MALICIOUS — dfa330fef905d6453b81287ba9b8f53bf3f460db85b961d91a2754935dcc34de
MALICIOUS — dfa330fef905d6453b81287ba9b8f53bf3f460db85b961d91a2754935dcc34de is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dfa330fef905d6453b81287ba9b8f53bf3f460db85b961d91a2754935dcc34de - SHA-1:
3412ce3ce30a43cfaec95dc4d77cdbc8cd20c653 - MD5:
eefd62ffe72c44f440d8c3436350e0c4 - ssdeep:
1536:lNlfJioVdjazW35cdRslUDWGpOKCWHZlpPA+ZN2:3VRVdj/5URslUkK7lp4+G - TLSH:
T10637BFF36197DD9CB79A8F0399BB03A8A48AC78D6162D760084CBB6C84BC57D7F40580 - Submitted as: dfa330fef905d6453b81287ba9b8f53bf3f460db85b961d91a2754935dcc34de
- File type: pdf · Size: 70258 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://associatedreclaimed.reclaimedoils.com/userfiles/files/denipulexitadomenu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://garglob.ru/uplcv?utm_term=nfs+no+limits+offline+mod+apk, http://pharmorgsyn.com/upload/files/95593198035.pdf, http://www.masozilina.sk/ckfinder/userfiles/files/vofalikejunujuvu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://garglob.ru/uplcv?utm_term=nfs+no+limits+offline+mod+apk
- http://pharmorgsyn.com/upload/files/95593198035.pdf
- http://www.masozilina.sk/ckfinder/userfiles/files/vofalikejunujuvu.pdf
- https://reaga.net/js/ckfinder/userfiles/files/10298228535.pdf
- https://euronuts2009.ge/files/files/valavovapukovumesotilimi.pdf
- https://sca-eagleegg5k.com/ckfinder/triplebuserfiles/file/91679332027.pdf
- http://associatedreclaimed.reclaimedoils.com/userfiles/files/denipulexitadomenu.pdf
- http://chataphan.com/file_media/file_image/file/dutigasuputiwuduza.pdf
- https://pre-www.bridge-college.com/uploaded/ckeditor/files/44064307690.pdf
- http://misr-consult.com/userfiles/file/rugurazasejozekave.pdf
- http://yokohama-model.com/userfiles/files/22599805665.pdf
- https://www.adler-leitishofen.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613a408abf43b---mesuk.pdf
- http://instant-image.net/UserFiles/Site/File/96975670595.pdf
- https://magatek.com/documents/file/11475717560.pdf
- http://snailgame.ru/upload/files/20210919185922.pdf
- http://kotrackusa.com/fckedit_file/file///20210910_15_3_9.pdf
- http://tutaylamhet.com/storage/ckfinder/files/7350181300.pdf
- https://www.aaptuk.org/ckfinder/userfiles/files/jemaruwuvetikorebixef.pdf
- http://firesecurity.sk/userfiles/file/terapekon.pdf
- http://fajni3333.fun4two.pl/uploads/assets/file/pupopipapizu.pdf
- http://systempro.kr/userData/board/file/suderufitezofimavide.pdf
- http://lisahyatthealth.com/wp-content/plugins/formcraft/file-upload/server/content/files/161350c11a22ec---19798047712.pdf
- https://web-sila.ru/wp-content/plugins/super-forms/uploads/php/files/f0d2d92bfe2523869b774d5c6070986b/jubodebepawek.pdf
- https://anandamsanyal.com/userfiles/file/nuxanozajuturewupe.pdf
- https://majubesar.com/contents/files/wudowuz.pdf
Embedded domains
- garglob.ru
- pharmorgsyn.com
- reaga.net
- sca-eagleegg5k.com
- associatedreclaimed.reclaimedoils.com
- chataphan.com
- pre-www.bridge-college.com
- misr-consult.com
- yokohama-model.com
- www.adler-leitishofen.de
- instant-image.net
- magatek.com
- snailgame.ru
- kotrackusa.com
- tutaylamhet.com
- www.aaptuk.org
- fajni3333.fun4two.pl
- systempro.kr
- lisahyatthealth.com
- web-sila.ru
- anandamsanyal.com
- majubesar.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report