MALICIOUS — ef977046c0f382761bccb1192368aa62a735fee8d128b6e5e4697a59b6c558ac
MALICIOUS — ef977046c0f382761bccb1192368aa62a735fee8d128b6e5e4697a59b6c558ac is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ef977046c0f382761bccb1192368aa62a735fee8d128b6e5e4697a59b6c558ac - SHA-1:
1e96f14befab98ef8b1fdc181e8b0a4992860f03 - MD5:
3c86871122068cfc2b9287f6ca72f54e - ssdeep:
1536:fn6XuE+blSe5JHr+6e007JRsU7dQsdWvHHftQWGpOKCWbGNRO/PXBR34dHS:f61AL+A07JRsts4vHHfzKRZ/PXf34U - TLSH:
T1C338CFF3109BDE4C7A9B9F1368F751AD608AE7493172EB904588A93C827C6BE7F10501 - Submitted as: ef977046c0f382761bccb1192368aa62a735fee8d128b6e5e4697a59b6c558ac
- File type: pdf · Size: 79307 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://nikkenj.com/userfiles/file/93977892147.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://finsura-lifedirect.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/161412578986fa---vobak.pdf, http://goang-hann.com/uploads/files/202109042120412105.pdf, http://a1-automotivegroup.com/upload/files/rigadipisepufevi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/Om9ozkHLxGw/uplcv?utm_term=nzqa+organic+chemistry+level+2
- http://finsura-lifedirect.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/161412578986fa---vobak.pdf
- http://goang-hann.com/uploads/files/202109042120412105.pdf
- http://a1-automotivegroup.com/upload/files/rigadipisepufevi.pdf
- http://nikkenj.com/userfiles/file/93977892147.pdf
- http://totaleclipsenv.com/wp-content/plugins/formcraft/file-upload/server/content/files/16130a2c356c66---kekojaduvibi.pdf
- http://cecev.com/stockages/files/14964202514.pdf
- https://www.prowallpanama.com/wp-content/plugins/super-forms/uploads/php/files/5c4749889c97f6332b8ed789aa4eb0dd/67875114250.pdf
- http://cambridgekapurthala.com/damana/userfiles/file/nokusulitebijagiduvanirom.pdf
- http://fishngrill.iorderfoods.com/uploads/files/34196829513.pdf
- http://gardena.crazyrockinsushi.com/uploads/files/balilojitamofadokepon.pdf
- https://gaadalagi.com/contents/files/71694312288.pdf
- https://jotelek.hu/files/file/barakaxesesuwigekadus.pdf
- https://playgametoday.ru/wp-content/plugins/super-forms/uploads/php/files/5c975ecbd41c6a751951ad1e4332f753/51346330294.pdf
- http://bikaji.zohukum.com/ckfinder/userfiles/files/tipijemirowejawisufajoxu.pdf
- http://www.afamaresme.org/wp-content/plugins/formcraft/file-upload/server/content/files/161449dabd3db8---nujubotujozugigoxoruluva.pdf
- http://www.iciparis.ru/ckfinder/userfiles/files/guwafonaxotalowoxumuba.pdf
- http://decamiones.com/userfiles/file/45736967401.pdf
- http://biomehl.com/images/content/files/tipawemiruwalisezinadiva.pdf
- https://caribemed.com/userfiles/file/pepawepu.pdf
- http://jmvlpslimited.com/ci/userfiles/files/76089750526.pdf
- http://brandorbit.in/userfiles/file/41622625788.pdf
- http://vidol.eu/userfiles/file/vetese.pdf
- http://1night2daytour.com/ckupload/files/nubujotivatizikadega.pdf
- http://www.firengo.com/userfiles/files/7255131114.pdf
Embedded domains
- feedproxy.google.com
- finsura-lifedirect.com.au
- goang-hann.com
- a1-automotivegroup.com
- nikkenj.com
- totaleclipsenv.com
- cecev.com
- www.prowallpanama.com
- cambridgekapurthala.com
- fishngrill.iorderfoods.com
- gardena.crazyrockinsushi.com
- gaadalagi.com
- playgametoday.ru
- bikaji.zohukum.com
- www.afamaresme.org
- www.iciparis.ru
- decamiones.com
- biomehl.com
- caribemed.com
- jmvlpslimited.com
- brandorbit.in
- vidol.eu
- 1night2daytour.com
- www.firengo.com
- oryginalnedekoracje.pl
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report