MALICIOUS — f770abdb1305117972e6c51195bb7f8d888ae5ddcd578158fc745c1062391ddc
MALICIOUS — f770abdb1305117972e6c51195bb7f8d888ae5ddcd578158fc745c1062391ddc is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f770abdb1305117972e6c51195bb7f8d888ae5ddcd578158fc745c1062391ddc - SHA-1:
69278416c62c919bef2386609706e14e833a2edb - MD5:
56a4e5e555667bc8e44153f1cabb7728 - ssdeep:
1536:cqn9p5O8TrqHL1UPekvivMdT1SWXzu7WGlKxfwWQpOCKpA2YA:HvOhUPe8UqeBKxffCKC6 - TLSH:
T18538CFF36197ED5C724B9B1759F601ADA48AD6C42022EB504088FBBCC57C9BEFE10990 - Submitted as: f770abdb1305117972e6c51195bb7f8d888ae5ddcd578158fc745c1062391ddc
- File type: pdf · Size: 83183 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://connect-event.fr/ckfinder/userfiles/files/laxojemilujetuteloxakuk.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=how+the+modern+method+of+irrigation+are+more+water+efficient+than+the+traditional+ones, http://mutamobilya.com/images_upload/files/buletemotaxidivunoruvadi.pdf, https://adlinefor.com/home/webagen/public_html/korn/data/file/64412456010.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=how+the+modern+method+of+irrigation+are+more+water+efficient+than+the+traditional+ones
- http://mutamobilya.com/images_upload/files/buletemotaxidivunoruvadi.pdf
- https://adlinefor.com/home/webagen/public_html/korn/data/file/64412456010.pdf
- http://energosol.pl/images_cms/file/73906325444.pdf
- http://st-johnson.com/Uploadfiles/files/34060424216.pdf
- https://maychieuvinh.vn/upload/files/lukuwumixuwugoroze.pdf
- https://callhfelectric.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613dbf50bf5ec---2349266620.pdf
- http://connect-event.fr/ckfinder/userfiles/files/laxojemilujetuteloxakuk.pdf
- http://ombs.ru/uploads/files/48979007422.pdf
- http://wxeina.com/userfiles/files/3173292669.pdf
- http://dep14kirov.ru/userfiles/file/82413903446.pdf
- http://sea-cruise.ru/ckfinder/userfiles/files/wapobesoluxorenozugoru.pdf
- https://universitecentrale.net/uploads/FCK_files/file/jorozowo.pdf
- http://decaldankinh.net/upload/files/34137419514.pdf
- http://studiogiovannone.com/userfiles/files/muxadodatiferezumem.pdf
- http://charolais-hessen.de/write/userfiles/file/pugapupu.pdf
- https://alcoquimicos.com/ckfinder/userfiles/files/507879590.pdf
- http://puebloexec.com/userfiles/file/39620104208.pdf
- http://langeline.com/ckeditor/upload/files/gubevuluxoralupikojigetag.pdf
- http://wjcopy.com/upload/files/74834237392.pdf
- http://s-pack.kr/userfiles/file/20210912175834.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/6934v8eug8eoisepn7tlrmf547/41891510881.pdf
- http://www.cddfct.com/up_files/file/xunewaraziwer.pdf
- http://extreamtuning.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1614557b5aba3f---daxoderusivomoso.pdf
- https://kantankacreative.com/wp-content/plugins/super-forms/uploads/php/files/fc0f3ebe62b619d8d1fc4fb2be816457/guremowopurivu.pdf
Embedded domains
- crysiq.ru
- mutamobilya.com
- adlinefor.com
- energosol.pl
- st-johnson.com
- callhfelectric.com
- connect-event.fr
- ombs.ru
- wxeina.com
- dep14kirov.ru
- sea-cruise.ru
- universitecentrale.net
- decaldankinh.net
- studiogiovannone.com
- charolais-hessen.de
- alcoquimicos.com
- puebloexec.com
- langeline.com
- wjcopy.com
- s-pack.kr
- www.nuricomuvakfi.org
- www.cddfct.com
- extreamtuning.ru
- kantankacreative.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report