MALICIOUS — 9916e1405b5186fca658b5e83ff06d5141764fd85b6c4605195d49e9d8adfaab
MALICIOUS — 9916e1405b5186fca658b5e83ff06d5141764fd85b6c4605195d49e9d8adfaab is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9916e1405b5186fca658b5e83ff06d5141764fd85b6c4605195d49e9d8adfaab - SHA-1:
e54a1ca88e1282688c8cd84cee2a1e78b5d1d396 - MD5:
3c8e45f2dbbf3781e07a2caac10ac73b - ssdeep:
1536:vKzRhnqyYNfxYWKOgY8Hw6NgIOG3L8EaKZcrY6HBWXq85Cv:Aq1Nfx5LgXHwANnLLaGcrY485E - TLSH:
T1FD36C0F625BBED0C7D5F4B075DDB229ED58DE2488066C2612088A359E5BC6BF7E10D00 - Submitted as: 9916e1405b5186fca658b5e83ff06d5141764fd85b6c4605195d49e9d8adfaab
- File type: pdf · Size: 63832 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://e3edu.vn/public/ckfinder/core/connector/php/connector.phppublic/uploadsfiles/93341910761.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://ozkayalartrans.com/userfiles/file/26696965575.pdf, https://herfection.herfection.tw/upload/ckfinder_temp/files/20210907192708.pdf, https://granitabrasive.hu/editor_up/61926629626.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/A3Ryygt5BCM/uplcv?utm_term=burn+after+reading+full+movie+online
- http://ozkayalartrans.com/userfiles/file/26696965575.pdf
- https://herfection.herfection.tw/upload/ckfinder_temp/files/20210907192708.pdf
- https://granitabrasive.hu/editor_up/61926629626.pdf
- http://yves-segers.be/userfiles/files/60926439401.pdf
- http://brava-ekb.ru/userfiles/file/favojugibelad.pdf
- http://hkxhjfc.ltd/uploads/files/20210909012939.pdf
- http://av72-reklama.ru/userfiles/file/1632294973582a390cd323bef4bad0.pdf
- http://canadianartistic.com/userfiles/file/71628272127.pdf
- https://stakeoutllc.com/wp-content/plugins/super-forms/uploads/php/files/42cf2dac9734ccdccaba81ec1cc8746d/12619461720.pdf
- http://e3edu.vn/public/ckfinder/core/connector/php/connector.phppublic/uploadsfiles/93341910761.pdf
- https://beautifulhairstore.com/upload/files/31070741912.pdf
- http://assushop.com/userfiles/assushop.com/file/pisozuxik.pdf
- http://theelementrama9.com/userfiles/files/guwesewalamew.pdf
- http://sibleyestateplanning.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/49178279799.pdf
- https://cfi-registration.amyhalter.com/buzzboxgift/img/userfiles/files/refufakofitabikepitobe.pdf
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613feb2fb4fe0---46179032877.pdf
- http://raczcsalad.hu/files/58822198033.pdf
- https://jerseyshorepirates.com/userfiles/files/zanosaxukitamenipakufan.pdf
- http://stopasbestos.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1614c4fea723bf---3857553574.pdf
- http://itnetworkconsultingsf.com/helpdesk/app/webroot/img/userfiles/files/doseriwova.pdf
- https://www.avenueroadadvertising.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614ae4313e33a---zovulexobexebadozo.pdf
- http://tiwtactic.com/userfiles/files/48433396821.pdf
- http://lynxauto.ru/userfiles/file/43496339534.pdf
- https://pasationtravellers.com/root/FCKeditor/file/mutosaraxekaja.pdf
Embedded domains
- feedproxy.google.com
- ozkayalartrans.com
- herfection.herfection.tw
- yves-segers.be
- brava-ekb.ru
- av72-reklama.ru
- canadianartistic.com
- stakeoutllc.com
- beautifulhairstore.com
- assushop.com
- theelementrama9.com
- sibleyestateplanning.com
- cfi-registration.amyhalter.com
- kaufdeinauto.de
- jerseyshorepirates.com
- stopasbestos.ca
- itnetworkconsultingsf.com
- www.avenueroadadvertising.com
- tiwtactic.com
- lynxauto.ru
- pasationtravellers.com
- dd-eng.com
- deltools.com
- granitabrasive.hu
- hkxhjfc.ltd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report