MALICIOUS — fcc9c26374faa095f3b5f6ff62b3bf18c252b8737bf3abc104abecc7788c3699
MALICIOUS — fcc9c26374faa095f3b5f6ff62b3bf18c252b8737bf3abc104abecc7788c3699 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fcc9c26374faa095f3b5f6ff62b3bf18c252b8737bf3abc104abecc7788c3699 - SHA-1:
e3ff4dcd8e1dc741a0c9d1bed2a77be3dd0137d7 - MD5:
0f11904fdfd65b1bfab081c529cba49a - ssdeep:
1536:qwEruUY4MFTQyG3a/gNnlVOjySYUWvKa1zWMaCWuYnWOpOaZEWLXMcBnu/RzP7:OruULMayG3IgNlVDcWvKasMjWuaZnXFA - TLSH:
T13539D0F312F7ED4C765B5B1369E711A8E086E28D6022DB60868C77ACC47C6FD6E10921 - Submitted as: fcc9c26374faa095f3b5f6ff62b3bf18c252b8737bf3abc104abecc7788c3699
- File type: pdf · Size: 85833 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://cataga.de/beta/files/file/nuxovopirasurituxavajaj.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://oniceh.ru/uplcv?utm_term=in+your+eyes+song+by+george+benson, http://cataga.de/beta/files/file/nuxovopirasurituxavajaj.pdf, https://suncables.co/images/file/jumabifawabilelonoga.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oniceh.ru/uplcv?utm_term=in+your+eyes+song+by+george+benson
- http://cataga.de/beta/files/file/nuxovopirasurituxavajaj.pdf
- https://suncables.co/images/file/jumabifawabilelonoga.pdf
- https://aokman-drive.com/d/files/razovazuxelavukazijarovib.pdf
- https://reformedgeneration.com/userfiles/file/32386961621.pdf
- https://guijek.com/userfiles/file/84293741619.pdf
- http://fcv-bo.org/data/fcv-bo/userfiles/file/82328177338.pdf
- http://conditum.nl/userfiles/file/35860886062.pdf
- https://tennis94.fr/img/pics/files/kuzusijemebakifuliv.pdf
- https://ismart99.net/upload/files/23852781447.pdf
- http://savitaco.com/uploads/images/files/76921842956.pdf
- https://apexsafetyproducts.com/ckfinder/userfiles/files/xudijazepuxeju.pdf
- https://harmony-lazienka.pl/Upload/file/lepopazixenukeridewugiwas.pdf
- http://skuplaptop.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1615fe0e14c18f---zokigoxolixex.pdf
- http://cyuansheng.com/userfiles/file/xurozujipuwozaguzu.pdf
- https://www.barrau-philippe-sedeco.fr/ckfinder/userfiles/files/vatofuwaxive.pdf
- http://eska-lift.ru/userfiles/file/fakawezupejegiwufeso.pdf
- http://kolesa.sk/files/64389626417.pdf
- https://miaousland.fr/ckfinder/userfiles/files/11685548265.pdf
- http://zezoalza.com/ckupload/files/12661447027.pdf
- http://www.biosafety.biz/ckfinder/userfiles/files/31112580456.pdf
- https://sapporopools.com/contents/files/mojetaloxowutoxufuzovepa.pdf
- http://gioiacompany.net/images/upload/file/91989799952.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- oniceh.ru
- cataga.de
- suncables.co
- aokman-drive.com
- reformedgeneration.com
- guijek.com
- fcv-bo.org
- conditum.nl
- tennis94.fr
- ismart99.net
- savitaco.com
- apexsafetyproducts.com
- harmony-lazienka.pl
- skuplaptop.pl
- cyuansheng.com
- www.barrau-philippe-sedeco.fr
- eska-lift.ru
- miaousland.fr
- zezoalza.com
- www.biosafety.biz
- sapporopools.com
- gioiacompany.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report