MALICIOUS — 9ddf4c10ee8bcd60bb31e136875cb3ea7d3b2509e8349b7778507fc79c0ae48b
MALICIOUS — 9ddf4c10ee8bcd60bb31e136875cb3ea7d3b2509e8349b7778507fc79c0ae48b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9ddf4c10ee8bcd60bb31e136875cb3ea7d3b2509e8349b7778507fc79c0ae48b - SHA-1:
e5359466e49249b59896e5075da74118082211ec - MD5:
cd658059518b8305c78e305ce7013891 - ssdeep:
3072:KlbHa4Uc6JxwFv0H56fw5xYgtuUY0lJseFd8:YbxB6JxwC8mtLY0lJk - TLSH:
T11D3CF1E724CBDE1C7A475B46AEDA02B8C69AE34495E3E3A041CC132580FCDAE7E505C1 - Submitted as: 9ddf4c10ee8bcd60bb31e136875cb3ea7d3b2509e8349b7778507fc79c0ae48b
- File type: pdf · Size: 120927 bytes
- Verdict: malicious (96/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://dawahcity.com/userfiles/file/jejidudaruxemurikaba.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://loaamtran.vn/files/usersfiles/files/suzobozib.pdf, http://elsekmont.eu/userfiles/file/mekupevorejodobemu.pdf, http://zuche0551.com/upload/file/simakamenugor.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/Xvkpad/~3/1hHberoKktI/uplcv?utm_term=how+to+make+a+secret+door+behind+a+painting+in+minecraft
- http://loaamtran.vn/files/usersfiles/files/suzobozib.pdf
- http://elsekmont.eu/userfiles/file/mekupevorejodobemu.pdf
- http://zuche0551.com/upload/file/simakamenugor.pdf
- https://tekstilkentrehber.com/upload/ckfinder/files/12687433051.pdf
- http://aluminial.pnh.pt/js/ckfinder/userfiles/files/71633366837.pdf
- http://topstec.com/d/files/70803685887.pdf
- http://www.cargeacrew.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16161ef633e5c4---58197610412.pdf
- https://dsodrecital.com/wp-content/plugins/formcraft/file-upload/server/content/files/16164a65fe06ec---37679542172.pdf
- http://dawahcity.com/userfiles/file/jejidudaruxemurikaba.pdf
- http://www.rsvpcatering-ar.com/files/imagesfile/banefevosazujawutasajenor.pdf
- http://hyundaiokla.com/uploads/files/99913888568.pdf
- http://meijialx.com/ckfinder/userfiles/files/6082281380.pdf
- https://saikekanglun.com/filespath/files/20210905122139.pdf
- https://communeouchamps.fr/userfiles/file/xunonevubuxu.pdf
- http://ktcz.eu/files/files/99614129201.pdf
- http://glbrsciencefair.sfiab.com/data/userfiles/file/fonipeku.pdf
- http://sh8ke.com/wp-content/plugins/formcraft/file-upload/server/content/files/16134a4d7b9204---37196599538.pdf
- https://barcelonacentromedico.es/files/galeria/files/60035866271.pdf
- http://shipsupply.ru/userfiles/files/1369969406.pdf
- http://pphu-joanna.pl/fckpliki/file/rusubukudagudi.pdf
- http://cassotech.nl/site/data/ws/files/27241960038.pdf
- http://www.morrisjones.co.uk/EditorImages/file/pomotamunukanudesof.pdf
- http://protok.pro/upload/files/83063632202.pdf
- http://samnakthodrahassob.com/userfiles/file/22274218893.pdf
Embedded domains
- feedproxy.google.com
- elsekmont.eu
- zuche0551.com
- tekstilkentrehber.com
- topstec.com
- www.cargeacrew.com.br
- dsodrecital.com
- dawahcity.com
- www.rsvpcatering-ar.com
- hyundaiokla.com
- meijialx.com
- saikekanglun.com
- communeouchamps.fr
- ktcz.eu
- glbrsciencefair.sfiab.com
- sh8ke.com
- barcelonacentromedico.es
- shipsupply.ru
- pphu-joanna.pl
- cassotech.nl
- www.morrisjones.co.uk
- protok.pro
- samnakthodrahassob.com
- loaamtran.vn
- aluminial.pnh.pt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report