MALICIOUS — a5e66afe035dc70a85362bc67d33e0f54bd70de658e0375b1ff958cec16567c4
MALICIOUS — a5e66afe035dc70a85362bc67d33e0f54bd70de658e0375b1ff958cec16567c4 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a5e66afe035dc70a85362bc67d33e0f54bd70de658e0375b1ff958cec16567c4 - SHA-1:
23a6abd0d2992ae587472731f087a792881440ba - MD5:
dfffe381df9ae78a014fd90d6fbfd076 - ssdeep:
1536:Ry/r0rrt6mr/kGi1YbpdTwVMsfxv6YsW9LsSxjdoAcWQpOCoiWNS5:jdVr/4STEXZv2SxpoAbCohu - TLSH:
T13039D0F300EBED5C3787DB0379BB51A83499D68432A2EA11504CBB9CD5BC5BDAE00961 - Submitted as: a5e66afe035dc70a85362bc67d33e0f54bd70de658e0375b1ff958cec16567c4
- File type: pdf · Size: 91616 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.justgiveahand.org/wp-content/plugins/formcraft/file-upload/server/content/files/160aa9ad051989---58897269798.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=how+to+change+netflix+login+on+roku, https://limpjet.com.br/wp-content/plugins/super-forms/uploads/php/files/6e5b5f3d98fdd701a749a8da5a333d95/31656998612.pdf, http://articolo17.it/siti//usr/foto/files/mupotagodub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=how+to+change+netflix+login+on+roku
- https://limpjet.com.br/wp-content/plugins/super-forms/uploads/php/files/6e5b5f3d98fdd701a749a8da5a333d95/31656998612.pdf
- http://articolo17.it/siti//usr/foto/files/mupotagodub.pdf
- http://blankheich.de/images/uploads/file/28148573153.pdf
- http://www.justgiveahand.org/wp-content/plugins/formcraft/file-upload/server/content/files/160aa9ad051989---58897269798.pdf
- https://m-co.de/wp-content/plugins/super-forms/uploads/php/files/3aiq8ocde3bn0ocvtq9ntshvom/97189278799.pdf
- https://www.hausbootgeiseltalsee.de/wp-content/plugins/super-forms/uploads/php/files/tjth4k0ga2c6i836sn0pgg7igu/mezogozagazotaz.pdf
- http://takeacode.eu/user/d41d8cd98f00b204e9800998ecf8427e/file/49116060089.pdf
- http://xn--22cjbbm2eyae3ehabdb4kqdtae3dxnnc1fhf.com/user_img/files/wufilizuvogobuv.pdf
- http://irmascaritasdejesus.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/160a1b2ca0c723---nemevomirexaz.pdf
- https://mauspro.net/upload/files/49654956140.pdf
- http://iwish-cosmetics.com/wp-content/plugins/formcraft/file-upload/server/content/files/16083ae5b5f8d0---82153610160.pdf
- http://fine-cottage.ru/userfiles/files/99384937359.pdf
- http://willtorock.com/wp-content/plugins/formcraft/file-upload/server/content/files/160849189e0925---83581155113.pdf
- http://shinserviceodi.ru/wp-content/plugins/super-forms/uploads/php/files/9d36b5b0cfa4e5e42273f28c251a8a09/vivamolunewun.pdf
- http://midiabyz.com/wp-content/plugins/super-forms/uploads/php/files/4a5a89c21e0bd4936f702c2c4454ff4c/guzujemegiwakunatod.pdf
- http://staractivecollection.com/resimler/site/files/gokinifusurikovu.pdf
- https://birgatour.mn/js/ckfinder/userfiles/files/velizasanibosev.pdf
- https://alamansyria.com/userfiles/file/89365377860.pdf
- https://mintedimages.com/ckfinder/userfiles/files/17332310116.pdf
- http://italiancousins.net/clients/5/54/54f3d33123424807706abe9154268524/File/56844938909.pdf
- https://ecomassage.pt/wp-content/plugins/super-forms/uploads/php/files/334rak5bgcdtb6hmh8ksd9374o/redabopa.pdf
- https://amagi.la/wp-content/plugins/formcraft/file-upload/server/content/files/160da1f651d0c9---53798136747.pdf
- https://estidevelopers.com/wp-content/plugins/super-forms/uploads/php/files/a5a70a79197b40ebda4f989fe2fd1e53/xinimumi.pdf
- https://xetnghiemadndanang.com/upload/userfiles/files/jalovoziku.pdf
Embedded domains
- huntic.ru
- limpjet.com.br
- articolo17.it
- blankheich.de
- www.justgiveahand.org
- m-co.de
- www.hausbootgeiseltalsee.de
- takeacode.eu
- xn--22cjbbm2eyae3ehabdb4kqdtae3dxnnc1fhf.com
- irmascaritasdejesus.org.br
- mauspro.net
- iwish-cosmetics.com
- fine-cottage.ru
- willtorock.com
- shinserviceodi.ru
- midiabyz.com
- staractivecollection.com
- alamansyria.com
- mintedimages.com
- italiancousins.net
- estidevelopers.com
- xetnghiemadndanang.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report