MALICIOUS — c90da47488f3a224af634d7c56f3feb76efcc5977b9c509180ece259fc004dba
MALICIOUS — c90da47488f3a224af634d7c56f3feb76efcc5977b9c509180ece259fc004dba is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c90da47488f3a224af634d7c56f3feb76efcc5977b9c509180ece259fc004dba - SHA-1:
eff5e838f0525105b250eed0406f499d3fcfdf62 - MD5:
48de99d991b4355228576606deda9208 - ssdeep:
1536:fSGnnPMyV3HPID3OU14OX9waD+i9jW/VgYAaSgWkNpOPgd3IsRWqbc2LQ4ZRsli5:6cEyE4OXqXYiOLDPA4slc4ZCm - TLSH:
T16338D0F31197DD5C7B5B970369FF54ADA08AD3C85122EEA00588BA3C95BCAFD6E00910 - Submitted as: c90da47488f3a224af634d7c56f3feb76efcc5977b9c509180ece259fc004dba
- File type: pdf · Size: 81321 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://xtremefitness.com.au/application/third_party/ckfinder/userfiles/files/dugafep.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://tribo.kz/userfiles/File/wadid.pdf, http://www.elsecretodelolivo.com/wp-content/plugins/formcraft/file-upload/server/content/files/161355154304bb---61277083686.pdf, https://xtremefitness.com.au/application/third_party/ckfinder/userfiles/files/dugafep.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/GLLx1DTH0VQ/uplcv?utm_term=latest+games+apk
- http://tribo.kz/userfiles/File/wadid.pdf
- http://www.elsecretodelolivo.com/wp-content/plugins/formcraft/file-upload/server/content/files/161355154304bb---61277083686.pdf
- https://xtremefitness.com.au/application/third_party/ckfinder/userfiles/files/dugafep.pdf
- http://goraku-sangyo.com/userfiles/file/polodawomivetoduzesumadun.pdf
- http://emiem.pl/public/upload/ckfinder/userfiles/files/40484546418.pdf
- http://megat.pl/uploaded/fck_files/file/66074308571.pdf
- https://relaxbotanika.cz/ckfinder/userfiles/files/dovusuvukofawotupiledagi.pdf
- https://ctapigroup3.com/contents/files/ripumonuxamidifanep.pdf
- http://siddharpeedam.org/userfiles/file/
- https://tbsva.org/Upload/files/20210904191806.pdf
- http://njchemland.com/upload/files/51911043400.pdf
- http://bjhtdszdh.com/v15/Upload/file/20219211538192662.pdf
- http://gocep.org/data/userfiles/files/wajidezodukukazizejavari.pdf
- https://kitapkapla.com/upload/ckfinder/files/fojemetewebizubo.pdf
- https://hbfilm.ca/resimler/files/30690610830.pdf
- https://h1t-url12shio-turbo.com/contents/files/dumari.pdf
- http://www.reroofingbrisbaneqld.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16143af51ddd80---damonidenesil.pdf
- https://pataniforum.com/admin/jquery/ckfinder/userfiles/files/wuvosulok.pdf
- http://hit-air.pro/ckfinder/userfiles/files/36033952788.pdf
- http://yizhu580.com/ckfinder/userfiles/files/96314777968.pdf
- http://autowassenindex.nl/images/uploads/10038419626.pdf
- https://ka-base.no/images_students/files/fonidumo.pdf
- http://www.logistiekverbeteren.nl/ckfinder/userfiles/files/pemiteruwixajaxazidak.pdf
- https://get-insurance.in/ckfinder/userfiles/files/13908482169.pdf
Embedded domains
- feedproxy.google.com
- www.elsecretodelolivo.com
- xtremefitness.com.au
- goraku-sangyo.com
- emiem.pl
- megat.pl
- ctapigroup3.com
- siddharpeedam.org
- tbsva.org
- njchemland.com
- bjhtdszdh.com
- gocep.org
- kitapkapla.com
- hbfilm.ca
- h1t-url12shio-turbo.com
- www.reroofingbrisbaneqld.com.au
- pataniforum.com
- hit-air.pro
- yizhu580.com
- autowassenindex.nl
- ka-base.no
- www.logistiekverbeteren.nl
- get-insurance.in
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report