MALICIOUS — ec066f94088e41c770a6384f2bd5cfeeffb0e4f6ed347178c0c46073bbb75bc4
MALICIOUS — ec066f94088e41c770a6384f2bd5cfeeffb0e4f6ed347178c0c46073bbb75bc4 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ec066f94088e41c770a6384f2bd5cfeeffb0e4f6ed347178c0c46073bbb75bc4 - SHA-1:
1f93b8ca97f1e8b81281e2a8ef6c95b3b792e71f - MD5:
f329fed8b5c887ff78c0a2d2c1083d25 - ssdeep:
1536:4kbOqwmGmLXsAhcq5WT8Lf7MyOye2KSEZvBu06OqQWHpOvTWHiBincRuQ9wyx/d:kmJPhcUvf7xDe2uZvBu0veiWcRuQbX - TLSH:
T1B238D0F321ABDD4C7B8F9B4768EB129C558AE2846532DB600088767D96BC6FD7E00601 - Submitted as: ec066f94088e41c770a6384f2bd5cfeeffb0e4f6ed347178c0c46073bbb75bc4
- File type: pdf · Size: 79853 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://hani-bee.com/userfiles/files/sakiganugivar.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://allytemp.ru/uplcv?utm_term=happy+sunday+hd+images, http://vagtteam.com/userfiles/Files/bulerawisisurazodel.pdf, http://lncxjzxxw.com/upload_fck/file/2021-9-15/20210915144505859275.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://allytemp.ru/uplcv?utm_term=happy+sunday+hd+images
- http://vagtteam.com/userfiles/Files/bulerawisisurazodel.pdf
- http://lncxjzxxw.com/upload_fck/file/2021-9-15/20210915144505859275.pdf
- https://netlandschool.cl/files/37831932787.pdf
- http://odumakus.com/uploads/files/wonexizapodaniv.pdf
- https://kasihpaham.com/contents/files/96256934574.pdf
- http://hoanggiaphatland.com/uploads/image/files/28911702137.pdf
- http://technoauto.jp/js/upload/files/674905788.pdf
- http://chanhungcorp.com/images/uploads/files/seroxumak.pdf
- http://hani-bee.com/userfiles/files/sakiganugivar.pdf
- https://szamitogep-szerviz-javitas.hu/ckfinder/userfiles/files/18362399541.pdf
- http://vimbark.sk/editor_uploads/files/golozozilutosatenenewev.pdf
- https://bnovum.hu/downloads/fewezaneb.pdf
- http://yuqiaohome.com/uploads/files/202109181714321110.pdf
- http://clingac.com/d/files/10358131870.pdf
- http://soft-pro.hr/upload/datoteke/fiziderosonedipigiwanume.pdf
- http://urbanelect.com/userfiles/file/22066361792.pdf
- https://xylemleads.com/userfiles/file/41200926444.pdf
- https://excore.hu/ckfinder/userfiles/files/80517695040.pdf
- https://cottonweb.net/userfiles/file/kafidirapekavotenexutig.pdf
- http://myucmas.com/userfiles/file/kotezuxosuwefoduru.pdf
- http://yjccnc.com/upload/files/lasakinavexavenupipufa.pdf
- http://93564497.com/userfiles/90682393817.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- allytemp.ru
- vagtteam.com
- lncxjzxxw.com
- odumakus.com
- kasihpaham.com
- hoanggiaphatland.com
- technoauto.jp
- chanhungcorp.com
- hani-bee.com
- yuqiaohome.com
- clingac.com
- urbanelect.com
- xylemleads.com
- cottonweb.net
- myucmas.com
- yjccnc.com
- 93564497.com
- www.w3.org
- purl.org
- ns.adobe.com
- netlandschool.cl
- szamitogep-szerviz-javitas.hu
- vimbark.sk
- bnovum.hu
- soft-pro.hr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report