MALICIOUS — c47a319e9b46e7c3355cfd3b05ad3c9751bdb1414f6b9d8c8e654ff82fa2a481
MALICIOUS — c47a319e9b46e7c3355cfd3b05ad3c9751bdb1414f6b9d8c8e654ff82fa2a481 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c47a319e9b46e7c3355cfd3b05ad3c9751bdb1414f6b9d8c8e654ff82fa2a481 - SHA-1:
76327f5767af09a2f48e22ddb8622d26f739b35f - MD5:
02aaefa01e9e4d452a54c8841fc579cc - ssdeep:
1536:cTN7L9Z0BmcWe0eAYPILyM2vovSi0GRQWOpOwrKWRhsSl3s:UN7L/YmNe0mPILUvovSi0GLwrfhsc3s - TLSH:
T12437D1E33197DC1CB74F5F029AFA22AE85CDD7486152F1415048A6ADE4ACCBF7E28604 - Submitted as: c47a319e9b46e7c3355cfd3b05ad3c9751bdb1414f6b9d8c8e654ff82fa2a481
- File type: pdf · Size: 71953 bytes
- Verdict: malicious (96/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://car-zone.sk/data/data/file/lakeke.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://drafthe.ru/uplcv?utm_term=subway+surfer+online+play+free, http://chicagohalo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613abd030fcf7---62252312554.pdf, http://car-zone.sk/data/data/file/lakeke.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://drafthe.ru/uplcv?utm_term=subway+surfer+online+play+free
- http://chicagohalo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613abd030fcf7---62252312554.pdf
- http://car-zone.sk/data/data/file/lakeke.pdf
- https://doctornhospital.com/banglanews24/editorsfiles/files/xasewetefegegosaz.pdf
- https://www.c2commercial.com/wp-content/plugins/super-forms/uploads/php/files/1544201bf9292e7865dae40153e72263/wejikajotazo.pdf
- https://33mobility.net/uploads/files/31805135066.pdf
- http://wasserburg.pl/userfiles/file/vudaxobas.pdf
- https://bilegt.mn/userfiles/files/17871584720.pdf
- https://capitalsyndic.com/userfiles/file/kokovevasojipiwaxoxapewik.pdf
- https://www.lavishlook.se/wp-content/plugins/super-forms/uploads/php/files/3f111f147a7dcb5a0b64c830fca7c430/bapaxex.pdf
- https://www.focus.mu/wp-content/plugins/super-forms/uploads/php/files/85e89819e502d1c8171049a27678eb4c/71006008651.pdf
- https://pustelnik-budownictwo.pl/ckfinder/userfiles/files/61957571960.pdf
- https://hacunamatata.ru/wp-content/plugins/super-forms/uploads/php/files/835807a8d5c278f9d6fe9d4312c260dc/40806852016.pdf
- http://leebyunghun.kr/new/upload/board/files/wefew.pdf
- http://onishi-kyosendo.jp/archive/fimejobij.pdf
- https://www.sesc-am.com.br/Selecao/ckfinder/files/numomimozulobazoba.pdf
- https://cruiseship.cruises/wp-content/plugins/super-forms/uploads/php/files/br5rbe05odb0om3ph42umbuf2p/dudibemoniz.pdf
- http://vector-mebel.ru/uploads/files/roxosejapuronadux.pdf
- http://big-blue-bus.com/pics/fotos/1/file/venemovepuzilazejelijewo.pdf
- https://mamap.in/ci/userfiles/files/70905594089.pdf
- https://responsible-tourism-alliance.com/content_file/files/ketovupamagipamumi.pdf
- http://topoint.cc/userfiles/fckFile/20210911072144.pdf
- https://www.fecomerciomg.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/16133ee3de9b91---40055911722.pdf
- http://jfhcoaching.com/userfiles/files/72730187493.pdf
- http://studiotecnicopinto.it/userfiles/files/mokosabevawiwewatines.pdf
Embedded domains
- drafthe.ru
- chicagohalo.com
- doctornhospital.com
- www.c2commercial.com
- 33mobility.net
- wasserburg.pl
- capitalsyndic.com
- www.lavishlook.se
- pustelnik-budownictwo.pl
- hacunamatata.ru
- leebyunghun.kr
- onishi-kyosendo.jp
- www.sesc-am.com.br
- vector-mebel.ru
- big-blue-bus.com
- mamap.in
- responsible-tourism-alliance.com
- topoint.cc
- www.fecomerciomg.org.br
- jfhcoaching.com
- studiotecnicopinto.it
- poongdung.com
- car-zone.sk
- bilegt.mn
- www.focus.mu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report