MALICIOUS — a2f6a32f522e0e465cc2cfd5b8fe27dcb2cbf08ace55ea5c80d2811853d0c768
MALICIOUS — a2f6a32f522e0e465cc2cfd5b8fe27dcb2cbf08ace55ea5c80d2811853d0c768 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a2f6a32f522e0e465cc2cfd5b8fe27dcb2cbf08ace55ea5c80d2811853d0c768 - SHA-1:
e2a4e0668ad279c3c0d26bd93a75a64d0023509c - MD5:
bf31125d161d8c5e19a265a53f6c048a - ssdeep:
1536:ZlkZ3J8b/xzF4qGP/g7umu/rr7vxSLbN/ShUAWzGOz5HtiZLWApO6lOs:kZ58hFGH0uR/rr7JibFoUiUTCa6r - TLSH:
T1B438CFF320C7CD4CB68B5B037DF715AC608AD3885A22EA905488BB7CD57C9AD7E14A01 - Submitted as: a2f6a32f522e0e465cc2cfd5b8fe27dcb2cbf08ace55ea5c80d2811853d0c768
- File type: pdf · Size: 78725 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://lightningriskassessment.com/ci/userfiles/files/98937099820.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://fitness-base.tw/uploads/files/202109281905374943.pdf, https://www.darrellstuckey.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613eaa7844538---22923476467.pdf, http://jenan.com/ckfinder/userfiles/files/71385931656.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BvfzZFkJO3s/uplcv?utm_term=wright+this+down
- https://fitness-base.tw/uploads/files/202109281905374943.pdf
- https://www.darrellstuckey.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613eaa7844538---22923476467.pdf
- http://jenan.com/ckfinder/userfiles/files/71385931656.pdf
- http://lightningriskassessment.com/ci/userfiles/files/98937099820.pdf
- https://monarchwinemerchants.com/wp-content/plugins/super-forms/uploads/php/files/6a64392183166a244d89aa31ffcd6bc7/xebirifad.pdf
- https://eurosan.pl/user_images/file/88938228013.pdf
- https://holocaustresearch.pl/nowy/photo/file/zeriziribuku.pdf
- https://www.kiteschule-eckernfoerde.de/wp-content/plugins/formcraft/file-upload/server/content/files/1614f38a81f809---66515440126.pdf
- https://hopefor.today/wp-content/plugins/super-forms/uploads/php/files/2e1012cd5e16d11cd55802db64a498d3/ferexotona.pdf
- https://lederstuhlshop.de/ckfinder/userfiles/files/jozumiduwapopaz.pdf
- http://macierz-grodziec.org/files/file/23958370253.pdf
- https://www.jdconstinc.com/ckfinder/userfiles/files/bupujemeromuses.pdf
- https://indiachristian.org/uploads/files/29991580565.pdf
- https://casaalu.com/luutru/files/19649368555.pdf
- http://ashioke.com/images/library/File/lavuvenosedegubu.pdf
- https://ecableapp.com/FCKeditor/FCKimgUpload/file/56858123905.pdf
- http://domgr11.ru/uploads/files/55219769629.pdf
- http://www.hydro-tg.pro/upload/file/49660082380.pdf
- https://ceral.pl/ceral/pliki/file/67183600347.pdf
- https://tenekedjieva.com/uploads/file/padex.pdf
- http://akgdsgfly.pretty-match.com/upload/files/vusuvevolisutan.pdf
- http://stroynerud-sm.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1615954cc2cab1---zorij.pdf
- https://godahoian.com/app/webroot/upload/files/jitulapanaxitipeli.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- fitness-base.tw
- www.darrellstuckey.com
- jenan.com
- lightningriskassessment.com
- monarchwinemerchants.com
- eurosan.pl
- holocaustresearch.pl
- www.kiteschule-eckernfoerde.de
- hopefor.today
- lederstuhlshop.de
- macierz-grodziec.org
- www.jdconstinc.com
- indiachristian.org
- casaalu.com
- ashioke.com
- ecableapp.com
- domgr11.ru
- www.hydro-tg.pro
- ceral.pl
- tenekedjieva.com
- akgdsgfly.pretty-match.com
- stroynerud-sm.ru
- godahoian.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report