MALICIOUS — cbc139e2249a2196a5e435f4b5b961ca1ba5a07f227cc05c50fcc4e97692ff95
MALICIOUS — cbc139e2249a2196a5e435f4b5b961ca1ba5a07f227cc05c50fcc4e97692ff95 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cbc139e2249a2196a5e435f4b5b961ca1ba5a07f227cc05c50fcc4e97692ff95 - SHA-1:
62c67b7e0eb806d0f3e70e4e2c9f668b0b952a47 - MD5:
84d9e061cc2e4020764953f36eaa778f - ssdeep:
1536:nufX8gsJOq181M6vhKkDu+ASgrESiToxhOknPnRZWGpOKHc:ufgJOqMMEgViM7LcK8 - TLSH:
T1F336D0E320A7DD4CB59FAB021DB712CD818EE348A465E6F1604CA31AE4DCD7EBD41941 - Submitted as: cbc139e2249a2196a5e435f4b5b961ca1ba5a07f227cc05c50fcc4e97692ff95
- File type: pdf · Size: 65488 bytes
- Verdict: malicious (94/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://codienlanhtrangia.com/Images_upload/files/21130010411.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://www.saenger-ohg.de/wp-content/plugins/formcraft/file-upload/server/content/files/16140ea79d6495---98378232628.pdf, http://codienlanhtrangia.com/Images_upload/files/21130010411.pdf, http://uts.edu.co/portal/app/ckfinder/userfiles/files/gobukerutoro.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/S30rS-6n6vg/uplcv?utm_term=in+love+and+trouble
- https://www.saenger-ohg.de/wp-content/plugins/formcraft/file-upload/server/content/files/16140ea79d6495---98378232628.pdf
- http://codienlanhtrangia.com/Images_upload/files/21130010411.pdf
- http://uts.edu.co/portal/app/ckfinder/userfiles/files/gobukerutoro.pdf
- http://sns.hu/_user/file/90380173444.pdf
- http://suportti.com/wp-content/plugins/formcraft/file-upload/server/content/files/16144eb344cf18---mewunawom.pdf
- https://marljivo.hr/UserFiles/files/76238199650.pdf
- http://uni-soar.com/userfiles/file/botovixobamokal.pdf
- https://www.fangjin.org/ckfinder/userfiles/files/nobepogokipogasesako.pdf
- https://nullemont.fr/nullemont/ckfinder/userfiles/files/82701765776.pdf
- http://majortaylorride.info/images/uploaded/file/belalorepokoxanaruk.pdf
- https://parc-hotel.info/file/24989776435.pdf
- http://gazetavk.ru/img/file/natil.pdf
- https://gogift-it.com/userfiles/files/wiguz.pdf
- http://www.siscard.com/wp-content/plugins/formcraft/file-upload/server/content/files/16159a6f7a0cfa---mizedozodaxotomerenuxe.pdf
- http://stickerbarcode.com/file_media/file_image/file/65955111940.pdf
- http://www.lbtfilm.com/uploads/files/220039944.pdf
- http://autolubitel-irk.ru/userfiles/file/pawamer.pdf
- http://www.corazondelsol.es/ckfinder/userfiles/files/zosijolurepuzebosujowo.pdf
- https://iqmuseum.mn/uploads/files/pedodutodimivukosi.pdf
- http://originalavto.ru/userfiles/file/fasonemezilu.pdf
Embedded domains
- c.ca
- feedproxy.google.com
- www.saenger-ohg.de
- codienlanhtrangia.com
- uts.edu.co
- suportti.com
- uni-soar.com
- www.fangjin.org
- nullemont.fr
- majortaylorride.info
- parc-hotel.info
- gazetavk.ru
- gogift-it.com
- www.siscard.com
- stickerbarcode.com
- www.lbtfilm.com
- autolubitel-irk.ru
- www.corazondelsol.es
- originalavto.ru
- sns.hu
- marljivo.hr
- iqmuseum.mn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report