MALICIOUS — ffa4242ec797bdcf9be6af3fa664dadb746600b0c4d85415f513776ec21a1d78
MALICIOUS — ffa4242ec797bdcf9be6af3fa664dadb746600b0c4d85415f513776ec21a1d78 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ffa4242ec797bdcf9be6af3fa664dadb746600b0c4d85415f513776ec21a1d78 - SHA-1:
33a390f6e9ca4caf4f4662312c762a2fb6a17863 - MD5:
affda577036a66f74b370f2fdc0f0b6f - ssdeep:
3072:RWA88AebB0dyW3Zbb7by10hw7aj/BXrIPVD3wrLKxvtPZ9o:5LBm9u10hKaj/ZrIPRQspZS - TLSH:
T1DD3E01E7126F9D5C375FE502DDBF40A8908EE79865A2D6819008AF6C80EC57EF900686 - Submitted as: ffa4242ec797bdcf9be6af3fa664dadb746600b0c4d85415f513776ec21a1d78
- File type: pdf · Size: 135978 bytes
- Verdict: malicious (94/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://rmdschoolandcollege.com/wp-content/plugins/super-forms/uploads/php/files/6858t1k08v4qd61gtn5rv3inm7/lovuxosaburitunew.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://stgeorgedentalcare.in/ckfinder/userfiles/files/retedezigipenigemeparod.pdf, https://alakharia.com/public_html/userfiles/file/75467161631.pdf, http://polish-house.com/uploades/fckeditorfile/wizukaj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=teacher%27s+guide+grade+8+math+answers
- https://stgeorgedentalcare.in/ckfinder/userfiles/files/retedezigipenigemeparod.pdf
- https://alakharia.com/public_html/userfiles/file/75467161631.pdf
- http://polish-house.com/uploades/fckeditorfile/wizukaj.pdf
- http://akcjonariusz.com/UserFiles/file/titavurodexasizekukiv.pdf
- https://accesoriosalmayor.com/images/userfiles/file/11180742643.pdf
- http://boulderdivorcelaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c19d81555f3---papuxubug.pdf
- https://www.horisunmauritius.com/wp-content/plugins/super-forms/uploads/php/files/ab051f4436324d4b0849f0a273c9287f/53118784136.pdf
- https://rmdschoolandcollege.com/wp-content/plugins/super-forms/uploads/php/files/6858t1k08v4qd61gtn5rv3inm7/lovuxosaburitunew.pdf
- https://motionslam.com/wp-content/plugins/super-forms/uploads/php/files/91f1b3b427bdc53d7a58ac30ce322938/velara.pdf
- https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/b42692566e89ac958844ecd701f5ec61/kufofifewofevexuziso.pdf
- http://gleneaglehoa.org/images/file/wezozitezutizutikimenegor.pdf
- https://xn--fiqa735be48e.com/upload/files/55666098793.pdf
- http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1606ea113c04a8---55471027253.pdf
- http://chargers68-50th.com/clients/3/3d/3dd154274af4887fbe356f6dcfc18689/File/10374868430.pdf
- http://ilkyoukais.com/Images/Media/files/kijivemotokulozug.pdf
- http://sieuthihatgiong.vn/webroot/img/files/sitefibibiniwojutasifipud.pdf
- http://protech.com.ng/wp-content/plugins/formcraft/file-upload/server/content/files/1606cfada138cb---48381155439.pdf
- http://tutaylamhet.com/storage/ckfinder/files/toliwugidegupajeputi.pdf
- http://www.siscard.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607f1a9ececff---bufor.pdf
Embedded domains
- feedproxy.google.com
- stgeorgedentalcare.in
- alakharia.com
- polish-house.com
- akcjonariusz.com
- accesoriosalmayor.com
- boulderdivorcelaw.com
- www.horisunmauritius.com
- rmdschoolandcollege.com
- motionslam.com
- amartzon.store
- gleneaglehoa.org
- xn--fiqa735be48e.com
- prodesign31.ru
- chargers68-50th.com
- ilkyoukais.com
- tutaylamhet.com
- www.siscard.com
- sieuthihatgiong.vn
- protech.com.ng
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report