MALICIOUS — a00f66221d28e2136217197382efeee435c6fdcf81818554dbd8dc83f87a4e58
MALICIOUS — a00f66221d28e2136217197382efeee435c6fdcf81818554dbd8dc83f87a4e58 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a00f66221d28e2136217197382efeee435c6fdcf81818554dbd8dc83f87a4e58 - SHA-1:
22e9ac0a8af3f28316eee60e42ba6557cef1c87e - MD5:
974939b54c5cba37096c66a997633ad7 - ssdeep:
1536:8VCOhTTmsTLphPxZc1spwBrx2RiMovWT:4TTffphDc1spwF6oi - TLSH:
T19D36E0F380A7CE1CFADB5F469EAB32FD4849D34996B5DB210148676981EC8EE7910402 - Submitted as: a00f66221d28e2136217197382efeee435c6fdcf81818554dbd8dc83f87a4e58
- File type: pdf · Size: 63830 bytes
- Verdict: malicious (94/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://gramercy-grand.ru/files/file/72613370595.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://queure.ru/uplcv?utm_term=accept+credit+cards+on+smartphone, http://sirinthepgroup.com/userfiles/file/wumarobaxedixudatogu.pdf, http://taigesw.com/upload/files/voluwoluze.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://queure.ru/uplcv?utm_term=accept+credit+cards+on+smartphone
- http://sirinthepgroup.com/userfiles/file/wumarobaxedixudatogu.pdf
- http://taigesw.com/upload/files/voluwoluze.pdf
- http://gramercy-grand.ru/files/file/72613370595.pdf
- http://opakowania-loga.pl/zdjecia/fotki/file/sipitopizanamabezu.pdf
- http://hmconcretemixingplant.ru/d/files/50910652791.pdf
- http://tsg-vaganovskoe.ru/ckfinder/userfiles/files/44719948885.pdf
- https://amoslodge10-org.alljobsinliberia.com/ckfinder/userfiles/files/51661718215.pdf
- https://mihalex.by/files/files/51335895590.pdf
- https://yastudio.net/wp-content/plugins/super-forms/uploads/php/files/e2d8d019558820ecd2aa8596ee0cdad3/gitaveri.pdf
- http://rdasesores.gestconcursal.com/editor/ckfinder/userfiles/files/45782816306.pdf
- https://pioneerlift.com/upfiles/editor/files/87594473014.pdf
- https://bakotech.at/uploads/ckeditor/files/58739743942.pdf
- http://zovsh.com/Uploadfiles/files/fesazisefepikuniwonedimo.pdf
- https://smshealthcareservices.com/ckfinder/userfiles/files/dolosulekados.pdf
- http://nhuaduongnhapkhauaz.org/upload/files/sofaladutuvide.pdf
- https://12shio3.com/contents/files/lupibakamogiwitulisojase.pdf
- http://strategie-online.net/catalogue_dynamique/file/sikozofebeg.pdf
- https://mayxaydungthienlong.com/uploads/files/files/vofimiropusa.pdf
- https://yarpaket.ru/userfiles/file/51811355422.pdf
- http://imosa.asia/uploads/files/202109180346531177.pdf
- https://gedayapi.com/userfiles/file/19000935708.pdf
- https://brakos.it/file/moborujuzetipunili.pdf
Embedded domains
- queure.ru
- sirinthepgroup.com
- taigesw.com
- gramercy-grand.ru
- opakowania-loga.pl
- hmconcretemixingplant.ru
- tsg-vaganovskoe.ru
- amoslodge10-org.alljobsinliberia.com
- yastudio.net
- rdasesores.gestconcursal.com
- pioneerlift.com
- zovsh.com
- smshealthcareservices.com
- nhuaduongnhapkhauaz.org
- 12shio3.com
- strategie-online.net
- mayxaydungthienlong.com
- yarpaket.ru
- imosa.asia
- gedayapi.com
- brakos.it
- mihalex.by
- bakotech.at
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report