MALICIOUS — f28c5fa0e3c8cf7f3836afdb7af77bee04450698b45dfe9cd929b4503474fa79
MALICIOUS — f28c5fa0e3c8cf7f3836afdb7af77bee04450698b45dfe9cd929b4503474fa79 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f28c5fa0e3c8cf7f3836afdb7af77bee04450698b45dfe9cd929b4503474fa79 - SHA-1:
6539c634031a9bc06972f6f5b7a5b10e5961bd43 - MD5:
f994472b490bf35389cf91a19c53dd23 - ssdeep:
1536:g93En8ifXwQgeytvgJ5NZHkORvBJ6i1AngGfM3Up9klcWLBT2ksKzrs76VzoWApj:8U8ifAmytIJ53T/X1AMMkCTKnsiH6r - TLSH:
T17D39D0F7619FDD8C374B5B133AB6016994CAD7993272DB400688B57C8A3CA7F7A00911 - Submitted as: f28c5fa0e3c8cf7f3836afdb7af77bee04450698b45dfe9cd929b4503474fa79
- File type: pdf · Size: 85761 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.projectorrentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615f15463f0e2---nufabimiroxelivodij.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://garglob.ru/uplcv?utm_term=giant+cave+cockroach, http://schule.havonix.com/ckfinder/userfiles/files/23407427877.pdf, http://gat-asset.com/CKEdit/upload/files/pizenasamudegowamup.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://garglob.ru/uplcv?utm_term=giant+cave+cockroach
- http://schule.havonix.com/ckfinder/userfiles/files/23407427877.pdf
- http://gat-asset.com/CKEdit/upload/files/pizenasamudegowamup.pdf
- http://www.letnifestiwal.pl/ckfinder/userfiles/files/9995407663.pdf
- https://trompis-tondschungel.de/userfiles/file/veravekiwuvitubunu.pdf
- https://www.projectorrentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615f15463f0e2---nufabimiroxelivodij.pdf
- http://dailymaydemtien.com/userfiles/files/noneruposanijurokimut.pdf
- http://myslizdrave.com/soubory/62260803411.pdf
- https://specializzati.tecnaevolution.it/dataload/ckupload/dusamejemazutagojo.pdf
- https://hattshopping.com/admin/assets/images/ckfiles/merepatu.pdf
- https://leunamgroup.com/wp-content/plugins/super-forms/uploads/php/files/30f63d257815f55f4bfee06c66048e57/27918905597.pdf
- https://samsungklimalar.com/upload/ckfinder/files/35713856542.pdf
- https://mgc.to/sites/web/upload/files/81127160329.pdf
- http://revistaspontan.ro/assets/ckfinder/core/connector/php/uploads/files/xokotasawiwowu.pdf
- http://intertexmedical.com/userfiles/files/wuvofirufufalumitibaro.pdf
- https://www.la-providence-ehpad.fr/ckfinder/userfiles/files/gusomutajesudopuziza.pdf
- https://www.rt9.rspo.org/ckfinder/userfiles/files/98145434786.pdf
- http://dglytbt.com/upfolder/e/files/20210905110013.pdf
- https://mkting.com.co/wp-content/plugins/super-forms/uploads/php/files/deda0cedb56c8cdfc7317bb2ce73a8fe/18839467313.pdf
- http://satakantaresort.com/user_img/files/dujubu.pdf
- http://mamnonkitty.com/webroot/img/posts/files/wowopijorisobidavogugedol.pdf
- http://milkyway-vn.com/upload/files/67733146458.pdf
- http://epoptavky.com/is/images/FCKeditor/File/duluzuwoxafoveta.pdf
- http://cetis156.neutronds.com/assets/js/ckfinder/userfiles/files/maditinujelinebipumabon.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- garglob.ru
- schule.havonix.com
- gat-asset.com
- www.letnifestiwal.pl
- trompis-tondschungel.de
- www.projectorrentals.com
- dailymaydemtien.com
- myslizdrave.com
- specializzati.tecnaevolution.it
- hattshopping.com
- leunamgroup.com
- samsungklimalar.com
- mgc.to
- intertexmedical.com
- www.la-providence-ehpad.fr
- www.rt9.rspo.org
- dglytbt.com
- mkting.com.co
- satakantaresort.com
- mamnonkitty.com
- milkyway-vn.com
- epoptavky.com
- cetis156.neutronds.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report