MALICIOUS — bf7a187bd027a86f4948d301c1876da42936635616fd093e30f5518785f5471b
MALICIOUS — bf7a187bd027a86f4948d301c1876da42936635616fd093e30f5518785f5471b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bf7a187bd027a86f4948d301c1876da42936635616fd093e30f5518785f5471b - SHA-1:
def542233295462685e84eaa4dc29390fe3b1e73 - MD5:
f3ac2c5beb83a7ee46847def792797de - ssdeep:
1536:v6/w+Ol7Uv4nzxIPQK9QaKMUcrZYWxTBvapMfnbW8pO+vJ/94V:yI+Ol7UAnzx4QadVZxhv/i+xk - TLSH:
T17C37BFF351D7CC8CB78B9F4369A9119D618AD3445171FFA04088B3AC997CABEBB04A11 - Submitted as: bf7a187bd027a86f4948d301c1876da42936635616fd093e30f5518785f5471b
- File type: pdf · Size: 73626 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://topimmigrationlawyer.org/ckfinder/userfiles/files/moduxibumolewusujaxivep.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://infrive.ru/uplcv?utm_term=zoom+instruction+manual, http://sportsht.com/userfiles/file/luwasuzifoxegef.pdf, http://oawebserver.com/piceditor/file/nerikapen.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://infrive.ru/uplcv?utm_term=zoom+instruction+manual
- http://sportsht.com/userfiles/file/luwasuzifoxegef.pdf
- http://oawebserver.com/piceditor/file/nerikapen.pdf
- http://ceresasrl.it/userfiles/files/89108483078.pdf
- https://xlspandoek.nl/userfiles/file/jalaripozum.pdf
- http://topimmigrationlawyer.org/ckfinder/userfiles/files/moduxibumolewusujaxivep.pdf
- http://wagnerpc.com/userfiles/files/38825879221.pdf
- https://xn--interpeas-r6a.es/upload/files/wiliwa.pdf
- https://miamivanservice.net/wp-content/plugins/formcraft/file-upload/server/content/files/1614058efe51e7---vejefogosep.pdf
- http://studiotecnicomaglio.it/userfiles/files/42373424063.pdf
- http://webinaris.training/ckfinder/userfiles/publics/files/92799471090.pdf
- http://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1614d16b041de2---65980236630.pdf
- http://darstin.com/userfiles/files/62774985349.pdf
- https://www.hs-hofgastein.salzburg.at/ckfinder/userfiles/files/91330745264.pdf
- http://www.uvhk.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613dbfa97b6c1---13329196860.pdf
- https://phunhai.net/upload/files/67346594564.pdf
- https://sardavetri.it/userfiles/file/senuzowagura.pdf
- http://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1614cfa18b138a---xajiwivaje.pdf
- http://multiseal.com.ph/wp-content/plugins/formcraft/file-upload/server/content/files/1614c615ae2abd---26091288346.pdf
- https://mptradingcompany.com/userfiles/file/kidefatesikikowira.pdf
- http://zespolbahamas.pl/zdjecia/file/fusesotarigibal.pdf
- http://alda.pl/ckfinder/userfiles/files/6849991841.pdf
- http://vietdubai.com/userfiles/file/fazamafofobexoxizafimosuz.pdf
- https://www.modianodesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614181a8a29b8---47848227422.pdf
- http://impex-italia.it/userfiles/files/wufibugozuvenum.pdf
Embedded domains
- infrive.ru
- sportsht.com
- oawebserver.com
- ceresasrl.it
- xlspandoek.nl
- topimmigrationlawyer.org
- wagnerpc.com
- xn--interpeas-r6a.es
- miamivanservice.net
- studiotecnicomaglio.it
- darstin.com
- www.uvhk.com
- phunhai.net
- sardavetri.it
- mptradingcompany.com
- zespolbahamas.pl
- alda.pl
- vietdubai.com
- www.modianodesign.com
- impex-italia.it
- tuvantindat.com
- franchiseinnovations.org
- www.gitialiganjlko.org
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report