MALICIOUS — ddf5ca67dddfe6f50c11ebc8966fce603ef68ea1df85083e03433b21aa1aabe9
MALICIOUS — ddf5ca67dddfe6f50c11ebc8966fce603ef68ea1df85083e03433b21aa1aabe9 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ddf5ca67dddfe6f50c11ebc8966fce603ef68ea1df85083e03433b21aa1aabe9 - SHA-1:
1073003944c5e48322301a6d10772a1d97bd105d - MD5:
e4c39654ddab45b69b9b2d1cf1567046 - ssdeep:
1536:zItntSSs+z5eWm2p0Wea2a20BSnusiHWQpOCoWBZn613EdMV:mtSb392pXeapnNsiyCRZn6ZEM - TLSH:
T13B38C0F361DFCD4C768B5F436AA6126CB08BD3846266DA904088FF6CD8785BD7A10711 - Submitted as: ddf5ca67dddfe6f50c11ebc8966fce603ef68ea1df85083e03433b21aa1aabe9
- File type: pdf · Size: 76838 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://sgicorp.com/userfiles/files/5685620733.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=pdf+stories+for+grade+4, https://sgicorp.com/userfiles/files/5685620733.pdf, http://almar-bus.pl/userfiles/file/segebefodex.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pistant.ru/uplcv?utm_term=pdf+stories+for+grade+4
- https://sgicorp.com/userfiles/files/5685620733.pdf
- http://almar-bus.pl/userfiles/file/segebefodex.pdf
- http://detikakdeti.ru/img/file/44022026666.pdf
- https://digireg.dk/upload/8105238637.pdf
- http://www.elsecretodelolivo.com/wp-content/plugins/formcraft/file-upload/server/content/files/161515d1853fd5---39196417642.pdf
- http://dglytbt.com/upfolder/e/files/20211005112544.pdf
- https://careerroots.net/ckfinder/userfiles/files/54369252183.pdf
- http://africansafaris-spain.com/FCKeditor/editor/filemanager/connectors/php/connector.php?Command=FileUpload&Type=File&CurrentFolder=%2Ffile/42742903881.pdf
- http://thelonerangerfanclub.com/ckfinder/userfiles/files/gunokiduxukifofotobi.pdf
- http://www.platformliften.info/wp-content/plugins/formcraft/file-upload/server/content/files/1613cfd515f150---18742834581.pdf
- http://m3hotels.com/userfiles/file/powen.pdf
- http://visualpaint.com/wp-content/plugins/formcraft/file-upload/server/content/files/16159c62082ff7---12535847803.pdf
- http://swvocal.com/data/se2/file/30661959445.pdf
- http://dent-pro.cz/pic/file/voxanutapotikezusi.pdf
- http://gazomotor.com/allinone/file/fuwowodenuzised.pdf
- http://www.santamyoga.be/images/file/tukoxotare.pdf
- https://faktxeber.com/resimler/files/18714235997.pdf
- http://ambulatorioveterinarioilprato.eu/userfiles/files/42908632654.pdf
- http://jakpaisanestate.com/images/upload/files/gijomegewod.pdf
- https://fidelishospice.com/ckfinder/userfiles/files/wowipasezaj.pdf
- http://www.kinoimaging.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16156b15d2de9b---kuxaxaxevavaxel.pdf
- https://ntct.dz/ckfinder/userfiles/files/kaber.pdf
- http://www.msjcongregation.org/www/js/ckfinder/userfiles/files/39700242529.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- pistant.ru
- sgicorp.com
- almar-bus.pl
- detikakdeti.ru
- www.elsecretodelolivo.com
- dglytbt.com
- careerroots.net
- africansafaris-spain.com
- thelonerangerfanclub.com
- www.platformliften.info
- m3hotels.com
- visualpaint.com
- swvocal.com
- gazomotor.com
- www.santamyoga.be
- faktxeber.com
- ambulatorioveterinarioilprato.eu
- jakpaisanestate.com
- fidelishospice.com
- www.kinoimaging.nl
- www.msjcongregation.org
- www.w3.org
- purl.org
- ns.adobe.com
- digireg.dk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report