MALICIOUS — bed2fd0f105d2261f51cf8929914e030001d883b264d3bfe0942bae232d5cdbb
MALICIOUS — bed2fd0f105d2261f51cf8929914e030001d883b264d3bfe0942bae232d5cdbb is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bed2fd0f105d2261f51cf8929914e030001d883b264d3bfe0942bae232d5cdbb - SHA-1:
2ecd33b4328146444d215b9d7d31122e5b63224a - MD5:
8a3033b53f39c6e7d29f36ff9bcca570 - ssdeep:
1536:Mu4+kaKapRFauJdqHAXeRpHgt0rWA8YAHHbCuWOpOaZEWPHdWbGCkKenWczt:7T/7auJdqggHgtc/8Y0HGDaZzHdWCCk7 - TLSH:
T18D38DFF321D7FD8C76538F5354A20165948AD3847222EF9054CCBB2C967CABDBE04A91 - Submitted as: bed2fd0f105d2261f51cf8929914e030001d883b264d3bfe0942bae232d5cdbb
- File type: pdf · Size: 84089 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://myshopgroup.com/userfiles/files/55524446.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://stillincontact.com/images/mails/file/13837587872.pdf, http://lutechmed.com/Images_upload/files/85479033282.pdf, http://msinziniering.com/userfiles/file/zisadakekotebuf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/fzgW7-mxBc0/uplcv?utm_term=justice+league+snyder+cut
- http://stillincontact.com/images/mails/file/13837587872.pdf
- http://lutechmed.com/Images_upload/files/85479033282.pdf
- http://msinziniering.com/userfiles/file/zisadakekotebuf.pdf
- http://transbur.ru/admin/ckfinder/userfiles/files/46802521697.pdf
- http://matchonusa.com/uploads/files/betomewikaxesunimoli.pdf
- https://foulardfotografando.it/file/najaxux.pdf
- https://catequesisnavarra.org/guiarte_userfiles/files/13659782529.pdf
- http://soldearenales.com/galeria/files/95817869385.pdf
- http://tc-muehlacker.de/data/tcmuehlacker/userfiles/file/84817901944.pdf
- http://myshopgroup.com/userfiles/files/55524446.pdf
- https://monyetmesum.com/contents/files/36787753928.pdf
- http://ibtaker.ps/userfiles/file/dedadikotekadulowo.pdf
- http://www.smpnuenen.nl/images/files/zigesozawuguxomikelaw.pdf
- https://emotionalgift.youngzonejewelry.com/ckfinder/userfiles/files/56113220149.pdf
- http://zafirkort.com/uploads/files/gujafikafowixofetebutaju.pdf
- http://kioskcondoweb.wpengine.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f7ad5b2325---xuveze.pdf
- http://synerfreight.com/syner_upload/images/files/guzisunesinu.pdf
- http://zhongjiukeji.com/upload_fck/file/2021-9-9/20210909060429556542.pdf
- https://joyfool.art/wp-content/plugins/super-forms/uploads/php/files/6d330e5aee0d82a73f57d030e6672f67/57217088080.pdf
- http://autoscuolepintozzi.it/userfiles/files/jadezipidelozorelixud.pdf
- https://www.coconutlodge.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613540875e9f9---bolegotofenuwag.pdf
- https://johanbjerke.se/userfiles/file/xerasufifirafab.pdf
- http://visit-pune.com/userfiles/file/49495742624.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- stillincontact.com
- lutechmed.com
- msinziniering.com
- transbur.ru
- matchonusa.com
- foulardfotografando.it
- catequesisnavarra.org
- soldearenales.com
- tc-muehlacker.de
- myshopgroup.com
- monyetmesum.com
- www.smpnuenen.nl
- emotionalgift.youngzonejewelry.com
- zafirkort.com
- kioskcondoweb.wpengine.com
- synerfreight.com
- zhongjiukeji.com
- autoscuolepintozzi.it
- www.coconutlodge.com
- johanbjerke.se
- visit-pune.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report