MALICIOUS — e60f33d04c8de6d18d9b321799d968da408e621e234b253f9b535ae5cc7a1a5c
MALICIOUS — e60f33d04c8de6d18d9b321799d968da408e621e234b253f9b535ae5cc7a1a5c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e60f33d04c8de6d18d9b321799d968da408e621e234b253f9b535ae5cc7a1a5c - SHA-1:
248cbf1f5c920ab62f21e746efcab8343ae267bc - MD5:
84f3b4c9505fd1eb68173739a1f97dc2 - ssdeep:
1536:FGQ7GTF9Ieg3wgM7yeRtqqsjrl5W0YDd5uKqFDUlMWWspO2i4Zt:5GJOegfevqqsjrfYDd5uKqhr12nr - TLSH:
T11A37BFF760E7CD0CB79B9B43A8A6215D684ADBC45131AB51008CA76CD4BC9BFBF10A41 - Submitted as: e60f33d04c8de6d18d9b321799d968da408e621e234b253f9b535ae5cc7a1a5c
- File type: pdf · Size: 73104 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/06d58007f5a1968a2ab0e2667b2590c3/79815408990.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://irlanc.ru/uplcv?utm_term=adb+not+working, http://marathon-gexin.com/Uploadfiles/files/lijeve.pdf, http://ascensionchina.com/userfiles/file/kixitegud.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://irlanc.ru/uplcv?utm_term=adb+not+working
- http://marathon-gexin.com/Uploadfiles/files/lijeve.pdf
- http://ascensionchina.com/userfiles/file/kixitegud.pdf
- http://webinaris.eu/ckfinder/userfiles/publics/files/82062909602.pdf
- https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/06d58007f5a1968a2ab0e2667b2590c3/79815408990.pdf
- http://tofuyatogo.com/uploads/files/53470399610.pdf
- https://drticket.ir/basefile/drtiketcom/files/9621069955.pdf
- http://elskup.pl/images/assets/file/seturimivujap.pdf
- http://maezawa-jidousha.com/js/upload/files/13572419952.pdf
- http://labellebeaute.com.hk/ckfinder/userfiles/files/28222498866.pdf
- http://www.tenniscanberra.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/161437808c6ca7---bumaxifij.pdf
- http://chieusangducphat.com/uploads/userfiles/file/dawawafejavamilujaj.pdf
- https://atavio.ru/files/file/xanowup.pdf
- http://tuttotop.com/userfiles/files/dotisan.pdf
- http://studiotecnicobergamaschi.it/userfiles/files/fegobidozifisereduno.pdf
- https://rawoctane.com/uploads/file/53732842556.pdf
- https://alpasol.e-giant.net/upload/files/bipopi.pdf
- http://garantc.ru/userfiles/file/werovaseximawaludeterebu.pdf
- http://driver-jazda.pl/upload/file/14019094692.pdf
- http://icaalliance.org/filespath/files/20210919143621.pdf
- http://metamorfoza-krosno.pl/userfiles/file/84447677033.pdf
- https://www.andimoda.com/wp-content/plugins/super-forms/uploads/php/files/172814dde48e69d574d57cf5357d4499/78361293760.pdf
- http://kronospan-mofa-hungary.hu/editor_up/31323356054.pdf
- http://tsradviseurs.nl/mailing/images/photo/file/lagijubeguwisevulivuxesem.pdf
- https://www.ruchya.com.tw/upload/files/5270175002.pdf
Embedded domains
- irlanc.ru
- marathon-gexin.com
- ascensionchina.com
- webinaris.eu
- alenakovalchuk.ru
- tofuyatogo.com
- drticket.ir
- elskup.pl
- maezawa-jidousha.com
- labellebeaute.com.hk
- www.tenniscanberra.com.au
- chieusangducphat.com
- atavio.ru
- tuttotop.com
- studiotecnicobergamaschi.it
- rawoctane.com
- alpasol.e-giant.net
- garantc.ru
- driver-jazda.pl
- icaalliance.org
- metamorfoza-krosno.pl
- www.andimoda.com
- tsradviseurs.nl
- www.ruchya.com.tw
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report