MALICIOUS — f6892f948057e3153d256fdb3b752d6a1a523abf853590dec425e2acbf696a19
MALICIOUS — f6892f948057e3153d256fdb3b752d6a1a523abf853590dec425e2acbf696a19 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f6892f948057e3153d256fdb3b752d6a1a523abf853590dec425e2acbf696a19 - SHA-1:
ff46e7aa377b4aa5124e7225640ec815d538410b - MD5:
0e669c0677cb5417672070d8011e5da6 - ssdeep:
1536:FZdi4/DEfA3rSMY9DqG99Zb2zKcDvC2WapOtQHWqwtdkYboPDJu:E5foGMYpf9Zb2zxCLtQPwtdkYsPc - TLSH:
T1E637BFF710E7DE4CB7479F836DAB21ADB486D7897221AA604084767CC9BC57E6F00A01 - Submitted as: f6892f948057e3153d256fdb3b752d6a1a523abf853590dec425e2acbf696a19
- File type: pdf · Size: 72760 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://npk-bypassdrr2.com/file_media/file_image/file/59942981481.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://bya-ingenieria.com/ckfinder/userfiles/files/51436391469.pdf, http://aligokdemir.com/resimler/files/41995736028.pdf, https://bvphcn.bdata.vn/upload/files/75379460025.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/GLLx1DTH0VQ/uplcv?utm_term=video+live+wallpaper+video+wallpaper+maker+apk
- https://bya-ingenieria.com/ckfinder/userfiles/files/51436391469.pdf
- http://aligokdemir.com/resimler/files/41995736028.pdf
- https://bvphcn.bdata.vn/upload/files/75379460025.pdf
- https://globalybm.com/ckfinder/userfiles/files/1630975729.pdf
- http://npk-bypassdrr2.com/file_media/file_image/file/59942981481.pdf
- http://immobilieninvestors.de/userfiles/file/1333207109.pdf
- https://zniczekowalczyk.com/user_images/file/9066081030.pdf
- https://mptradingcompany.com/userfiles/file/23224045750.pdf
- http://aa-nusd.jp/roxifujusoj.pdf
- http://gamaxmotor.cz/data/dokumenty/93081123894.pdf
- https://www.lorenzofranzone.it/wp-content/plugins/super-forms/uploads/php/files/9bf8420b1045e3996e6b684ebd51d575/20630283818.pdf
- https://vadihosting.com/calisma2/files/uploads/55837096359.pdf
- http://munnarteabungalows.com/userfiles/file/40640721048.pdf
- http://dlugopis.kbo.pl/ckfinder/userfiles/files/muregogejo.pdf
- http://charugarware.com/DEVELOPMENT/charu_garware/uploaded/userfiles/file/tegavusivev.pdf
- https://reviewz.eu/app/webroot/files/userfiles/files/91070695134.pdf
- http://encino.kopanramen.com/uploads/files/60321122439.pdf
- https://eniedu.com/data/file/20210914131849.pdf
- https://www.etbsupplies.com/wp-content/plugins/formcraft/file-upload/server/content/files/16145364c96745---54934565516.pdf
- http://markaz-e-durood.com/EditorImages/file/85082086820.pdf
- https://whitelightdesign.com/wp-content/plugins/super-forms/uploads/php/files/c98351d9c850bdd8886c62009531d507/35409268671.pdf
- http://apsencollege.org/test/fckeditor/file/38053455465.pdf
- https://web-sila.ru/wp-content/plugins/super-forms/uploads/php/files/a24e1eb9728fe6197795b7f0077655b6/13469671658.pdf
- http://rustproofingottawa.com/userfiles/file/341436396.pdf
Embedded domains
- feedproxy.google.com
- bya-ingenieria.com
- aligokdemir.com
- globalybm.com
- npk-bypassdrr2.com
- immobilieninvestors.de
- zniczekowalczyk.com
- mptradingcompany.com
- aa-nusd.jp
- www.lorenzofranzone.it
- vadihosting.com
- munnarteabungalows.com
- dlugopis.kbo.pl
- charugarware.com
- reviewz.eu
- encino.kopanramen.com
- eniedu.com
- www.etbsupplies.com
- markaz-e-durood.com
- whitelightdesign.com
- apsencollege.org
- web-sila.ru
- rustproofingottawa.com
- tinavaron.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report