MALICIOUS — b6a9157001313d2c0002df66b8da6a18e7d7fc22a9c071b035dc1484a38f1ed3
MALICIOUS — b6a9157001313d2c0002df66b8da6a18e7d7fc22a9c071b035dc1484a38f1ed3 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b6a9157001313d2c0002df66b8da6a18e7d7fc22a9c071b035dc1484a38f1ed3 - SHA-1:
415e030e656af62498320232dd6f2ff290f3e8e9 - MD5:
cdbe74144d33fbe09be1d5f25b33785e - ssdeep:
1536:yWKF4mJM6wh3PsGYxAZlIWMG35gxI/3m2xutWlK9XZDbVfoZfWspO2zz/:mFLGd9PtIWMGJgxIvm2g6WZDBoi2X - TLSH:
T19838C0F36053DC1C6B9FCB5329FB11ADA486D388A061FA518184B66CD17C9BEBB20611 - Submitted as: b6a9157001313d2c0002df66b8da6a18e7d7fc22a9c071b035dc1484a38f1ed3
- File type: pdf · Size: 81539 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://shellserva.nl/docs/Image/file/58694138609.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://crewmak.ru/uplcv?utm_term=watch+avengers+endgame+free+online+no+account, http://sobateracota.ro/mm/file/topevi.pdf, https://securitydm.net/slicice/file/wamedidevi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crewmak.ru/uplcv?utm_term=watch+avengers+endgame+free+online+no+account
- http://sobateracota.ro/mm/file/topevi.pdf
- https://securitydm.net/slicice/file/wamedidevi.pdf
- https://xrtradingfeedback.com/cmsimages/file/948270518.pdf
- http://bright-mineral.com/uploadfile/file/2021091121531591.pdf
- https://absoluteanytime.com/media_file/files/files/48842383960.pdf
- https://shellserva.nl/docs/Image/file/58694138609.pdf
- http://medrea.ru/upload/files/58027912099.pdf
- http://grafichesirio.com/userfiles/files/sadasopojatajupovemufo.pdf
- http://skolicka.eu/foto/images/file/korofupixowatemuret.pdf
- https://myphi.biz/nbloom/fckuploads/file/bafarevisutexenenebotedi.pdf
- http://ecohort.com/userfiles/files/18650145879.pdf
- http://www.cuerpomenteyespiritu.es/wp-content/plugins/formcraft/file-upload/server/content/files/16130ffc39ed7f---74764474769.pdf
- http://biomedia.asia/upload/ckimage/files/5542673190.pdf
- http://stoka-saarlouis.de/userfiles/file/63024265106.pdf
- http://sanmorales.es/userfiles/files/wawidolinaworemasaxepetel.pdf
- https://unosms.us/userfiles/file/mutatexedisoduwefat.pdf
- http://uteambio.com/upload/files/lapidesofebuwo.pdf
- https://eatorhours.org/e-bussiness/fckimages/file/8390745992.pdf
- http://hoachathoanggia.com/userfiles/file/voravazag.pdf
- http://nuuts.mn/uploads/assets/46334263451.pdf
- https://akanaymatbaa.com/calisma2/files/uploads/bijanijetukanedoluwede.pdf
- http://jubileejec.com/userfiles/files/kukimogaxexale.pdf
- http://www.cst.rnu.tn/js/ckfinder/userfiles/files/tewovusup.pdf
- http://agataklimowska.pl/userfiles/file/88672491436.pdf
Embedded domains
- crewmak.ru
- securitydm.net
- xrtradingfeedback.com
- bright-mineral.com
- absoluteanytime.com
- shellserva.nl
- medrea.ru
- grafichesirio.com
- skolicka.eu
- myphi.biz
- ecohort.com
- www.cuerpomenteyespiritu.es
- biomedia.asia
- stoka-saarlouis.de
- sanmorales.es
- unosms.us
- uteambio.com
- eatorhours.org
- hoachathoanggia.com
- akanaymatbaa.com
- jubileejec.com
- agataklimowska.pl
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report