MALICIOUS — b548be087a392adea078a9607efc2967d04085975da53bb3fb7ca8fcf1e9df4a
MALICIOUS — b548be087a392adea078a9607efc2967d04085975da53bb3fb7ca8fcf1e9df4a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b548be087a392adea078a9607efc2967d04085975da53bb3fb7ca8fcf1e9df4a - SHA-1:
e810fdda1790a47c425923ebf46fcc9d455e8eaa - MD5:
d87c19dbc3cfa57d4437be616fae4635 - ssdeep:
1536:Bl0cYbV2Axlpxo8/el538H+1Pb6G15MVeEAzlWaw+IO5a6gBWkCwbi9ycSRhpDji:4nbYWo8/e7886GQeEAzlWrv2nqCwSfSU - TLSH:
T16E38D0E761A7DD5C778A9B43A97A0298D48BD3946266EF5000C8B73CC07C5BD7E01AB0 - Submitted as: b548be087a392adea078a9607efc2967d04085975da53bb3fb7ca8fcf1e9df4a
- File type: pdf · Size: 83842 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://sapporomn.com/userfiles/files/49372502550.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=streaming+film+venom+2018, http://tlxzkj.com/uploads/file/091113458373.pdf, http://prosquash.by/data/bapibifetufirowo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/uplcv?utm_term=streaming+film+venom+2018
- http://tlxzkj.com/uploads/file/091113458373.pdf
- http://prosquash.by/data/bapibifetufirowo.pdf
- http://visit-pune.com/userfiles/file/75130439260.pdf
- http://dhf-china.com/d/files/fidolasowogoxewuponuvene.pdf
- https://sapporomn.com/userfiles/files/49372502550.pdf
- http://www.andreapondika.cz/file/41239019658.pdf
- https://getlovebooks.com/wp-content/plugins/super-forms/uploads/php/files/970d83ff4969e9f0d21624b1a8c463c6/52876892617.pdf
- https://sistemagestiondpr.com/userfiles/file/93563022271.pdf
- http://www.bongbansaigon.com/uploads/files/vevezemupabesesifupexuxes.pdf
- http://skupka54.ru/upload/m/fawugevelelerovezunok.pdf
- http://ramenzoni.eu/userfiles/files/ladixepefur.pdf
- https://widepolymers.com/userfiles/file/31456149473.pdf
- http://tdbm.vn/upload/files/79432747395.pdf
- https://htchninc.com/d/files/jiwabasawidukubaleg.pdf
- https://angkortaxiservice.com/userfiles/file/zeselesa.pdf
- http://www.belladermeestetica.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16136ec7db6e8d---29454821435.pdf
- https://xn--fct5g39pjpo.tw/upload/leakstop/files/maralitevutoji.pdf
- http://topoint.net/userfiles/fckFile/20210915140513.pdf
- https://onutglen.com/caningest/images/file/24127420772.pdf
- https://cordovajewelry.com/images/file/7840497148.pdf
- http://geriatriccarenewjersey.com/userfiles/files/26978116981.pdf
- http://studiolegaletrotta.eu/userfiles/files/1661965179.pdf
- https://www.acptechnologies.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614178b4481c4---fujogag.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- medvor.ru
- tlxzkj.com
- visit-pune.com
- dhf-china.com
- sapporomn.com
- getlovebooks.com
- sistemagestiondpr.com
- www.bongbansaigon.com
- skupka54.ru
- ramenzoni.eu
- widepolymers.com
- htchninc.com
- angkortaxiservice.com
- www.belladermeestetica.com.br
- xn--fct5g39pjpo.tw
- topoint.net
- onutglen.com
- cordovajewelry.com
- geriatriccarenewjersey.com
- studiolegaletrotta.eu
- www.acptechnologies.com
- www.w3.org
- purl.org
- ns.adobe.com
- prosquash.by
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report