MALICIOUS — b41ffa2206b21780430f60321d41de07bb0716d2e0b2636a446c2c4d6c2401f6
MALICIOUS — b41ffa2206b21780430f60321d41de07bb0716d2e0b2636a446c2c4d6c2401f6 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b41ffa2206b21780430f60321d41de07bb0716d2e0b2636a446c2c4d6c2401f6 - SHA-1:
013599ee0e8cd2e721b81e7d1ae456f218a4d583 - MD5:
d5d7086c4e8577203a78b875aa7656a5 - ssdeep:
1536:F4for4ol8ZpHhxX2Nr9BKu9WOpOaZEW3c3CAIKdfYbSr6tq:mgr4u8HHhUNrau2aZrhSQb4D - TLSH:
T18537C0F721F7CD4CB396CB436CE6525C608ADB882261DA105588767CA5FC5BEBF20610 - Submitted as: b41ffa2206b21780430f60321d41de07bb0716d2e0b2636a446c2c4d6c2401f6
- File type: pdf · Size: 75785 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://gdfsztal.com/uploadfile/files/marader.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://laborke.ru/uplcv?utm_term=abominable+torrent+magnet, http://gdfsztal.com/uploadfile/files/marader.pdf, https://themodernla.com/wp-content/plugins/super-forms/uploads/php/files/32dbb2262a53256106828daf9ad90c94/16198888887.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://laborke.ru/uplcv?utm_term=abominable+torrent+magnet
- http://gdfsztal.com/uploadfile/files/marader.pdf
- https://themodernla.com/wp-content/plugins/super-forms/uploads/php/files/32dbb2262a53256106828daf9ad90c94/16198888887.pdf
- http://flygarfield.net/userfiles/file/tikasogomewibizukesiwo.pdf
- https://dnm.tw/uploads/files/202109140406093775.pdf
- http://punaide.com/userfiles/files/kefisawuburubod.pdf
- https://vnsteeldetailing.com/UserFiles/files/lugas.pdf
- https://theshairpodcast.com/wp-content/plugins/super-forms/uploads/php/files/189ce61192d8f28a69970935484f15bc/nokizigafonidujo.pdf
- http://sk4education.com/ckfinder/userfiles/files/69140051652.pdf
- http://lblussana.it/images/file/94534998164.pdf
- http://kmimmigrationlaw.com/userfiles/file/tisujegubemaf.pdf
- https://40parables.com/wp-content/plugins/super-forms/uploads/php/files/155f80e59799e8e5109427931cf7a554/nixif.pdf
- http://abwrichmond.com/uploads/files/89520812718.pdf
- http://e-sportis.com/images/upload/72035142657.pdf
- https://taichielite.com/louis/taichi/ckfinder/userfiles/files/52960931071.pdf
- https://gkia.org/kingkong/userfiles/files/77919009864.pdf
- http://nek.ua/wp-content/plugins/formcraft/file-upload/server/content/files/1613fceb01b540---47809783059.pdf
- https://mercedesmazo.es/wp-content/plugins/formcraft/file-upload/server/content/files/16136d6905030b---gilod.pdf
- http://khangvietdn.com/uploads/file/58662190999.pdf
- http://consorzio-csa.it/userfiles/files/43250898303.pdf
- https://daulte.ch/ckfinder/userfiles/files/49459675009.pdf
- http://hamzalegalservices.com/userfiles/file/kusubukelenafomimov.pdf
- https://mondoaudio.it/img/uploaded/file/3957292318.pdf
- https://tumujerrusa.com/userfiles/11033907707.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- laborke.ru
- gdfsztal.com
- themodernla.com
- flygarfield.net
- dnm.tw
- punaide.com
- vnsteeldetailing.com
- theshairpodcast.com
- sk4education.com
- lblussana.it
- kmimmigrationlaw.com
- 40parables.com
- abwrichmond.com
- e-sportis.com
- taichielite.com
- gkia.org
- nek.ua
- mercedesmazo.es
- khangvietdn.com
- consorzio-csa.it
- daulte.ch
- hamzalegalservices.com
- mondoaudio.it
- tumujerrusa.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report