MALICIOUS — accbbf41fec0f9fa0286db98d61ab5d053fa766c17b01ec38324fb3553e917ff
MALICIOUS — accbbf41fec0f9fa0286db98d61ab5d053fa766c17b01ec38324fb3553e917ff is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
accbbf41fec0f9fa0286db98d61ab5d053fa766c17b01ec38324fb3553e917ff - SHA-1:
88df3d828ddcb4a90ed74f75977057e312f61303 - MD5:
d440bfd2fe27995d4bcc9d1d3007abe7 - ssdeep:
1536:igLjS1IdI5cHDJeEZPOao5sMUuTWW1kImskwu9HeK+74kCWIWUpO7qWozBGJI9uw:dKrqDZO5sMUuTd1k3sTYJo0Wr7ezBSct - TLSH:
T1CD37CFF3226BCD0C339B9B0369BB2155508AD74C21B2EFD00088B7BDD6689BDBE10911 - Submitted as: accbbf41fec0f9fa0286db98d61ab5d053fa766c17b01ec38324fb3553e917ff
- File type: pdf · Size: 73433 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://foulardfotografando.it/file/25191467417.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://matchedtubes.de/userfiles/file/tuvikatemoxowaboza.pdf, http://rsentco.com/upload/file/fenuzose.pdf, http://architectureanddesign.it/userfiles/files/70551076927.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/3CAf4wW3hvY/uplcv?utm_term=s+pass+and+work+permit
- http://matchedtubes.de/userfiles/file/tuvikatemoxowaboza.pdf
- http://rsentco.com/upload/file/fenuzose.pdf
- http://architectureanddesign.it/userfiles/files/70551076927.pdf
- http://a2kat.ru/userfiles/file/52808069354.pdf
- http://cn-polylysine.com/d/files/lalulu.pdf
- http://balletpanov.com/uploads/files/39776442542.pdf
- https://horgaszvelem.hu/ckfinder/userfiles/files/41461746200.pdf
- https://foulardfotografando.it/file/25191467417.pdf
- https://dobre-akce.cz/media/files/file/zosibovizojorumif.pdf
- http://perksys.com/userfiles/file/ruxokotizemezavajo.pdf
- https://jasz-pap.hu/UserFiles/file/41301366280.pdf
- https://seikai.jp/free_images/files/26994791334.pdf
- https://sfeerweter.nl/userfiles/files/14805967342.pdf
- https://hopclickhospitality.com/scgtest/team-explore/uploads/files/77980764656.pdf
- https://stefandes.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614dfb9296012---bidezuwerupodubu.pdf
- http://www.biharikft.hu/bihari-admin/ckfinder/userfiles/files/33241029059.pdf
- http://www.kliningstroy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1615834b7ae248---36713401571.pdf
- https://lasanisports.com/files/29868114377.pdf
- https://successalpha.team/upload/files/zotigonumap.pdf
- http://lachina.cn/upload/file/174212229.pdf
- http://easytravel63.ru/ckfinder/userfiles/files/dadavu.pdf
- https://art-eria.pl/mandarynka/pliki/files/15397662385.pdf
- http://avsa.org/sites/default/files/images/files/10097696100.pdf
- http://vektor-bezpeki.com/userfiles/files/supibibedi.pdf
Embedded domains
- feedproxy.google.com
- matchedtubes.de
- rsentco.com
- architectureanddesign.it
- a2kat.ru
- cn-polylysine.com
- balletpanov.com
- foulardfotografando.it
- perksys.com
- seikai.jp
- sfeerweter.nl
- hopclickhospitality.com
- stefandes.com
- www.kliningstroy.ru
- lasanisports.com
- lachina.cn
- easytravel63.ru
- art-eria.pl
- avsa.org
- vektor-bezpeki.com
- www.w3.org
- purl.org
- ns.adobe.com
- horgaszvelem.hu
- dobre-akce.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report