MALICIOUS — e5da57f1b94163ca6daedf31eb66e45d662ef064fb0eaccaa9e6be1554342693
MALICIOUS — e5da57f1b94163ca6daedf31eb66e45d662ef064fb0eaccaa9e6be1554342693 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e5da57f1b94163ca6daedf31eb66e45d662ef064fb0eaccaa9e6be1554342693 - SHA-1:
bb514e9e7d7992a5f9c63b67002c72f096e500ee - MD5:
e76ca05af1a6809974bdda49f167a00d - ssdeep:
1536:9SgT5DCNRWOtIDwxaN2g+zWOpOaZgyfeWoU7dH4xpymO:JTNCj10gaNNBaZDf+FpW - TLSH:
T15B37BFE76097DD8C3B8FEB436DB71058548AD3855272FBA00088B3BD967C53DAE60681 - Submitted as: e5da57f1b94163ca6daedf31eb66e45d662ef064fb0eaccaa9e6be1554342693
- File type: pdf · Size: 70314 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://mebelhotel.ru/userfiles/files/vanamuwetu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://jedzenie365.pl/ckfinder/userfiles/files/94898133814.pdf, https://www.booster-p.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615046d6df787---tigirivedaritudimop.pdf, https://villanakarin.com/userfiles/files/jowunoxekupasa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/PmAiG5ZyT-k/uplcv?utm_term=positive+letters+that+start+with+a
- http://jedzenie365.pl/ckfinder/userfiles/files/94898133814.pdf
- https://www.booster-p.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615046d6df787---tigirivedaritudimop.pdf
- https://villanakarin.com/userfiles/files/jowunoxekupasa.pdf
- http://kasaitogo.com/uploads/files/57067976607.pdf
- http://musik-fachberatung-neumarkt.de/images/uploadedimages/file/79267630343.pdf
- http://scuderia512.com/js/upload/files/wujuludibi.pdf
- http://konditsionery-odincovo.ru/upload_picture/file/79576089493.pdf
- http://mebelhotel.ru/userfiles/files/vanamuwetu.pdf
- http://atmaircenter.com/lb/userfiles/files/45003789599.pdf
- http://princeverma.in/uploads/files/56990968894.pdf
- https://oasis-travel.ro/files/fuxokararugig.pdf
- http://www.ssc-ras.ru/ckfinder/userfiles/files/79325738468.pdf
- https://jatransfer.com/userfiles/file/14039787448.pdf
- http://studiotecnicoligioni.com/userfiles/files/luzarepasawabadaf.pdf
- https://www.medicalbi.com/ckfinder/userfiles/files/puzenex.pdf
- http://www.goldenlantern.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1614f208f23eaa---togasamugudukigos.pdf
- http://shouquan.scarclinic-cn.com/uploadfile/file///602408503.pdf
- http://www.sbawerribee.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1613315dc0b46a---95146983212.pdf
- http://www.orarestauratorisaf.it/wp-content/plugins/formcraft/file-upload/server/content/files/1613205544b7a9---gajijujuwelad.pdf
- http://jatyn.cn/upfiles/202109/file/1631596509.pdf
- http://sicilalluminio.it/userfiles/files/gubetesemekub.pdf
- http://flyingwedge.com/uploads/assets/file/29927071883.pdf
- http://partiaweb.ir/upload/files/woxefokorezikevag.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- jedzenie365.pl
- www.booster-p.com
- villanakarin.com
- kasaitogo.com
- musik-fachberatung-neumarkt.de
- scuderia512.com
- konditsionery-odincovo.ru
- mebelhotel.ru
- atmaircenter.com
- princeverma.in
- www.ssc-ras.ru
- jatransfer.com
- studiotecnicoligioni.com
- www.medicalbi.com
- www.goldenlantern.co.za
- shouquan.scarclinic-cn.com
- www.sbawerribee.com.au
- www.orarestauratorisaf.it
- jatyn.cn
- sicilalluminio.it
- flyingwedge.com
- partiaweb.ir
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report