MALICIOUS — fa66f73465f119819d263f9fd150417dbcbb1acf2b65c761526643bb1867b4e1
MALICIOUS — fa66f73465f119819d263f9fd150417dbcbb1acf2b65c761526643bb1867b4e1 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fa66f73465f119819d263f9fd150417dbcbb1acf2b65c761526643bb1867b4e1 - SHA-1:
25a1251522be7dbc48c3fb357b8b602ee428b22c - MD5:
6d2ca7dcd242907c68347df644035945 - ssdeep:
1536:FYRVvtYk5t+2YoimHjy0yvXMWWkNpOPvppVyXyoWBNy5PLybDT+S:oVvtD+2YoimH+vXM7PhAyxYzy33 - TLSH:
T12C37B0F31053ED9C7B8B9F4369BB11E8604DE3482572E7905488BAACD57C9BD7E009A0 - Submitted as: fa66f73465f119819d263f9fd150417dbcbb1acf2b65c761526643bb1867b4e1
- File type: pdf · Size: 72716 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://west-holding.com/userfiles/file/56539628908.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://west-holding.com/userfiles/file/56539628908.pdf, https://schreinerheusi.de/wp-content/plugins/formcraft/file-upload/server/content/files/16139ab2184980---wisage.pdf, https://fivetc.net/uploads/files/85081361930.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/zMnd8XtcwSM/uplcv?utm_term=highway+rider+motorcycle+racer+mod+apk
- https://west-holding.com/userfiles/file/56539628908.pdf
- https://schreinerheusi.de/wp-content/plugins/formcraft/file-upload/server/content/files/16139ab2184980---wisage.pdf
- https://fivetc.net/uploads/files/85081361930.pdf
- https://mabuksusu.com/contents/files/xigosigikarivapi.pdf
- https://segurosjdd.com/wp-content/plugins/super-forms/uploads/php/files/1i64austcvb854dl3e55jn22l7/bogajagobepuzopivune.pdf
- http://ark-mr.com/data/home/qxu2063190031/htdocs/uploadfile/files/wejebovezuwojexasubosak.pdf
- https://hobbyschuurtje-webwinkel.be/images/userfiles/file/44067408278.pdf
- http://majorpropertygroup.com/userfiles/files/91027270975.pdf
- https://majubesar.net/contents/files/12872916680.pdf
- https://elperrocallejero.info/ckfinder/files/pobisinexig.pdf
- https://gjbuyerbroker.com/userfiles/file/tuted.pdf
- https://bhandarisurgical.com/ckfinder/userfiles/files/luzamaja.pdf
- https://bahamianbrewery.com/ckfinder/userfiles/files/99039356662.pdf
- https://rmissio.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1613120600be9e---bafid.pdf
- https://stcc-sa.com/motakamel/Ups/files/bodenegigipawux.pdf
- https://mavismanagement.com/wp-content/plugins/formcraft/file-upload/server/content/files/161375ac9a8001---zaxinevezoduzok.pdf
- http://nsdadventist.org/FCKData/file/72805479590.pdf
- http://chataphan.com/file_media/file_image/file/37709309189.pdf
- http://studiotecnicostradi.eu/userfiles/files/80416031564.pdf
- http://sweatrinserepeat.com/ckfinder/userfiles/files/96885853822.pdf
- https://giltmorestukko.hu/ckfinder/userfiles/files/51768052836.pdf
- https://i-try.tw/upfile/files/2021/09/06/52078477029.pdf
- https://triangle-electronics.com/assets/userfiles/file/nolavaxul.pdf
- http://barudan.hk/UploadFile/file/20210921122932010.pdf
Embedded domains
- feedproxy.google.com
- west-holding.com
- schreinerheusi.de
- fivetc.net
- mabuksusu.com
- segurosjdd.com
- ark-mr.com
- hobbyschuurtje-webwinkel.be
- majorpropertygroup.com
- majubesar.net
- elperrocallejero.info
- gjbuyerbroker.com
- bhandarisurgical.com
- bahamianbrewery.com
- rmissio.pl
- stcc-sa.com
- mavismanagement.com
- nsdadventist.org
- chataphan.com
- studiotecnicostradi.eu
- sweatrinserepeat.com
- i-try.tw
- triangle-electronics.com
- barudan.hk
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report