MALICIOUS — b7cbb0fbc649f68c031a780933fad9c5bbbdfe6123c6f8992480289967b181c0
MALICIOUS — b7cbb0fbc649f68c031a780933fad9c5bbbdfe6123c6f8992480289967b181c0 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b7cbb0fbc649f68c031a780933fad9c5bbbdfe6123c6f8992480289967b181c0 - SHA-1:
c235c0e7b868769ad73f5b5640331c31cf6d6e49 - MD5:
37d5182d6fef86dab479c8e618669766 - ssdeep:
1536:JvrJrpehhHua3U6YMeQ8I2kJ1gRHPFmtu+Wpmgbtzf:VrxYN/YS2BHPFmAmstzf - TLSH:
T18236DFD22097DD0CBA9F5E46EFB616AE95CFE38911AAE240484C43DCD0ACD3E7E10951 - Submitted as: b7cbb0fbc649f68c031a780933fad9c5bbbdfe6123c6f8992480289967b181c0
- File type: pdf · Size: 65232 bytes
- Verdict: malicious (94/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://elearning-chemistry.ro/userfiles/file/44948901805.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://status-go.net/gfx/userfiles/files/mabobaxubujuxitinelopivi.pdf, http://turskazka.ru/ckfinder/userfiles/files/poxirimixusujidajubegov.pdf, http://www.191seo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b0b50562717---64275775050.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/BvfzZFkJO3s/uplcv?utm_term=tough+data+structure+interview+questions
- http://status-go.net/gfx/userfiles/files/mabobaxubujuxitinelopivi.pdf
- http://turskazka.ru/ckfinder/userfiles/files/poxirimixusujidajubegov.pdf
- http://www.191seo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b0b50562717---64275775050.pdf
- http://adamlegal.com/userfiles/file/rurufexu.pdf
- https://avenue102.com/uploads/file/sedowiburopazegoturafar.pdf
- https://elearning-chemistry.ro/userfiles/file/44948901805.pdf
- https://arerp.kr/data/file///xeridazujurilarekogibunus.pdf
- https://janeunchained.com/wp-content/plugins/super-forms/uploads/php/files/h74c1k6ih0j8c9vsuo7rvks7r8/mewinu.pdf
- https://dtcprojects.com.au/wp-content/plugins/super-forms/uploads/php/files/20ren2ekv5ohuo87ikleieav9q/jijara.pdf
- https://bizdrive.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1/160aa5c3cb555c---nifurutorapisedisuf.pdf
- https://canadiancontractorservices.com/wp-content/plugins/super-forms/uploads/php/files/vnhpefm6kk863ncmcufkmchgh4/43008198939.pdf
- https://laneopx.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a14ea68ed38---ruraviz.pdf
- https://travelselection.us/wp-content/plugins/formcraft/file-upload/server/content/files/1607db2193a289---popovajufu.pdf
- https://mama-light.net/business_school/uploads/file/goxisudixuwavofijufamexum.pdf
- http://brodart01.com/wp-content/plugins/super-forms/uploads/php/files/9je03h5buqkvvrsd5tnfj3dth7/jutofikewavatal.pdf
- http://www.risingstars.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1608fd21bba470---65348489200.pdf
- https://www.bountyvacation.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607bcac895efd---banimerixozigufaxukifufex.pdf
- https://singaporeroadshow.com/wp-content/plugins/super-forms/uploads/php/files/095c5de74b771126f37a05409a14df9e/depane.pdf
- https://travelsafeway.com/userfiles/file/silaporoboguwo.pdf
- http://lifemartrealestateconnect.com/wp-content/plugins/super-forms/uploads/php/files/ls01u53do7mngddsc9keidm7u5/mowupijuvokipu.pdf
- https://monacollection.ua/wp-content/plugins/super-forms/uploads/php/files/62fd9aa8c4a555a6f24b8df52da49894/vetezoruduvagiza.pdf
- https://englewoodgrassfarm.com/wp-content/plugins/super-forms/uploads/php/files/bb1d4ab532e623590c594b326036242b/6530885769.pdf
- https://wamsconference.com/wp-content/plugins/super-forms/uploads/php/files/bf1d91be9e285d5b341ae911755ce4cc/rowerufij.pdf
- https://nhaban24h.com.vn/wp-content/plugins/super-forms/uploads/php/files/skt6j5cod2ekp37mv2k0lmb6b2/3078578808.pdf
Embedded domains
- feedproxy.google.com
- status-go.net
- turskazka.ru
- www.191seo.com
- adamlegal.com
- avenue102.com
- arerp.kr
- janeunchained.com
- dtcprojects.com.au
- bizdrive.nl
- canadiancontractorservices.com
- laneopx.com
- travelselection.us
- mama-light.net
- brodart01.com
- www.bountyvacation.com
- singaporeroadshow.com
- travelsafeway.com
- lifemartrealestateconnect.com
- monacollection.ua
- englewoodgrassfarm.com
- wamsconference.com
- gtsonline.nl
- elearning-chemistry.ro
- www.risingstars.com.tr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report