MALICIOUS — df8a1ef304e0856821032638fb8931defa3c18aa9baa363a1c7f7f59baf61e95
MALICIOUS — df8a1ef304e0856821032638fb8931defa3c18aa9baa363a1c7f7f59baf61e95 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
df8a1ef304e0856821032638fb8931defa3c18aa9baa363a1c7f7f59baf61e95 - SHA-1:
6be93dbb5535e4c63b9167e64d7b55ee2b9566f3 - MD5:
d099ba5bbd07062cd469723aab4e1baa - ssdeep:
1536:Fk/nQn4zhTaumLq+0IthezmnjImJDeG8gpxp1lQWvT8bFjJFerrW8pO7M:O/Qn1xjh3jImF/1T8bter27M - TLSH:
T17838E0F321E7EE5CBB8FCB036DA71294A44DE7C8B491EA40518C2665C0DC8BE7D64611 - Submitted as: df8a1ef304e0856821032638fb8931defa3c18aa9baa363a1c7f7f59baf61e95
- File type: pdf · Size: 76654 bytes
- Verdict: malicious (94/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://washlounge.in/ckfinder/userfiles/files/fipewubemetezekenomuzome.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://washlounge.in/ckfinder/userfiles/files/fipewubemetezekenomuzome.pdf, https://www.displaysdirectaustralia.com.au/application/third_party/ckfinder/userfiles/files/sevetuguwutixebadiga.pdf, https://www.digitalsofts.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132d73ad046e---8879314415.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/Xvkpad/~3/u-9XGpgKpwY/uplcv?utm_term=sturdevant%27s+art+and+science+of+operative+dentistry+6th+edition+pdf
- https://washlounge.in/ckfinder/userfiles/files/fipewubemetezekenomuzome.pdf
- https://www.displaysdirectaustralia.com.au/application/third_party/ckfinder/userfiles/files/sevetuguwutixebadiga.pdf
- https://www.digitalsofts.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132d73ad046e---8879314415.pdf
- http://telegid.tv/userfiles/file/66338898339.pdf
- http://bjhtdszdh.com/v15/Upload/file/2021919717197298.pdf
- http://telegid.tv/userfiles/file/pisowipewowudafire.pdf
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/161328119e1442---40595857174.pdf
- http://angelescare.com/userfiles/file/derivamupuliraxexojo.pdf
- http://timandlor.com/userfiles/file/15918432087.pdf
- https://saintarseny.ca/sites/saintarseny.ca/files/file/71702005995.pdf
- http://c-six.it/userfiles/files/gakenovaxipigatewofidob.pdf
- http://studioesflores.pl/obrazy/file/dusozulizateraxel.pdf
- https://cissud.com/uploads/ck_editor/files/betujawawixasozajewun.pdf
- https://thucphamtruongxanh.com/Upload/files/49207207871.pdf
- http://vejwun.cz/images/minipidexapirogovejokesej.pdf
- https://stephan-kratt.de/data/reiterhof/userfiles/file/guwipugigowidulojus.pdf
- https://eghamatyab.com/basefile/bainbookcom/files/36282557008.pdf
- https://astefin.ro/ckfinder/userfiles/files/69266101499.pdf
- http://olympusflights.com/files/files/72512379766.pdf
- http://ciaooo.ru/uploades/userfiles/file/kikamewuletazuziwekivixus.pdf
- https://www.rath-catering.de/wp-content/plugins/formcraft/file-upload/server/content/files/16148b52e2b12e---29054097306.pdf
- http://dichvuhangngay.vn/uploads/image/files/42672040912.pdf
- http://www.novosib-sport.ru/ckfinder/userfiles/files/96957764166.pdf
- http://tumakuruvoice.com/tumkurvoice/ckeditor/ckfinder/userfiles/files/ruzawejanekalet.pdf
Embedded domains
- feedproxy.google.com
- washlounge.in
- www.displaysdirectaustralia.com.au
- www.digitalsofts.com
- telegid.tv
- bjhtdszdh.com
- kaufdeinauto.de
- angelescare.com
- timandlor.com
- saintarseny.ca
- c-six.it
- studioesflores.pl
- cissud.com
- thucphamtruongxanh.com
- stephan-kratt.de
- eghamatyab.com
- olympusflights.com
- ciaooo.ru
- www.rath-catering.de
- www.novosib-sport.ru
- tumakuruvoice.com
- www.1000ena.com
- blackhorsesc.pl
- vejwun.cz
- astefin.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report