MALICIOUS — b8c48502dc37a8b78e0e961d5af0a2a0906a947f1731b69c956151376c89c4a0
MALICIOUS — b8c48502dc37a8b78e0e961d5af0a2a0906a947f1731b69c956151376c89c4a0 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b8c48502dc37a8b78e0e961d5af0a2a0906a947f1731b69c956151376c89c4a0 - SHA-1:
b7251d366d525cbd5af305c6767ba03d7a06890d - MD5:
b16de95bc013e70e3a47fbe8f7f538b2 - ssdeep:
1536:nKin7kCotrwVCv/H7tdxSjJZUXWUFR86JziWxApOGViYhZu:Z7kCotkO/HvAdsb86JzH3GMYy - TLSH:
T14837BFF321ABDD4C76879F4769BE419C908AE74421A2EBA0408CB73C94BC57E7E14E40 - Submitted as: b8c48502dc37a8b78e0e961d5af0a2a0906a947f1731b69c956151376c89c4a0
- File type: pdf · Size: 74084 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://hightechrustremovers.nl/wp-content/plugins/formcraft/file-upload/server/content/files/161437c1d3804b---72684851728.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://nomylo.ru/uplcv?utm_term=father+bear+comes+home, https://sidexsideaudio.com/wp-content/plugins/formcraft/file-upload/server/content/files/161323f5b97caf---petosazepepakones.pdf, https://aildf.in/userfiles/file/viruzudawududaw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nomylo.ru/uplcv?utm_term=father+bear+comes+home
- https://sidexsideaudio.com/wp-content/plugins/formcraft/file-upload/server/content/files/161323f5b97caf---petosazepepakones.pdf
- https://aildf.in/userfiles/file/viruzudawududaw.pdf
- https://ww150001.linebot.net/upfile/files/20210916020017.pdf
- https://patoman.ro/ckfinder/userfiles/files/43294727997.pdf
- https://basisangka.com/contents/files/zobiwutowag.pdf
- http://frutapac.es/ckfinder/userfiles/files/72527569253.pdf
- http://www.mbk-montage.nl/ckfinder/userfiles/files/jadujuzejiponemanud.pdf
- https://hightechrustremovers.nl/wp-content/plugins/formcraft/file-upload/server/content/files/161437c1d3804b---72684851728.pdf
- http://ichieh.tw/uploads/files/202109262213416134.pdf
- https://get.belonnanotservice.ga/away?/wp-content/plugins/formcraft/file-upload/server/content/files/16158f711ac17b---fokowonituxaguwewu.pdf
- https://carthink.org/wp-content/plugins/formcraft/file-upload/server/content/files/161402d6af3ae8---kiregej.pdf
- https://maria-galland.ru/files/file/zomebumudakug.pdf
- http://www.farparts.cl/wp-content/plugins/formcraft/file-upload/server/content/files/1613ec5089866e---wafiduzozatonogavejuj.pdf
- https://www.sahabatkeluargahomecare.com/wp-content/plugins/formcraft/file-upload/server/content/files/161328dfc02021---88334379114.pdf
- http://msci.com.ng/wp-content/plugins/formcraft/file-upload/server/content/files/161483d2409e9d---jilasoguforilifosowi.pdf
- https://dimensioninteractive.com/WYSIWYGImage/file/25057868721.pdf
- http://pietroquatriniarchitetto.eu/userfiles/files/revaxobugu.pdf
- http://car-zone.sk/data/data/file/wabevez.pdf
- https://endeligmandag.no/e-brev/data/div/73595075441.pdf
- http://hissekurban.com/resimler/files/sejubega.pdf
- http://piqiso.ru/userfiles/file/fejewuzevelikarogivo.pdf
- https://hearing-outlet.com/uploads/files/202109030453533689.pdf
- https://webmodeli.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613e9673d5686---pukiwimukegedejolas.pdf
- https://ceiling.holcom.vn/webroot/img/files/17265848034.pdf
Embedded domains
- nomylo.ru
- sidexsideaudio.com
- aildf.in
- ww150001.linebot.net
- basisangka.com
- frutapac.es
- www.mbk-montage.nl
- hightechrustremovers.nl
- ichieh.tw
- get.belonnanotservice.ga
- carthink.org
- maria-galland.ru
- www.sahabatkeluargahomecare.com
- dimensioninteractive.com
- pietroquatriniarchitetto.eu
- endeligmandag.no
- hissekurban.com
- piqiso.ru
- hearing-outlet.com
- webmodeli.com
- htk2.altrodesign.eu
- www.w3.org
- purl.org
- ns.adobe.com
- patoman.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report