MALICIOUS — 9abfe834005b7e55af439e19404e36cdd380e7ef09344e855d421a2c64cbb9e2
MALICIOUS — 9abfe834005b7e55af439e19404e36cdd380e7ef09344e855d421a2c64cbb9e2 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9abfe834005b7e55af439e19404e36cdd380e7ef09344e855d421a2c64cbb9e2 - SHA-1:
e3c2e0f9545da621d93c2d0dd8d23d237e0ec515 - MD5:
4913fbfeaea2859fcbc0dba4e4ff6211 - ssdeep:
1536:nHhr5ZtGwI4nY0E5EpcAPx+8O6ASWNL5pX0iLo8WqNYLW8pO7+9c:B7pnfE5Eeb8O5Lj0qo8W0YW7V - TLSH:
T1CD37C0F320E7DD8CB78AAB43A8B611E9B147E7886372DB50548C7A5C807C97D7E18910 - Submitted as: 9abfe834005b7e55af439e19404e36cdd380e7ef09344e855d421a2c64cbb9e2
- File type: pdf · Size: 74050 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/32270be40ce26ba37568661cf0877cb1/nanunijitaxepijesopakojip.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://chcial.ru/uplcv?utm_term=unity+muzzle+flash+particle+download+free, https://grahampropertytax.com/wp-content/plugins/super-forms/uploads/php/files/54d5ebf05abbafca6c752674b6b31a8c/newidaf.pdf, http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/32270be40ce26ba37568661cf0877cb1/nanunijitaxepijesopakojip.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://chcial.ru/uplcv?utm_term=unity+muzzle+flash+particle+download+free
- https://grahampropertytax.com/wp-content/plugins/super-forms/uploads/php/files/54d5ebf05abbafca6c752674b6b31a8c/newidaf.pdf
- http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/32270be40ce26ba37568661cf0877cb1/nanunijitaxepijesopakojip.pdf
- http://bhavalaya.org/ckfinder/userfiles/files/23341709393.pdf
- http://thm-holding.ru/wp-content/plugins/super-forms/uploads/php/files/a25d845794a05816cbf9aeeef0432be7/mozajobujedirawekizonuwip.pdf
- http://jocoseatee.com/userfiles/files/68419857828.pdf
- http://andrenickels.de/ckfinder/userfiles/files/44237072885.pdf
- http://nrgmedia.hu/files/file/8972785658.pdf
- http://fairfresh.net/assets/admin/ckeditorimage/files/48952248931.pdf
- https://vnnc.vn/img-hdmedia/files/wazefunotanifuledoz.pdf
- http://gpmpoolandspa.com/ckfinder/userfiles/files/mebafuguwemafuparafaroj.pdf
- http://vntattoosupply.net/uploads/image/files/72018340804.pdf
- http://guides2alpes.fr/uploads/file/wajizenijujonufib.pdf
- https://sushixusa.com/userfiles/files/ledokemezi.pdf
- http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/a8647baafd6dd593d536a3192f723e70/kedodoxadorob.pdf
- http://labuchedeberce.fr/userfiles/file/xoduvedakitozikebogip.pdf
- http://stevis.cz/files/file/dabemugur.pdf
- http://mlight.cz/archiv/file/watokezik.pdf
- http://amongelite.com/ci/userfiles/files/84241385803.pdf
- http://csc028.com/userfiles/file/20211002221709_74i61l.pdf
- https://verticala.ro/images/userfiles/97596399962.pdf
- https://efficimm.fr/userfiles/files/juminolikimu.pdf
- https://adlinefor.com/home/webagen/public_html/korn/data/file/96889833115.pdf
- https://helicopterleasingservices.com/userfiles/files/fewukoligowedelapap.pdf
- http://mingzhicc.com/userfiles/files/94318458600.pdf
Embedded domains
- chcial.ru
- grahampropertytax.com
- chagatea.ru
- bhavalaya.org
- thm-holding.ru
- jocoseatee.com
- andrenickels.de
- fairfresh.net
- gpmpoolandspa.com
- vntattoosupply.net
- guides2alpes.fr
- sushixusa.com
- asirius.su
- labuchedeberce.fr
- amongelite.com
- csc028.com
- efficimm.fr
- adlinefor.com
- helicopterleasingservices.com
- mingzhicc.com
- www.iso-clean.fr
- www.w3.org
- purl.org
- ns.adobe.com
- nrgmedia.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report