MALICIOUS — e9df533d8e790be991744d8e375b9baffc499744ded510def06ecb275fb70149
MALICIOUS — e9df533d8e790be991744d8e375b9baffc499744ded510def06ecb275fb70149 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e9df533d8e790be991744d8e375b9baffc499744ded510def06ecb275fb70149 - SHA-1:
d5e25b39ae13ddb8e05ea5de73d9d6a1daf1a06f - MD5:
399d9d64faebc93083c1ceb2868bb556 - ssdeep:
1536:HFwi5sJj2aGJzkTMHshzhhEXXxBe3MOu3v3UQydDmxbi/WOpOaZEW8fU4cR17c:lwiejxGmSslgBe34j0ebiQaZlR1o - TLSH:
T19038E0F3518BDD5C7F5BAB5336BF115A948AE34C106AE610850CA30CE2FC97CAE00695 - Submitted as: e9df533d8e790be991744d8e375b9baffc499744ded510def06ecb275fb70149
- File type: pdf · Size: 82356 bytes
- Verdict: malicious (94/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://equantumconsulting.com/files/files/75020695716.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=how+to+select+words+in+pdf, http://universalgroupautos.com/files/others/30678871050.pdf, https://oxfordjsr.com/userfiles/file/54987654050.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=how+to+select+words+in+pdf
- http://universalgroupautos.com/files/others/30678871050.pdf
- https://oxfordjsr.com/userfiles/file/54987654050.pdf
- http://www.fliesen-brill.de/wp-content/plugins/formcraft/file-upload/server/content/files/1615416c14277f---63246175574.pdf
- https://segurosjdd.com/wp-content/plugins/super-forms/uploads/php/files/trur197fqd29jsja7qt46nat53/mabopuzironev.pdf
- https://equantumconsulting.com/files/files/75020695716.pdf
- https://marblo.ph/app/webroot/img/files/pumobodizawub.pdf
- http://canadanur.com/resimler/files/pozagulesoji.pdf
- https://speedwayinfo.hu/uploads/file/nuxajasadodolojikonufe.pdf
- https://afma.pt/site/upload/file/nakexiwusidajukejewur.pdf
- https://semangkamerah.com/contents/files/80039806711.pdf
- https://doina.md/fckeditorfiles/file/29535795570.pdf
- https://micro-logic.ro/images/uploaded/file/89016499381.pdf
- http://pune-india.info/userfiles/file/14491685935.pdf
- http://nhatminhtrading.vn/app/webroot/uploads/files/vavedisokojenapixagitop.pdf
- https://tidaksusah.com/contents/files/12587222004.pdf
- https://iwanbim.com/userfiles/files/naminaminogiw.pdf
- http://klubalfa.org/img/userfiles/file/16080639327.pdf
- http://tvcsoltau.de/userfiles/file/xozurorafidovuxo.pdf
- http://compow.net/ckfinder/userfiles/files/daxumunabusupetivixu.pdf
- http://rtm-plus.com/ckfinder/userfiles/files/32668023384.pdf
- https://borgopitti.it/userfiles/file/3775555768.pdf
- https://apc-algercentre.dz/ckfinder/userfiles/files/70751737800.pdf
Embedded domains
- crysiq.ru
- universalgroupautos.com
- oxfordjsr.com
- www.fliesen-brill.de
- segurosjdd.com
- equantumconsulting.com
- canadanur.com
- semangkamerah.com
- pune-india.info
- tidaksusah.com
- iwanbim.com
- klubalfa.org
- tvcsoltau.de
- compow.net
- rtm-plus.com
- borgopitti.it
- marblo.ph
- speedwayinfo.hu
- afma.pt
- doina.md
- micro-logic.ro
- nhatminhtrading.vn
- apc-algercentre.dz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report