MALICIOUS — f8ad9f0a851c28a251fc99d195583ce36ac6db2b3e7be28a6e4a6b6e7b578ff0
MALICIOUS — f8ad9f0a851c28a251fc99d195583ce36ac6db2b3e7be28a6e4a6b6e7b578ff0 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f8ad9f0a851c28a251fc99d195583ce36ac6db2b3e7be28a6e4a6b6e7b578ff0 - SHA-1:
9a64ec11a4bc00e15fb7ca1e26fcaf5a62579dd4 - MD5:
187937568c401a6c63938f25acd53ac6 - ssdeep:
12288:WNtrmxyZYig5Q0O6EOnC7EkCumWo+ooQuSZ0yPjWneT16Bl6ha62QGpARV7wkOla:urgyZ0O6ELET+3NSyyHQQGp0V76wwLA3 - TLSH:
T1654F23E1326028A52DFFBD10D9496C61D06CF8912315E6C11ADB0F91EE8C46A5C6BFE3 - Submitted as: f8ad9f0a851c28a251fc99d195583ce36ac6db2b3e7be28a6e4a6b6e7b578ff0
- File type: pdf · Size: 720053 bytes
- Verdict: malicious (94/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://melissajacksonmd.com/wp-content/plugins/formcraft/file-upload/server/content/files/160701541170b9---31763008014.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://amfmeg.org/wp-content/plugins/formcraft/file-upload/server/content/files/160765b423df42---vurifuwubixowilaxafiv.pdf, https://karapinarinsaat.net/userfiles/upload/file/90831537218.pdf, https://www.rath-catering.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607b1305d3ff6---48897841514.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/cv9VXjIrmdE/uplcv?utm_term=bye+bye+video+by+rjz
- http://amfmeg.org/wp-content/plugins/formcraft/file-upload/server/content/files/160765b423df42---vurifuwubixowilaxafiv.pdf
- https://karapinarinsaat.net/userfiles/upload/file/90831537218.pdf
- https://www.rath-catering.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607b1305d3ff6---48897841514.pdf
- https://414movement.com/wp-content/plugins/super-forms/uploads/php/files/fbc7806b959604a9aaa1464fda811308/50878758010.pdf
- http://melissajacksonmd.com/wp-content/plugins/formcraft/file-upload/server/content/files/160701541170b9---31763008014.pdf
- https://www.citysecurity.org.uk/wp-content/plugins/super-forms/uploads/php/files/k13uogo1fli52u6v0t0kq26uuk/42752545557.pdf
- https://leo-translate.com.ua/wp-content/plugins/formcraft/file-upload/server/content/files/160857702eb66f---ximodenesa.pdf
- http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160877c33d61de---18532773818.pdf
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/16099559024d70---33908103360.pdf
- http://plusbateria.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075805f0ad4c---beribomozulugoxururapod.pdf
- http://tubietelbar.hu/uploadfile/mikiwa.pdf
- https://rhythmcprandfirstaid.com/wp-content/plugins/super-forms/uploads/php/files/f30043af0ff96baa002f17d5982d62e6/13526236759.pdf
- https://wpsqld.com.au/wp-content/plugins/super-forms/uploads/php/files/8a43ca8c3b1002bb96ef4d0fa71b335b/22626715751.pdf
- http://moveisgarciadigital.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1607f6fbb7b7c1---giruruwe.pdf
- http://maxitelt.no/wp-content/plugins/formcraft/file-upload/server/content/files/160836aaf79fd2---1672253705.pdf
Embedded domains
- feedproxy.google.com
- amfmeg.org
- karapinarinsaat.net
- www.rath-catering.de
- 414movement.com
- melissajacksonmd.com
- www.citysecurity.org.uk
- leo-translate.com.ua
- www.inhd.com.br
- kaufdeinauto.de
- plusbateria.com
- rhythmcprandfirstaid.com
- wpsqld.com.au
- moveisgarciadigital.com.br
- maxitelt.no
- tubietelbar.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report