MALICIOUS — 11129197229.pdf
MALICIOUS — 11129197229.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
00880dcbace449c909565282369c5f9b6bb61ec32871825a655d77ecc302cf09 - SHA-1:
52c966e714c33250259febf66a9c563b9e2ffeb9 - MD5:
80977ae27fc1c3031a9c5e184bc6abb4 - ssdeep:
1536:5XA60Oxsxv7pukEW7UbpOQLzoZm8XkRa/rWwpOStCmWmLh7zzTentvx3:27wfLcw8URoOSUSH/entR - TLSH:
T18539D0F35287DD4CB6978F436DEA0268A04DE6846672EB500084AE6CD9BC6FC7F10D91 - Submitted as: 11129197229.pdf
- File type: pdf · Size: 92248 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://cevhertemizlik.com/userfiles/files/96877185276.pdf, http://esenkardeslerinsaat.com/resimlerfiles/32178919138.pdf, http://www.argentum.com/wp-content/plugins/super-forms/uploads/php/files/b6lae50nebm5tdnpafvvbjqkoq/15958295105.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/3vuEKuznOb8/uplcv?utm_term=dungeons+and+dragons+monsters+list
- https://cevhertemizlik.com/userfiles/files/96877185276.pdf
- http://esenkardeslerinsaat.com/resimlerfiles/32178919138.pdf
- http://www.argentum.com/wp-content/plugins/super-forms/uploads/php/files/b6lae50nebm5tdnpafvvbjqkoq/15958295105.pdf
- https://amkboiler.com/wp-content/plugins/super-forms/uploads/php/files/hj74ul62nhaf6717ne64g908so/penixi.pdf
- http://eyupsifalibitkiler.com/resimler/files/lemodomoto.pdf
- https://www.demetagras.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ce3cd346e4---webubirakolimip.pdf
- https://vakukh.ru/wp-content/plugins/super-forms/uploads/php/files/b5d4059e91428c31e024284e66cde609/50202245039.pdf
- http://studiogallerani.it/userfiles/files/bifoxalome.pdf
- https://lifecareproduct.in/ckfinder/userfiles/files/67219821734.pdf
- http://sixtyguildersresearch.com/admin/photos/file/19820133492.pdf
- http://pasted-radio.de/web/files/lupiweriselokevujuv.pdf
- http://jinyezi.cn/upload/63007048983.pdf
- https://papiratisk.cz/soubory/xuxolikup.pdf
- http://pericosrentcar.com.mx/wp-content/plugins/formcraft/file-upload/server/content/files/160bbb63152f43---piwira.pdf
- http://spbmedax.ru/sites/default/files/uploads/jomedutiwudiwona.pdf
- http://aroma-es.site/yamituki-n/uploads/files/jutapivorotijefa.pdf
- https://lederstuhlshop.de/ckfinder/userfiles/files/dubusun.pdf
- https://webtraffic.ch/wp-content/plugins/super-forms/uploads/php/files/05evsa4ujpeo391l42t9l214c9/18079267974.pdf
- http://sazjah.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606e5e4359f9b---fiwodabivibowobizodini.pdf
- http://www.maderas-navarro.com/ckfinder/userfiles/files/68903866399.pdf
- https://studiogreenwich.ru/wp-content/plugins/super-forms/uploads/php/files/40c3e554a7b0d10ba157541ba0a0a723/luzarivevo.pdf
- http://hondatayho.top/img-ngocbao/files/sojusu.pdf
- https://aawyx.com/sites/default/imageuser/file/16290662001.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- cevhertemizlik.com
- esenkardeslerinsaat.com
- www.argentum.com
- amkboiler.com
- eyupsifalibitkiler.com
- www.demetagras.com
- vakukh.ru
- studiogallerani.it
- lifecareproduct.in
- sixtyguildersresearch.com
- pasted-radio.de
- jinyezi.cn
- pericosrentcar.com.mx
- spbmedax.ru
- aroma-es.site
- lederstuhlshop.de
- webtraffic.ch
- sazjah.com
- www.maderas-navarro.com
- studiogreenwich.ru
- hondatayho.top
- aawyx.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report