MALICIOUS — dc8efad68bc0d4792083f942475d61f66d6bc9fe1e12f7b0c545cd39b7e80cc4
MALICIOUS — dc8efad68bc0d4792083f942475d61f66d6bc9fe1e12f7b0c545cd39b7e80cc4 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dc8efad68bc0d4792083f942475d61f66d6bc9fe1e12f7b0c545cd39b7e80cc4 - SHA-1:
d7efa59eda762150bfef7c1c8ef002793e1bcb79 - MD5:
dff8ac8a12ff2478d1d9d6612450f3cf - ssdeep:
1536:BvEF8PjbKxnFGRgiaZHQyA4f8qGGmL7tmFA6WthFQR5UWspO27Zs:ZPaxnFa36w9DG+YAru5X2a - TLSH:
T1D838C1F310DBDD5C779ADB4399EA219C6189D3886271EE501488772C94BCCBEAF00791 - Submitted as: dc8efad68bc0d4792083f942475d61f66d6bc9fe1e12f7b0c545cd39b7e80cc4
- File type: pdf · Size: 80046 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://piemonteforyou.it/userfiles/file/41133314996.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://af.ssla.ru/images/fornews/files/jepugiluvurubalaterodo.pdf, http://chaukitchen.com/uploads/files/buvetotirono.pdf, http://suliaox.com/v15/Upload/file/2021921659288217.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/BvfzZFkJO3s/uplcv?utm_term=flower+zombie+war+mod+apk
- http://af.ssla.ru/images/fornews/files/jepugiluvurubalaterodo.pdf
- http://chaukitchen.com/uploads/files/buvetotirono.pdf
- http://suliaox.com/v15/Upload/file/2021921659288217.pdf
- http://piemonteforyou.it/userfiles/file/41133314996.pdf
- http://kyokushin96.ru/admin/ckfinder/userfiles/files/kudotizapamadaruwisuzib.pdf
- http://www.ondebiz.com/userfiles/file/nilobomirafetapam.pdf
- http://files.ibiza-ferien.de/file/nolego.pdf
- http://dmn.ca/wp-content/plugins/formcraft/file-upload/server/content/files/161346eec4e177---nojakuji.pdf
- http://uticachemical.com/files/upload/files/81096755789.pdf
- https://doitsolutions.co/wp-content/plugins/super-forms/uploads/php/files/3a1efc9ae130dce659843a01843dd49f/tatesikifomo.pdf
- http://muacuoi.vn/Pictures/files/73504425561.pdf
- https://argentinaproduct.com/ckfinder/userfiles/files/72776655330.pdf
- https://fullhousetourism.com/UploadFiles/file/20210922045442150.pdf
- https://torbay.ru/images/uploads/file/29023854404.pdf
- http://olympusflights.com/files/files/lorovilawukoge.pdf
- https://www.cdsale.org.au/application/third_party/ckfinder/userfiles/files/tejefuwalatiwidasin.pdf
- https://qualitycountscleaning.com/wp-content/plugins/super-forms/uploads/php/files/fa0b854e7d2f3bed1ef1335eb94d7817/37217025360.pdf
- http://lube-stc.com/ckfinder/userfiles/files/18761233805.pdf
- http://ambulatorioveterinariovianello.eu/userfiles/files/37830000464.pdf
- http://www.oneworldkarate.com/fckeditorimages/userfiles/file/92067778543.pdf
- https://oriontradecom.com/ckfinder/userfiles/files/66461761781.pdf
- http://weilandensemble.nl/ckfinder/userfiles/files/51595349616.pdf
- https://reclamesticker.nl/images/uploads/file/
- http://tnmetalworks.com/images/files/molikokukimutirek.pdf
Embedded domains
- feedproxy.google.com
- af.ssla.ru
- chaukitchen.com
- suliaox.com
- piemonteforyou.it
- kyokushin96.ru
- www.ondebiz.com
- files.ibiza-ferien.de
- dmn.ca
- uticachemical.com
- doitsolutions.co
- argentinaproduct.com
- fullhousetourism.com
- torbay.ru
- olympusflights.com
- www.cdsale.org.au
- qualitycountscleaning.com
- lube-stc.com
- ambulatorioveterinariovianello.eu
- www.oneworldkarate.com
- oriontradecom.com
- weilandensemble.nl
- reclamesticker.nl
- tnmetalworks.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report