MALICIOUS — b448749dd8cec9d9f1f513233a0f3d9920de31a7ca6a18e8a34678b163294434
MALICIOUS — b448749dd8cec9d9f1f513233a0f3d9920de31a7ca6a18e8a34678b163294434 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b448749dd8cec9d9f1f513233a0f3d9920de31a7ca6a18e8a34678b163294434 - SHA-1:
8920196134a0682f51b6960bfc1fb17b72110eb5 - MD5:
191d26f356b3069d6a6536d05f884aac - ssdeep:
1536:AKRzTAZ65wRXGlhJjnRax55mUmQucnhWapOtQdhSWerubj:NkAKZGFjRax5kUmQnutQdhK+ - TLSH:
T18438D0E311AB9D5C378F5B07AFAF20BDA18EE7448162DC51408C6A5C91EC9BD7E10A90 - Submitted as: b448749dd8cec9d9f1f513233a0f3d9920de31a7ca6a18e8a34678b163294434
- File type: pdf · Size: 78052 bytes
- Verdict: malicious (96/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://e2ingenieros.com/ckfinder/userfiles/files/62275265601.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cructi.ru/uplcv?utm_term=introduction+to+health+physics+pdf, http://grandviewgroupresort.com/upload/files/megefitanuxesizu.pdf, http://az4group.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1612f6ba749835---63483770292.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cructi.ru/uplcv?utm_term=introduction+to+health+physics+pdf
- http://grandviewgroupresort.com/upload/files/megefitanuxesizu.pdf
- http://az4group.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1612f6ba749835---63483770292.pdf
- https://www.focus.mu/wp-content/plugins/super-forms/uploads/php/files/d65f6978fa3978bfa294c4b1b2ca350c/terofogeluxologetagalogit.pdf
- https://ilonew.tasksplan.com/userfiles/files/79357059266.pdf
- http://clearspace-design.com/CKEdit/upload/files/devir.pdf
- https://mrdak.cc/uploadfile/files/27345897500.pdf
- https://amt-alarmy.pl/userfiles/file/bonavipapetuz.pdf
- http://e2ingenieros.com/ckfinder/userfiles/files/62275265601.pdf
- http://fuguchair.com/upfolder/e/files/20210909040648.pdf
- https://miguktour.com/FileData/ckfinder/files/20210907_ABF7090742ABC5C8.pdf
- http://www.infranetltd.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614700140d3e4---42125758271.pdf
- http://baozhaopharm.com/upload/files/makerixazawugi.pdf
- http://www.guus.edu.mn/ckfinder/userfiles/files/giwumobexekaki.pdf
- http://sjanzee.nl/file/20584353521.pdf
- http://uk-finansist.ru/userfiles/file/tumebebukixi.pdf
- http://around-sicily.net/userfiles/file/vilexazebufeped.pdf
- http://axiomestates.com/userfiles/file/pepejemas.pdf
- https://karaari.leaddeehub.com/userfiles/files/97891924931.pdf
- http://2girlstrippin.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613bfc35d9869---83162831525.pdf
- http://ciba.lv/uploaded/file/32812091653.pdf
- http://angelofthewinds.org/ckfinder/userfiles/files/45936598400.pdf
- https://srldirect.com/ckfinder/userfiles/files/72278869458.pdf
- http://yokohama-model.com/userfiles/files/80861766473.pdf
- https://derechosenred.org/aym_image/files/kamakag.pdf
Embedded domains
- cructi.ru
- grandviewgroupresort.com
- az4group.com.br
- ilonew.tasksplan.com
- clearspace-design.com
- mrdak.cc
- amt-alarmy.pl
- e2ingenieros.com
- fuguchair.com
- miguktour.com
- www.infranetltd.com
- baozhaopharm.com
- sjanzee.nl
- uk-finansist.ru
- around-sicily.net
- axiomestates.com
- karaari.leaddeehub.com
- 2girlstrippin.com
- angelofthewinds.org
- srldirect.com
- yokohama-model.com
- derechosenred.org
- irisapp.cn
- www.focus.mu
- www.guus.edu.mn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report