MALICIOUS — af4aab085437cfc9a55636a333123c90bf55db3023006a5d4f3cb4d2f71bac10
MALICIOUS — af4aab085437cfc9a55636a333123c90bf55db3023006a5d4f3cb4d2f71bac10 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
af4aab085437cfc9a55636a333123c90bf55db3023006a5d4f3cb4d2f71bac10 - SHA-1:
246893983301560820040e3f1bbd0387b0710867 - MD5:
700b7ab92823902423f90897b53b1644 - ssdeep:
1536:K3UC/PfTVj00BYhxoU1M9IMqvGOsaOBYtMv8AvMjYegEpPsrwTWgjT+JPyiKTWAs:AU23TZ0WYHoU1M9IH+OsxBYMjegY4wAf - TLSH:
T1593AD0F3508BDD4C7B8BDF0325BB0658A04ADB9C6272E79051887F2D857C6BDAE50920 - Submitted as: af4aab085437cfc9a55636a333123c90bf55db3023006a5d4f3cb4d2f71bac10
- File type: pdf · Size: 97741 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://alkathirilaw.com/userfiles/files/nunovujakixukijimoniki.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://cathugo-yachts.de/res/wysiwyg/file/12633940169.pdf, https://martybermanassociates.com/wp-content/plugins/super-forms/uploads/php/files/2e7b87f36975db97fd8ef1e08b7ad5e2/24077724254.pdf, https://www.mercedesbenzofaustinservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b8f150d3ee---74798767369.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/ngfLrbzwjls/uplcv?utm_term=manual+de+homiletica+pdf
- http://cathugo-yachts.de/res/wysiwyg/file/12633940169.pdf
- https://martybermanassociates.com/wp-content/plugins/super-forms/uploads/php/files/2e7b87f36975db97fd8ef1e08b7ad5e2/24077724254.pdf
- https://www.mercedesbenzofaustinservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b8f150d3ee---74798767369.pdf
- http://longarmquiltacademy.com/fckeditor/userfiles/file/zejotubajonunasikakuze.pdf
- http://lnianemarzenie.pl/userfiles/file/xovasefagaxor.pdf
- https://www.weboonline.com/ckfinder/userfiles/files/ribijejumajazede.pdf
- https://papiratisk.cz/soubory/kovovapoxedut.pdf
- https://alkathirilaw.com/userfiles/files/nunovujakixukijimoniki.pdf
- https://beysukonaklari.com/ckfinder/userfiles/files/39449013870.pdf
- https://truonggiangcompany.com/userfiles/file/44167042938.pdf
- http://globalfeedindustry.com/upload/files/90915382157.pdf
- http://dragonera.cn/admin/userfiles/file/31523248251.pdf
- https://mygamedaysports.com/wp-content/plugins/super-forms/uploads/php/files/1ed99148b0ede5274aafbcbfe1aeaed7/79542823331.pdf
- http://ingpoggi.eu/userfiles/files/84378343902.pdf
- https://kachhiproperties.com/wp-content/plugins/super-forms/uploads/php/files/3np1i9o7jkc4c2g529ur0rorq4/lanimeturuxumuliwinuvubuj.pdf
- https://xpress2.eu/ckfinder/userfiles/files/71742998655.pdf
- https://www.golddustdental.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a4478653b61---doronigi.pdf
- http://nicenpos.com/userData/board/file/sagowapekapega.pdf
- https://bibonatura.com/ckfinder/userfiles/files/8136109820.pdf
- http://marinda.ru/pics/images/file/lemutexes.pdf
- http://alteredcompta.com/buddha/ckfinder/userfiles/files/23008011297.pdf
- https://rh-h1tapi-turbo.com/contents//files/71943739476.pdf
- https://gservicepz.com/wp-content/plugins/super-forms/uploads/php/files/b9c3d093e93d3ca3614bd70ec32c2246/26930313830.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- cathugo-yachts.de
- martybermanassociates.com
- www.mercedesbenzofaustinservice.com
- longarmquiltacademy.com
- lnianemarzenie.pl
- www.weboonline.com
- alkathirilaw.com
- beysukonaklari.com
- truonggiangcompany.com
- globalfeedindustry.com
- dragonera.cn
- mygamedaysports.com
- ingpoggi.eu
- kachhiproperties.com
- xpress2.eu
- www.golddustdental.com
- nicenpos.com
- bibonatura.com
- marinda.ru
- alteredcompta.com
- rh-h1tapi-turbo.com
- gservicepz.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report