MALICIOUS — dc721164b9119478660162130555b1e3f91da79ab1c1ff6071ffc0bcebba4f1d
MALICIOUS — dc721164b9119478660162130555b1e3f91da79ab1c1ff6071ffc0bcebba4f1d is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dc721164b9119478660162130555b1e3f91da79ab1c1ff6071ffc0bcebba4f1d - SHA-1:
6c56cb5a15d55d4b3f1c1e1ef9ceea1cd5f51f1e - MD5:
269e748990fd60bb049cf27462998599 - ssdeep:
1536:zATkNEDCyWos6YRlclKdy+tqsqQCtGoEUMBDI3iWxDKiDlSzXW8pO+IuH:5CvWi3a3dqJtGoER2HDKiDEzO+F - TLSH:
T13E38C0F711A7ED8CBB464B4779A710BCA049D74821A3DA804548B6BCC57CEBFBB10911 - Submitted as: dc721164b9119478660162130555b1e3f91da79ab1c1ff6071ffc0bcebba4f1d
- File type: pdf · Size: 80589 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://kiuanai.com/userfiles/file/wunal.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://kiuanai.com/userfiles/file/wunal.pdf, http://cga82.com/admin/File/nakonamipegora.pdf, http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/16137b0f6af0e5---numofixibuvor.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/GLLx1DTH0VQ/uplcv?utm_term=pacify+apk+horror+game
- http://kiuanai.com/userfiles/file/wunal.pdf
- http://cga82.com/admin/File/nakonamipegora.pdf
- http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/16137b0f6af0e5---numofixibuvor.pdf
- http://topup-fight.com/ckfinder/userfiles/files/92728562404.pdf
- https://comfortinnbarrie.com/phpsites/vertical_living/uploads/file/disasazibet.pdf
- https://leavereview.com/customerinterview/ckfinder/userfiles/files/76777688634.pdf
- https://www.opsclown.it/ckfinder/userfiles/files/fepemax.pdf
- https://goooinggroup.com/userfiles/files/20210910_211127.pdf
- http://socialbomjesus.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/161379aa270f8f---74590789595.pdf
- http://vako.vn/app/webroot/uploads/files/61029769576.pdf
- https://www.dekleinewerf.nl/wp-content/plugins/formcraft/file-upload/server/content/files/161378d6fac37a---90958772933.pdf
- http://jhdjt.com/images/upload/File/fujowutugol.pdf
- http://ficfart.org/userfiles/file/wamekuzutef.pdf
- http://szkolaprywatnaleszno.pl/userfiles/file/jakevixulewekibatezezo.pdf
- http://mjengo.org/FCKeditor/editor/filemanager/connectors/php/connector.php?Command=FileUpload&Type=File&CurrentFolder=%2Ffile/90127201811.pdf
- https://proff-doors.ru/wp-content/plugins/super-forms/uploads/php/files/4b4f88367469dcfc34a8a3e63975e869/vuxepuli.pdf
- https://ibrahimkoc.com/images/Media/files/77441129286.pdf
- https://globaltranslation.com/demo/global_translation/beta/userfiles/files/wejilenozuwogajez.pdf
- http://keralatravelpath.com/uploads/file/vazexaseje.pdf
- https://ijacr.net/assets_admin/ckfinder/core/connector/php/uploads/files/42339207827.pdf
- http://willajarmar.pl/userfiles/file/tapigivonuvewudugali.pdf
- http://mrpokedb.com/uploads/files/98493949993.pdf
- http://3e3i.com/UserFiles/file///wevime.pdf
- http://kleinschadenexperte.de/userfiles/file/22735742749.pdf
Embedded domains
- feedproxy.google.com
- kiuanai.com
- cga82.com
- vtracauto.com
- topup-fight.com
- comfortinnbarrie.com
- leavereview.com
- www.opsclown.it
- goooinggroup.com
- socialbomjesus.org.br
- www.dekleinewerf.nl
- jhdjt.com
- ficfart.org
- szkolaprywatnaleszno.pl
- mjengo.org
- proff-doors.ru
- ibrahimkoc.com
- globaltranslation.com
- keralatravelpath.com
- ijacr.net
- willajarmar.pl
- mrpokedb.com
- 3e3i.com
- kleinschadenexperte.de
- www.gieskestukadoors.nl
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report