MALICIOUS — d1611c08088c27c8d543fa6c753d89680036003d2f9fc117d43bf09345a378f1
MALICIOUS — d1611c08088c27c8d543fa6c753d89680036003d2f9fc117d43bf09345a378f1 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d1611c08088c27c8d543fa6c753d89680036003d2f9fc117d43bf09345a378f1 - SHA-1:
24cc6653bdb489f0ef8a5dabf3aa7c37295385c8 - MD5:
c0a52143d915f3b51bf878ed945efed5 - ssdeep:
1536:wu6iBhNffqV5gv2IQ7SOQ1B9lNS96JRhN:CiBhNfVv2IhT17v/hN - TLSH:
T1A536F1F3927BEE4CB8476E82EEFB52415C4EF39C6031E6581168A79CD08CA5DAC11B04 - Submitted as: d1611c08088c27c8d543fa6c753d89680036003d2f9fc117d43bf09345a378f1
- File type: pdf · Size: 65536 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Trellix Stinger (McAfee): PDF/Phish-FAB!C0A52143D915
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://tfh-filter.hu/_user/file/gelirogusur.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://wastran.ru/uplcv?utm_term=gateway+b2+workbook+answers, https://ercrs.org/wp-content/plugins/super-forms/uploads/php/files/df9pcd2pg38mim6ad6d4kniicb/19892667617.pdf, http://tfh-filter.hu/_user/file/gelirogusur.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://wastran.ru/uplcv?utm_term=gateway+b2+workbook+answers
- https://ercrs.org/wp-content/plugins/super-forms/uploads/php/files/df9pcd2pg38mim6ad6d4kniicb/19892667617.pdf
- http://tfh-filter.hu/_user/file/gelirogusur.pdf
- http://baigeleather.com/userfiles/file/vunelokosuluva.pdf
- https://paron-rebondir.com/uploads/files/ladukas.pdf
- http://structurecreative.com/wp-content/plugins/formcraft/file-upload/server/content/files/160834753b1415---55476117693.pdf
- https://maturana.cl/upload/file/32401676283.pdf
- https://twr1115.net/files/fckeditor/file/jisokavuwidemi.pdf
- https://cambodiaangkorhomestay.com/userfiles/file/90767467545.pdf
- https://adbetelparaguay.com/wp-content/plugins/super-forms/uploads/php/files/8d31000d096cb5dfb905455561e4a2b7/fejodux.pdf
- http://vietthanhstone.com/images/news/file/jumezekarebafalonujokomo.pdf
- http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1607bee0c75663---69285807784.pdf
- https://islandsvefir.is/wp-content/plugins/super-forms/uploads/php/files/p31p8onoepo0euua6al5ihjmj9/joferimu.pdf
- https://feriaesotericadeatocha.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ae84add1269---62619267851.pdf
- https://www.bakirkoytemsilcisi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607d10bb6c0b1---26690804515.pdf
Embedded domains
- wastran.ru
- ercrs.org
- baigeleather.com
- paron-rebondir.com
- structurecreative.com
- twr1115.net
- cambodiaangkorhomestay.com
- adbetelparaguay.com
- vietthanhstone.com
- www.inhd.com.br
- feriaesotericadeatocha.com
- www.bakirkoytemsilcisi.com
- tfh-filter.hu
- maturana.cl
- islandsvefir.is
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report