MALICIOUS — bb40fd143857368e80de78239c4f32bda6ebd80b23ff8dbe5db117977533ff2c
MALICIOUS — bb40fd143857368e80de78239c4f32bda6ebd80b23ff8dbe5db117977533ff2c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bb40fd143857368e80de78239c4f32bda6ebd80b23ff8dbe5db117977533ff2c - SHA-1:
d86722c6ea338be369ecf01e90ce8cd7836a25a0 - MD5:
c1d8eac2c7d2283765d3d733174c987a - ssdeep:
1536:BHvaIGLQG6/eC+osouNjp+9/R49BBKNAWHpOvTWzoxMUHdlmgwcoCQSN0:Ba3O2Jo4jo9549BvvnB3mgwcYr - TLSH:
T1E637CFF32097DD9C77864B1358EB02A85446D3C92162EB9001CCB6BCD6BCABDBF14951 - Submitted as: bb40fd143857368e80de78239c4f32bda6ebd80b23ff8dbe5db117977533ff2c
- File type: pdf · Size: 73336 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.kotolantopeni.cz/files/gatewatuxisinimijilof.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://chiangmaicharmingtravel.com/ckfinder/userfiles/files/45313882136.pdf, http://autoklej.pl/app/webroot/media/files/9226516041.pdf, http://zhymwz.com/upfile/file/ralijosexomupo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/FevRqgeaUVY/uplcv?utm_term=cash+app+gift+card+generator
- http://chiangmaicharmingtravel.com/ckfinder/userfiles/files/45313882136.pdf
- http://autoklej.pl/app/webroot/media/files/9226516041.pdf
- http://zhymwz.com/upfile/file/ralijosexomupo.pdf
- https://inchirieriavioane.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1613e30b4a80ff---81973987163.pdf
- http://jobsandhi.com/uploaded_files/userfiles/files/18167825317.pdf
- http://www.kotolantopeni.cz/files/gatewatuxisinimijilof.pdf
- http://www.xpresswedding.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613067e6626eb---fifij.pdf
- http://apnschool.in/singhania/downloads/file/56201060008.pdf
- https://dispecom.com/cms_dispecom/sgi_userfiles/userfiles/files/donuxetaboweki.pdf
- https://jdbailbonds.com/wp-content/plugins/super-forms/uploads/php/files/45e3f57c7ed8032279c6a90d9c12aa97/duxaxirasabetom.pdf
- https://ccskin.com/geektic/files/43252306671.pdf
- http://photo-preiss.com/upload_files/files/26384999788.pdf
- http://weilandvloeren.nl/fckimages/fapejewabezil.pdf
- http://matrixuniverzum.eu/wp-content/plugins/formcraft/file-upload/server/content/files/161380ef4633d7---33559049279.pdf
- http://starfishdowney.com/uploads/files/nejamonisiropo.pdf
- http://gostium.com/wp-content/plugins/formcraft/file-upload/server/content/files/16146b76a3d61a---fijuzetanodetip.pdf
- https://eric-parnes.com/ckfinder/userfiles/files/mudakonev.pdf
- https://www.digitalsofts.com/wp-content/plugins/formcraft/file-upload/server/content/files/16137cfb863ecb---zumet.pdf
- http://www.evisiontiendaonline.com/ckfinder/userfiles/files/semofatoma.pdf
- http://massintech.ru/img/outer/files/14930378984.pdf
- http://aokunoil.com/ckfinder/userfiles/files/gutuwafebunivigitivawaba.pdf
- http://www.timtransportes.com/home/wp-content/plugins/formcraft/file-upload/server/content/files/1614ecd6e482ac---4490386068.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- chiangmaicharmingtravel.com
- autoklej.pl
- zhymwz.com
- jobsandhi.com
- www.xpresswedding.com
- apnschool.in
- dispecom.com
- jdbailbonds.com
- ccskin.com
- photo-preiss.com
- weilandvloeren.nl
- matrixuniverzum.eu
- starfishdowney.com
- gostium.com
- eric-parnes.com
- www.digitalsofts.com
- www.evisiontiendaonline.com
- massintech.ru
- aokunoil.com
- www.timtransportes.com
- www.w3.org
- purl.org
- ns.adobe.com
- inchirieriavioane.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report