MALICIOUS — f8bb532bc63aff1c60cef65878a75a3154e35820481bc48f6e4006ba8d00db85
MALICIOUS — f8bb532bc63aff1c60cef65878a75a3154e35820481bc48f6e4006ba8d00db85 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f8bb532bc63aff1c60cef65878a75a3154e35820481bc48f6e4006ba8d00db85 - SHA-1:
695c052635675291bed56722a027ffc0c938f8fd - MD5:
a3a941f89d82ae131369612a584013e3 - ssdeep:
1536:6x/cwQhp4OkM9R5g1hQ6Xwi4vvjxnoIWKK5e9WwpOSsnI:kEwQhMqR5EhQywLHNoaFkS5 - TLSH:
T1E137BFF351DBDC4C7B8ACF032BDA529C9489E7881266D7514088BAACC5BCA7DBF10950 - Submitted as: f8bb532bc63aff1c60cef65878a75a3154e35820481bc48f6e4006ba8d00db85
- File type: pdf · Size: 71194 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://heritran.vn/uploads/news_file/85874887875.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://studioriggio.it/userfiles/files/finimuzotutevujolepozev.pdf, http://amunt.madteam.net/ckfinder/userfiles/files/27584468582.pdf, http://posuni.com/userfiles/file/30862828841.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=airjack+wifi+hack
- http://studioriggio.it/userfiles/files/finimuzotutevujolepozev.pdf
- http://amunt.madteam.net/ckfinder/userfiles/files/27584468582.pdf
- http://posuni.com/userfiles/file/30862828841.pdf
- http://dd-eng.com/files/files/7428634254.pdf
- http://www.oneworldkarate.com/fckeditorimages/userfiles/file/vizopunikapul.pdf
- https://bokaichenyu.com/upload/files/42266374613.pdf
- http://clear-es.net/yamituki-n/uploads/files/93183429168.pdf
- https://2acontractor.it/images/file/rokejew.pdf
- http://tufaghanafc.com/js/ckfinder/userfiles/files/dakifofuginalo.pdf
- https://heritran.vn/uploads/news_file/85874887875.pdf
- https://stakeoutllc.com/wp-content/plugins/super-forms/uploads/php/files/906aa55fc8040aefefef697eace039d7/wivenegesad.pdf
- https://www.hmgfinance.com/ckfinder/userfiles/files/jalenepadijemoli.pdf
- http://patriabrno.cz/userfiles/files/69007364857.pdf
- http://bkmarine.net/ckfinder/userfiles/files/1631850510.pdf
- https://bilegt.mn/userfiles/files/52144698393.pdf
- http://decamiones.com/userfiles/file/nomomanozosuludiz.pdf
- http://thedewakohchang.com/image/upload/File/evurutek.pdf
- http://jamones-luna.shopcloud.es/ckfinder/userfiles/files/77131702442.pdf
- http://jyjjapan.jp/files/ckeditor/files/mojazagumebep.pdf
- http://grupafurman.pl/!mag2011/userfiles/file/vasanetifemuk.pdf
- https://hogozaty.com/ckfinder/userfiles/files/zematepijunadedikogejut.pdf
- http://badischer-kunstverein.de/ckfinder/userfiles/files/96447253595.pdf
- https://healthresearchinstitute.net/userfiles/file/64948657822.pdf
- http://www.sictombbi.fr/ckfinder/userfiles/files/57665736171.pdf
Embedded domains
- feedproxy.google.com
- studioriggio.it
- amunt.madteam.net
- posuni.com
- dd-eng.com
- www.oneworldkarate.com
- bokaichenyu.com
- clear-es.net
- 2acontractor.it
- tufaghanafc.com
- stakeoutllc.com
- www.hmgfinance.com
- bkmarine.net
- decamiones.com
- thedewakohchang.com
- jamones-luna.shopcloud.es
- jyjjapan.jp
- grupafurman.pl
- hogozaty.com
- badischer-kunstverein.de
- healthresearchinstitute.net
- www.sictombbi.fr
- spad.kr
- dinskayarealty.ru
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report