MALICIOUS — b240953f4f952c1b61efaad61e19e8b29be751b24478e11e36ae8fc2f0865f17
MALICIOUS — b240953f4f952c1b61efaad61e19e8b29be751b24478e11e36ae8fc2f0865f17 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b240953f4f952c1b61efaad61e19e8b29be751b24478e11e36ae8fc2f0865f17 - SHA-1:
f060d71ba5d54ec43b49d2ddb6960565098ebae9 - MD5:
210a92abaf1cc8d72136346dee8225db - ssdeep:
1536:sq9gyRcwD/x7PNTPSd9LcfYycvH5WvrNuISEU5jWOpOaZEWALqn+:Vg+cwDhRPSd6fXcx6NPG0aZwq+ - TLSH:
T15B37E1E310A3DD5CBF0FDA03659B0294C989F3C866A3E691618C5769E2ECD3EBD40542 - Submitted as: b240953f4f952c1b61efaad61e19e8b29be751b24478e11e36ae8fc2f0865f17
- File type: pdf · Size: 76303 bytes
- Verdict: malicious (94/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://vrieshorst.nl/images/uploads/file/11352723087.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://synerhu.ru/uplcv?utm_term=frost+ancient+god+of+war, https://dolupin.com/calisma2/files/uploads/lubowonanejotewamisupa.pdf, https://ewms.vn/wp-content/plugins/super-forms/uploads/php/files/sqmi6khhv42h4a18d6sabms1qm/jamuwabisadupi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://synerhu.ru/uplcv?utm_term=frost+ancient+god+of+war
- https://dolupin.com/calisma2/files/uploads/lubowonanejotewamisupa.pdf
- https://ewms.vn/wp-content/plugins/super-forms/uploads/php/files/sqmi6khhv42h4a18d6sabms1qm/jamuwabisadupi.pdf
- http://vrieshorst.nl/images/uploads/file/11352723087.pdf
- https://sg-design.top/wp-content/plugins/super-forms/uploads/php/files/f92113f5ee17f97700ed032bc05e0c0b/bebemozologoverufiwuru.pdf
- https://gulfcans.com/home/madarmun/public_html/gulfcans/images/bulk_images/files/lapudal.pdf
- http://cherriestattoo.com/ckfinder/userfiles/files/subafowaxurixosaja.pdf
- https://master.plus/wp-content/plugins/super-forms/uploads/php/files/f3427dd4c56c3618e6d4bb7df4b30b74/soseretonevejejafufu.pdf
- http://recamonde.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/161304faf4fc4a---66550543228.pdf
- http://uptindia.com/newsimages/file///repodo.pdf
- http://srtprogetti.eu/userfiles/files/44922308558.pdf
- https://solarconsulting.org/wp-content/plugins/super-forms/uploads/php/files/14d2a2f1b5bef37932f63fe99f818bbb/2476314176.pdf
- https://otoform.com/upload/ckfinder/files/fazibidesalos.pdf
- http://kraljicabih.com/wp-content/plugins/formcraft/file-upload/server/content/files/161371122789a2---misukubasusonefek.pdf
- https://habibitours.org/ckfinder/userfiles/files/zesumipusarezitaxo.pdf
- http://roomyab.ir/basefile/roomyabir/files/47203379498.pdf
- https://abogadosaccidentealicante.centralcms.cloud/galeria/files/vuxaset.pdf
- https://epagneuls-bretons.fr/caningest/images/file/siwakidisarizenaga.pdf
- http://carnavaldemarbella.com/Senegal_5/Content/files/userfiles/file/xozebegujowe.pdf
- https://premiersuli.hu/files/files/rovuposufure.pdf
- http://bilmatbasim.com/userfiles/file/52028658258.pdf
- http://kaus21.com/userData/board/file/82046431708.pdf
- https://asiapharma.la/files/files/30852002383.pdf
Embedded domains
- synerhu.ru
- dolupin.com
- vrieshorst.nl
- sg-design.top
- gulfcans.com
- cherriestattoo.com
- recamonde.com.br
- uptindia.com
- srtprogetti.eu
- solarconsulting.org
- otoform.com
- kraljicabih.com
- habibitours.org
- roomyab.ir
- abogadosaccidentealicante.centralcms.cloud
- epagneuls-bretons.fr
- carnavaldemarbella.com
- bilmatbasim.com
- kaus21.com
- ewms.vn
- master.plus
- premiersuli.hu
- asiapharma.la
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report