MALICIOUS — ca853677977eb2e424646d8d14c4195477c62105ad324123095032cbebce4357
MALICIOUS — ca853677977eb2e424646d8d14c4195477c62105ad324123095032cbebce4357 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ca853677977eb2e424646d8d14c4195477c62105ad324123095032cbebce4357 - SHA-1:
518b1e6ea3ec85a9c963de52ca0558aa98b436e5 - MD5:
81818564168b4e0fd10be9780b6c347f - ssdeep:
1536:aVOYHDvY3Q9ZQT2axb/uE0ao9qcS+DSls5Yy3iBGsY39jS2Y7wSWV:sOYHTH9Z8PVL0r4cSa630sY39jS2Ycz - TLSH:
T16F36D0F34067DD4C3F8FA781ACAB106DC18EE788515AE652028C276C40AC6FD7F16546 - Submitted as: ca853677977eb2e424646d8d14c4195477c62105ad324123095032cbebce4357
- File type: pdf · Size: 65242 bytes
- Verdict: malicious (96/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f2aad2b286---25353550267.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://archism.ru/uplcv?utm_term=hyuna+get+out+of+my+house, https://www.temsilcisitesi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608a04d26e9d7---79531360088.pdf, http://files.ibiza-ferien.de/file/ladakevazokefezasu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://archism.ru/uplcv?utm_term=hyuna+get+out+of+my+house
- https://www.temsilcisitesi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608a04d26e9d7---79531360088.pdf
- http://files.ibiza-ferien.de/file/ladakevazokefezasu.pdf
- http://www.kevinbrooks.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160b23798e7e35---zodinumuramerujedufi.pdf
- http://mrsinternationalbeautypageant.com/clients/8/8c/8c0f0497d7166b07b5568c04be8084ca/File/xuxibib.pdf
- https://ehblending.com/wp-content/plugins/super-forms/uploads/php/files/35f63e4d94774eb389af65682dd5bd08/lufebagijusomujik.pdf
- https://zoldlepes.hu/userfiles/file/9783703874.pdf
- http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f2aad2b286---25353550267.pdf
- http://kaplanpm.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c92e471dc0---23960278592.pdf
- http://www.rec39.ru/wp-content/plugins/super-forms/uploads/php/files/124426723eea42c8893c421800a1f7fd/zilezelesulumituvosexovor.pdf
- http://www.homefacelifters.com/wp-content/plugins/super-forms/uploads/php/files/56c0bef8be48914c6a4c1687e24bfab5/givorufexopubojani.pdf
- https://led7.ru/file/xelelodumuwu.pdf
- http://marmaraisg.com/images_upload/files/62038562765.pdf
- http://recamonde.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160917f6af2bff---19369824718.pdf
- https://whiteelephant.co.in/wp-content/plugins/super-forms/uploads/php/files/747b25cac952ab40d55490f146ea5432/wixubowa.pdf
- http://mhfmjournal.com/data/22/2/55/64/2544879/user/2788947/htdocs/userfiles/file/xodebetipiba.pdf
- http://peaceinsrilanka.lk/userfiles/file/67544512689.pdf
- https://www.traveltimevipp.com/wp-content/plugins/super-forms/uploads/php/files/f3cc68aa33aa6cefcb057bd9011d7bd7/pikotubisuvabikaladisose.pdf
- http://www.supercarrentalsofmiami.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b9a6ba849e4---12115494944.pdf
- http://alpanelektrik.com/depo/sayfaresim/file/baxid.pdf
- https://southernlightingsource.com/wp-content/plugins/super-forms/uploads/php/files/2b548218c6ff53dd367fde7327f54506/67522856444.pdf
- http://cravaluos.com/ckfinder/userfiles/files/48148514028.pdf
- https://retta-bg.com/userfiles/mibopaziwasorasutekejux.pdf
- https://villatoscana-pi.it/userfiles/file/2187139716.pdf
- http://kimhoatra.vn/upload/fckimagesfile/77085383176.pdf
Embedded domains
- archism.ru
- www.temsilcisitesi.com
- files.ibiza-ferien.de
- www.kevinbrooks.ca
- mrsinternationalbeautypageant.com
- ehblending.com
- leap-egypt.com
- kaplanpm.com
- www.rec39.ru
- www.homefacelifters.com
- led7.ru
- marmaraisg.com
- recamonde.com.br
- whiteelephant.co.in
- mhfmjournal.com
- www.traveltimevipp.com
- www.supercarrentalsofmiami.com
- alpanelektrik.com
- southernlightingsource.com
- cravaluos.com
- retta-bg.com
- villatoscana-pi.it
- zoldlepes.hu
- peaceinsrilanka.lk
- kimhoatra.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report