MALICIOUS — d5bb95252d3d5ff65c5a073de9f385cbb836b70bce095becfe0536889d623714
MALICIOUS — d5bb95252d3d5ff65c5a073de9f385cbb836b70bce095becfe0536889d623714 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d5bb95252d3d5ff65c5a073de9f385cbb836b70bce095becfe0536889d623714 - SHA-1:
ed343895cb68f7cf6da312ff5f3667ee88161ce5 - MD5:
526d2347936ac2cd8c1042b9ff28797f - ssdeep:
1536:mt/QoamIiAuui8ijw7GXV8MR0Gi/3nsI9jIJWcpOmiZcUmMWi29WmpVzt+y2:sPHAApj6AV1ls3nsI9jIAmiZgOipV6 - TLSH:
T1DD39DFF33187DD4D769B5F03B5FB2258605AEAC49132EAA04088B62CC5BC5BCBF14652 - Submitted as: d5bb95252d3d5ff65c5a073de9f385cbb836b70bce095becfe0536889d623714
- File type: pdf · Size: 92302 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://teplitsyoptom.ru/wp-content/plugins/super-forms/uploads/php/files/78e92a36eff8347de119771af898c728/zidejiduba.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://myucmas.com/userfiles/file/16059256825.pdf, https://bettenbaehren.de/wp-content/plugins/formcraft/file-upload/server/content/files/16099352ac80bc---tufurawomisuluwuxipebigil.pdf, https://lynnesnaturaltreats.com.au/wp-content/plugins/super-forms/uploads/php/files/183d41366bf3cc252596f1b851907952/wowozotaromokegakoxix.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/A3Ryygt5BCM/uplcv?utm_term=the+change+from+a+liquid+to+a+gas+is+called
- http://myucmas.com/userfiles/file/16059256825.pdf
- https://bettenbaehren.de/wp-content/plugins/formcraft/file-upload/server/content/files/16099352ac80bc---tufurawomisuluwuxipebigil.pdf
- https://lynnesnaturaltreats.com.au/wp-content/plugins/super-forms/uploads/php/files/183d41366bf3cc252596f1b851907952/wowozotaromokegakoxix.pdf
- http://makingtheturngolf.com/clients/9/92/925d9bae4ecf380f28dbe0e1390c16eb/File/55642650654.pdf
- http://jirehenl.com/userfiles/file/04094322695.pdf
- http://wujipacking.tw/upload/files/vubaziruxu.pdf
- https://dnsbp.com/all4help/fckuserfiles/file/18906792886.pdf
- https://vinaarc.com/app/webroot/files/ckfinder/userfiles/files/degemiziwikoba.pdf
- https://teplitsyoptom.ru/wp-content/plugins/super-forms/uploads/php/files/78e92a36eff8347de119771af898c728/zidejiduba.pdf
- https://marljivo.hr/UserFiles/files/73730226771.pdf
- https://swimproject.eu/wp-content/plugins/super-forms/uploads/php/files/20c1016625168094a17ee083e08d168c/bafedetajibu.pdf
- https://nsck-cykelmotion.dk/userfiles/file/rojotuv.pdf
- https://blackknowledge.com/wp-content/plugins/super-forms/uploads/php/files/17d99676c723b9b750f4ecd9d42ed6c2/30128837285.pdf
- https://maloneslandscape.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb04f4a0d20---xitanulenoduvurepe.pdf
- http://cl-metalparts.com/d/files/dedugu.pdf
- http://vdgairconditioning.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1609ec504bf94c---19068033178.pdf
- http://www.platformliften.info/wp-content/plugins/formcraft/file-upload/server/content/files/1608641bd9c0ed---laxoxosutonawop.pdf
- https://wccia-vastu.com/wp-content/plugins/super-forms/uploads/php/files/b6345c447608ad5b99423d7f6521f3cc/jaxexa.pdf
- http://imcborivali.org/userfiles/file/13866672438.pdf
- http://africareview.in/userfiles/file/jinekenumifireg.pdf
- https://ancoraeducacion.com/images/2563937094.pdf
- https://bonafideonline.com.ar/wp-content/plugins/super-forms/uploads/php/files/6f9ae60178ba09dad6636e541ef8367f/fumusuwowexit.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- myucmas.com
- bettenbaehren.de
- lynnesnaturaltreats.com.au
- makingtheturngolf.com
- jirehenl.com
- wujipacking.tw
- dnsbp.com
- vinaarc.com
- teplitsyoptom.ru
- swimproject.eu
- blackknowledge.com
- maloneslandscape.com
- cl-metalparts.com
- vdgairconditioning.nl
- www.platformliften.info
- wccia-vastu.com
- imcborivali.org
- africareview.in
- ancoraeducacion.com
- www.w3.org
- purl.org
- ns.adobe.com
- marljivo.hr
- nsck-cykelmotion.dk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report