MALICIOUS — dd2d27572e2fad822cb814b72a419a21f4ffc47651315715862417cc4527b502
MALICIOUS — dd2d27572e2fad822cb814b72a419a21f4ffc47651315715862417cc4527b502 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dd2d27572e2fad822cb814b72a419a21f4ffc47651315715862417cc4527b502 - SHA-1:
d40e93e5404ae5566badb886a4424d104e1aa502 - MD5:
27c1fd624537d5db08b37e7f264fc18f - ssdeep:
1536:bXP2rTXTRMPL38wSQbfAnWNQS2UsMEAWJz8K2mcZWspO2tT7:r2rOPL3/PrAKQSbEBAKM425 - TLSH:
T17C37B0F361EBDC4CB74A9B4339EA111890CED74C22B2E7504489BA6C957C9BDBF04A50 - Submitted as: dd2d27572e2fad822cb814b72a419a21f4ffc47651315715862417cc4527b502
- File type: pdf · Size: 72043 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://pasted-radio.de/web/files/92096034809.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://htcpost.vn/vietpost.vn/img_content/file/jumoguwepired.pdf, http://trainternational.in/wp-content/plugins/formcraft/file-upload/server/content/files/16147bd81e2e69---33941481765.pdf, http://pasted-radio.de/web/files/92096034809.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/DOqCt-cVA4I/uplcv?utm_term=youtube+video+for+android
- https://htcpost.vn/vietpost.vn/img_content/file/jumoguwepired.pdf
- http://trainternational.in/wp-content/plugins/formcraft/file-upload/server/content/files/16147bd81e2e69---33941481765.pdf
- http://pasted-radio.de/web/files/92096034809.pdf
- https://iva-vietnam.com/userfiles/file/18935752432.pdf
- https://ag-concept.ru/wp-content/plugins/super-forms/uploads/php/files/05049fc35ddf15e35b289403b7f0c50a/tiwojumagovafuzukixo.pdf
- https://imaggu.com/ci/userfiles/files/20544836203.pdf
- http://salonorganica.ru/upload/files/jiwofimawelaba.pdf
- https://byocamacho.com/ckfinder/userfiles/files/41845714557.pdf
- http://kolesnikov.pro/ckfinder/userfiles/files/77326362058.pdf
- http://lagostena.it/userfiles/files/78496300292.pdf
- http://hotel-gerard-dalsace.com/upload/document/59013501.pdf
- https://ladychief.com/wp-content/plugins/super-forms/uploads/php/files/1ccf24ce6070600fd0236e311461e09c/44522979286.pdf
- https://thic.muki001.com/plugin/ce1/ckfinder/userfiles/files/zokebepaj.pdf
- http://nanoservice.cz/upload/file/10199645147.pdf
- http://kowel.com/ckfinder/userfiles/files/1632329210.pdf
- https://kimcert.org/E/file/matimapawebi.pdf
- http://profstil.az/userfiles/file/bofozulonure.pdf
- http://change4best.ru/upload/file/96329021771.pdf
- https://iwistw.com/upload/files/15496242388.pdf
- https://ariaparvaz.com/basefile/ariaparvazcom/files/25542353106.pdf
- http://wagnerpc.com/userfiles/files/gimubolijuvijije.pdf
- http://uralcomservis.ru/crn_fls/crn_files/lujadurafigijisofexanokej.pdf
- http://skkl.cn/filespath/files/20210919164818.pdf
- https://rendszergazda-cegeknek.hu/ckfinder/userfiles/files/duguwusaguruzibuzisitofil.pdf
Embedded domains
- feedproxy.google.com
- trainternational.in
- pasted-radio.de
- iva-vietnam.com
- ag-concept.ru
- imaggu.com
- salonorganica.ru
- byocamacho.com
- kolesnikov.pro
- lagostena.it
- hotel-gerard-dalsace.com
- ladychief.com
- thic.muki001.com
- kowel.com
- kimcert.org
- change4best.ru
- iwistw.com
- ariaparvaz.com
- wagnerpc.com
- uralcomservis.ru
- skkl.cn
- www.w3.org
- purl.org
- ns.adobe.com
- htcpost.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report