MALICIOUS — ad68bedbaed787d5c8712872e23d9ecffee5ff3086f798f113837e33c727811d
MALICIOUS — ad68bedbaed787d5c8712872e23d9ecffee5ff3086f798f113837e33c727811d is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ad68bedbaed787d5c8712872e23d9ecffee5ff3086f798f113837e33c727811d - SHA-1:
c5d99e632fa47c1e414e95deddae9365200f5a43 - MD5:
f4477077c363eca03875b464cc60e63e - ssdeep:
1536:eCaB/Vhkt3PHWOVgLIPt2WXpOObdasjf5T0wo2ZWbpOND:lOkoOVgLIPtHOujlTjo2bND - TLSH:
T13236DFF720478E4CB68F9F42776A269C644FC7DC7191E9A0808C7668D15C8BEBC61B11 - Submitted as: ad68bedbaed787d5c8712872e23d9ecffee5ff3086f798f113837e33c727811d
- File type: pdf · Size: 66661 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://romangruszecki.com/uploaded/file/sigivenapananuraka.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://romangruszecki.com/uploaded/file/sigivenapananuraka.pdf, http://studionegro.net/userfiles/files/kujapobeluga.pdf, http://discarga.com/wp-content/plugins/formcraft/file-upload/server/content/files/161534f21bcb13---60178624520.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/BvfzZFkJO3s/uplcv?utm_term=idle+restaurant+tycoon+mod
- http://romangruszecki.com/uploaded/file/sigivenapananuraka.pdf
- http://studionegro.net/userfiles/files/kujapobeluga.pdf
- http://discarga.com/wp-content/plugins/formcraft/file-upload/server/content/files/161534f21bcb13---60178624520.pdf
- https://mediaskills.rs/files/fazorabawi.pdf
- http://ventmetal.ru/userfiles/files/luzanoxoruj.pdf
- https://landlorddebtadvisory.com/wp-content/plugins/super-forms/uploads/php/files/60f0e17ef3c354a83c71d2dcb92eb28c/20590183107.pdf
- http://broadgatecapital.com/userfiles/file/78783448827.pdf
- https://www.loscam.com/lib_common/ckeditor/ckfinder/userfiles/files/87355431973.pdf
- https://h1t-url12shio-turbo.com/contents/files/nipewelizonak.pdf
- http://servis-hradec.cz/files/file/7484831067.pdf
- http://positiveforce.in/uploads/files/degagulilawel.pdf
- http://vankouwenenmastop.nl/UserFiles/file/58783031088.pdf
- http://airmon.hu/images/files/6454718753.pdf
- https://dragonexpressml.apnaconsultant.com/userfiles/files/94988469035.pdf
- http://vattucongtrinh.com/userfiles/file/33939845322.pdf
Embedded domains
- feedproxy.google.com
- romangruszecki.com
- studionegro.net
- discarga.com
- ventmetal.ru
- landlorddebtadvisory.com
- broadgatecapital.com
- www.loscam.com
- h1t-url12shio-turbo.com
- positiveforce.in
- vankouwenenmastop.nl
- dragonexpressml.apnaconsultant.com
- vattucongtrinh.com
- mediaskills.rs
- servis-hradec.cz
- airmon.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report