MALICIOUS — f8b076275a129221a15341dec29db65fd508cbba797c126cd1537004b2997ca0
MALICIOUS — f8b076275a129221a15341dec29db65fd508cbba797c126cd1537004b2997ca0 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f8b076275a129221a15341dec29db65fd508cbba797c126cd1537004b2997ca0 - SHA-1:
104b48bc60f9751a715a89dd63a8e0e0dd36dcae - MD5:
35f490af15b8ed889d62fb14aaa375c9 - ssdeep:
1536:KpT6XpUehEXzBXaWhfw9x5o7ncSpTTMHJ8bjGoORf7pWOuSBeu8K/59KUyj0RWsL:ane+XlKRPO7lpTgp8buzcMnKUyj0A2N - TLSH:
T16C38D0F712A7DC0CB78BDB43B99B016D649CCB893212FA9044C8B668947C5FE7E04A51 - Submitted as: f8b076275a129221a15341dec29db65fd508cbba797c126cd1537004b2997ca0
- File type: pdf · Size: 84016 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://ubranni.com/uploader/files/6132091015.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://www.phonefixcomo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615152b5a8e88---petisejagofibidalolube.pdf, https://abouelhoulgroup.com/userfiles/files/83532895588.pdf, http://air-ned.com/uploads/files/9259954339.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://feedproxy.google.com/~r/MbOu/~3/23D8k0Ec_6w/uplcv?utm_term=months+in+malay
- http://www.phonefixcomo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615152b5a8e88---petisejagofibidalolube.pdf
- https://abouelhoulgroup.com/userfiles/files/83532895588.pdf
- http://air-ned.com/uploads/files/9259954339.pdf
- http://objetivovender.com/wp-content/plugins/formcraft/file-upload/server/content/files/16150991a90f58---vubinedetugufide.pdf
- https://ubranni.com/uploader/files/6132091015.pdf
- http://autokolcsonzoszolnok.hu/admin/fck_upload/file/megezobavevutebifokedalit.pdf
- http://www.novosib-sport.ru/ckfinder/userfiles/files/gupixisaripotebasevajin.pdf
- https://astoraccessories.com/uploads/ckfinder/files/popumajukopabujodex.pdf
- http://summitremodelinginc.com/userfiles/files/sakovazibilun.pdf
- https://thaiahpa.com/flash/files/bofevof.pdf
- http://hzxgdz.com/images/upload/File/wuserubobopojugagirasatut.pdf
- https://oncetrabzon.com/resimler/files/jafoketotixivonanoku.pdf
- http://yousefmaktabi.com/ckfinder/userfiles/files/wopojudufokox.pdf
- https://anzhero-sudzhensk.verlauf-ekb.ru/admin/ckfinder/userfiles/files/25479990899.pdf
- http://crimesla.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/nulamogifeserab.pdf
- http://shrlie.com/upload_fck/file/2021-9-5/20210905203131709253.pdf
- https://thefertilizerproductionline.com/d/files/nepitatuzaverakinozuvub.pdf
- http://www.idukkidiocese.org/files/js/ckfinder/userfiles/files/vofasimaxelujigo.pdf
- https://www.zolmedis.lt/ckfinder/userfiles/files/kefixevapadegopexi.pdf
- https://dolphinsolutions.net/ckfinder/userfiles/files/4369821753.pdf
- http://nscenter.cn/upload/files/subagu.pdf
- http://opuspointpartners.com/ckfinder/userfiles/files/99211646593.pdf
- http://axiomestates.com/userfiles/file/pepejemas.pdf
- https://shoppingplanet.cityplanet.ro/ckfinder/userfiles/files/3123947713.pdf
Embedded domains
- feedproxy.google.com
- www.phonefixcomo.com
- abouelhoulgroup.com
- air-ned.com
- objetivovender.com
- ubranni.com
- www.novosib-sport.ru
- astoraccessories.com
- summitremodelinginc.com
- thaiahpa.com
- hzxgdz.com
- oncetrabzon.com
- yousefmaktabi.com
- anzhero-sudzhensk.verlauf-ekb.ru
- crimesla.com
- shrlie.com
- thefertilizerproductionline.com
- www.idukkidiocese.org
- dolphinsolutions.net
- nscenter.cn
- opuspointpartners.com
- axiomestates.com
- autokolcsonzoszolnok.hu
- www.zolmedis.lt
- shoppingplanet.cityplanet.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report