pejorafujo.pdf
- https://techinnsrl.com/writable/public/userfiles/file/kamewujo.pdf
- http://fishngrill.iorderfoods.com/uploads/files/fipejizojozu.pdf
- https://htcpost.vn/vietpost.vn/img_content/file/segukag.pdf
Embedded domains
- inwebjor.ru
- huyminhplastic.com
- damsindia.org
- www.vljainandco.com
- bravo-hk.com
- www.tecnologycenter.com
- cesishotel.com
- 321eastern-thailand.com
- bjbtrh.com
- dabaizhongxue.com
- test.uebersetzungen-nesselberger.de
- www.fsnn.se
- gjbbang.com
- clarkfamilybuilders.com
- biplano.eu
- bacsiha.com
- www.jokilaaksonratsastajat.fi
- refakatci.net
- nowyhotelik.pl
- techinnsrl.com
- fishngrill.iorderfoods.com
- www.w3.org
- purl.org
- ns.adobe.com
- cukorbetegshop.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report