MALICIOUS — a744d0ec0229c93f45d5b32a4a3d548b22cb0743909bef43056624dbb9fd010c
MALICIOUS — a744d0ec0229c93f45d5b32a4a3d548b22cb0743909bef43056624dbb9fd010c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a744d0ec0229c93f45d5b32a4a3d548b22cb0743909bef43056624dbb9fd010c - SHA-1:
59f6e9d31d34eafee08643b302fdc6402546afe4 - MD5:
50b19b33396af2b8d0d644ad6eb46e9a - ssdeep:
1536:aluqAXvgwfCnaRrc6zinkmf4cJpvlRehWKRq6znenQCvH2cWBQvJNr/DAGs4iWAx:fR/g6EaC6z8kzcPlcAKRq6akWJp/DABx - TLSH:
T14438C0F3615BDE4C778ACB0369FB12B8604AD3985171DDA001C8BA7C957C9BDBE10A60 - Submitted as: a744d0ec0229c93f45d5b32a4a3d548b22cb0743909bef43056624dbb9fd010c
- File type: pdf · Size: 80066 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://rjbmachinery.com/d/files/60850311144.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://allytemp.ru/uplcv?utm_term=label+nonfiction+text+features, https://securitydm.com/slicice/file/menuzaj.pdf, http://rjbmachinery.com/d/files/60850311144.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://allytemp.ru/uplcv?utm_term=label+nonfiction+text+features
- https://securitydm.com/slicice/file/menuzaj.pdf
- http://rjbmachinery.com/d/files/60850311144.pdf
- http://cafehinglung.com/uploads/files/67712910021.pdf
- http://namngonviet.vn/user-/files/69759719214.pdf
- http://studioagm.it/userfiles/files/58168168163.pdf
- http://www.trimbleexpress.sk/wp-content/plugins/formcraft/file-upload/server/content/files/1613bd32c027c0---sifamif.pdf
- http://megaprestige.ru/uploads/files/91927117969.pdf
- http://theprojectmanagement.guru/cote_dor_import/admin/ckfinder/userfiles/files/77131828937.pdf
- http://zehanbiopharma.com/upload/files/muxejujunenebenogod.pdf
- http://www.tecnologycenter.com/admin/uploaded/fck/file/purefamorajenes.pdf
- http://denda.co.kr/ckfinder/userfiles/files/kukunoniredaximat.pdf
- http://reklama-v-sochi.com/ckfinder/userfiles/files/44075975257.pdf
- https://www.savininkai.lt/ckfinder/userfiles/files/74205297376.pdf
- https://songhong-thudo.com/img/files/69628299148.pdf
- http://studiotecnicobonoli.com/userfiles/files/63149900567.pdf
- https://driftwoodcc.com/userfiles/files/58600173892.pdf
- https://mytalk7.com/_UploadFile/Images/file/bikovi.pdf
- https://aluminiosarla.com/userfiles_arla/files/dodobukekirukilejazivupu.pdf
- http://sedaciesupravy.sk/media/file/51308017552.pdf
- https://liur-krd.ru/userfiles/file/pigar.pdf
- http://rnralpha.cz/res/file/94762829159.pdf
- http://quaint-house.com/images/blog/file/rajofojofofolig.pdf
- https://viettrungson.com/media/Files/tekumudabo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- allytemp.ru
- securitydm.com
- rjbmachinery.com
- cafehinglung.com
- studioagm.it
- megaprestige.ru
- zehanbiopharma.com
- www.tecnologycenter.com
- denda.co.kr
- reklama-v-sochi.com
- songhong-thudo.com
- studiotecnicobonoli.com
- driftwoodcc.com
- mytalk7.com
- aluminiosarla.com
- liur-krd.ru
- quaint-house.com
- viettrungson.com
- www.w3.org
- purl.org
- ns.adobe.com
- namngonviet.vn
- www.trimbleexpress.sk
- theprojectmanagement.guru
- www.savininkai.lt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report