MALICIOUS — b3a63f1b0ae10ed35fafeca76659aa9019bf9e5e80d7f455d987c1397d2250d7
MALICIOUS — b3a63f1b0ae10ed35fafeca76659aa9019bf9e5e80d7f455d987c1397d2250d7 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b3a63f1b0ae10ed35fafeca76659aa9019bf9e5e80d7f455d987c1397d2250d7 - SHA-1:
84dbe4f90d23ca70cecf2a5b4a886d99a73db89c - MD5:
1977f81ea60809720418f18002d4f669 - ssdeep:
1536:UXnf5obP5G7tdCDhDJwmJWwkiD3hqi3ge0HflwWrTGWCpOViIWFhKc8C7p0wRraZ:afS5GR8NDWAWwki7hge0/lZjViVgwKw+ - TLSH:
T13937C0F3219BDD8CB78B9B0349B6159DD04AE7982162EB5000487A7CC67CAFDBF18911 - Submitted as: b3a63f1b0ae10ed35fafeca76659aa9019bf9e5e80d7f455d987c1397d2250d7
- File type: pdf · Size: 73083 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://dom-nenilovo.ru/wp-content/plugins/super-forms/uploads/php/files/02bafe665598d3c0e7045fd4b3762921/20721463946.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cructi.ru/uplcv?utm_term=xplayer+3d+pro+apk, http://0975811252cool.linker.tw/files/86024880887.pdf, http://tvoirostov.ru/ckfinder/userfiles/files/tibapitunudelawoxolirev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cructi.ru/uplcv?utm_term=xplayer+3d+pro+apk
- http://0975811252cool.linker.tw/files/86024880887.pdf
- http://tvoirostov.ru/ckfinder/userfiles/files/tibapitunudelawoxolirev.pdf
- https://aquaticlandscape.com/wp-content/plugins/formcraft/file-upload/server/content/files/16141de9a89154---75786930906.pdf
- https://guijek.com/userfiles/file/56137222297.pdf
- http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/161301a4b15ea0---nuzifofefajunixo.pdf
- http://studiofranzoni.eu/userfiles/files/lagoguvogonat.pdf
- http://ceroki.com/image/files/42422938183.pdf
- https://actionsporting.com/userfiles/files/toxogutaninaripoba.pdf
- http://dom-nenilovo.ru/wp-content/plugins/super-forms/uploads/php/files/02bafe665598d3c0e7045fd4b3762921/20721463946.pdf
- https://jobtiara.com/files/files/kinejexoragopimiwomel.pdf
- http://davidhammerstein.org/userfiles/file/wamikega.pdf
- http://come2menorca.com/images/file/mujitasigikod.pdf
- http://mos-craciun-inchiriere.ro/fckfiles/file/74445798280.pdf
- https://dutchfansitenetwork.nl/ckfinder/userfiles/files/81423918791.pdf
- http://dexgerm.com/data/file/userfiles/files/69832241000.pdf
- http://kingspec.su/wp-content/plugins/super-forms/uploads/php/files/v3sijihc855flqqoavq69kl3u2/ralopijakoguwapinususot.pdf
- http://kayamedbursa.com/userfiles/file/buremofuxepokinemakireji.pdf
- https://sedefartphotography.com/resimler/files/memerejajirizenipogo.pdf
- http://bdsps.org/slbdavbatala/userfiles/file/52218188981.pdf
- https://pt2-turbo-j3t.com/contents/files/54981016059.pdf
- https://saglamahsapkutu.com/img/editor/image/file/wejiworag.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cructi.ru
- 0975811252cool.linker.tw
- tvoirostov.ru
- aquaticlandscape.com
- guijek.com
- www.inhd.com.br
- studiofranzoni.eu
- ceroki.com
- actionsporting.com
- dom-nenilovo.ru
- jobtiara.com
- davidhammerstein.org
- come2menorca.com
- dutchfansitenetwork.nl
- dexgerm.com
- kingspec.su
- kayamedbursa.com
- sedefartphotography.com
- bdsps.org
- pt2-turbo-j3t.com
- saglamahsapkutu.com
- www.w3.org
- purl.org
- ns.adobe.com
- mos-craciun-inchiriere.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report