MALICIOUS — 5970948610.pdf
MALICIOUS — 5970948610.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0213e1b2d1f6964cb476b5515e8f984cc03896790e01c47d42218f8ace565d96 - SHA-1:
4ebe4a66dcaae9c79ae89bbc2811ec7fb97fd522 - MD5:
c4cb394a56c2b8429362c85998208955 - ssdeep:
1536:sOFNQ9sYslPHe0rpYsTedZX5tP51t0xCZMFiYjQaeCc69qW40mChePki:fQ9VYHVlqd/tPbiQyFBEajL9GNCgh - TLSH:
T14338D0F3225BDC8CBE939B036BA5315C6459D2896033EB284448BB6CD57C7AD7E10A11 - Submitted as: 5970948610.pdf
- File type: pdf · Size: 76751 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!C4CB394A56C2
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://hart-metale.pl/gimnazjum/userfiles/file/87300490473.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://janeunchained.com/wp-content/plugins/super-forms/uploads/php/files/fko3p0hbkmnu9jiu14mkfv51t9/mufewatejazoletew.pdf, https://daleel.global/wp-content/plugins/super-forms/uploads/php/files/66e39rrmaoftlbkp76souglloe/95168735682.pdf, https://www.abaco-engineering.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607ddbf3e4b66---38399730457.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=converting+linear+equations+worksheet+answer+key
- https://janeunchained.com/wp-content/plugins/super-forms/uploads/php/files/fko3p0hbkmnu9jiu14mkfv51t9/mufewatejazoletew.pdf
- https://daleel.global/wp-content/plugins/super-forms/uploads/php/files/66e39rrmaoftlbkp76souglloe/95168735682.pdf
- https://www.abaco-engineering.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607ddbf3e4b66---38399730457.pdf
- https://discoverapartmentsforrent.com/wp-content/plugins/super-forms/uploads/php/files/b09a7f40b1b5320ae5a6090f5d73b563/26335225205.pdf
- http://mattstergamer.com/wp-content/plugins/super-forms/uploads/php/files/sceq0v95pnfup7v8e9rvv3jgpr/69705173861.pdf
- http://hart-metale.pl/gimnazjum/userfiles/file/87300490473.pdf
- https://apparel.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/d39b71dfad183a88ee90fd54d8b18ded/zifemotejujalizobor.pdf
- https://championsforchildren.org/wp-content/plugins/super-forms/uploads/php/files/b2e652b736c250248423f286e5ba52ca/33954555127.pdf
- https://kindliving.org/wp-content/plugins/super-forms/uploads/php/files/tmp/20631167913.pdf
- https://www.etbsupplies.com/wp-content/plugins/formcraft/file-upload/server/content/files/160824d455326a---kitovo.pdf
- https://estigotours.com/wp-content/plugins/super-forms/uploads/php/files/2323ba80cffcce93d9a4e278e67fea28/zegerajunimenu.pdf
- https://www.escon.it/wp-content/plugins/super-forms/uploads/php/files/ffe3f3fa45981f3f27cbc5739503691a/mebesulilanorerazizija.pdf
- https://nowbali.co.id/wp-content/plugins/formcraft/file-upload/server/content/files/160763d0a220ca---79097077729.pdf
- https://www.energetisch-therapeut-estie.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16078a52a21a5c---razabo.pdf
- http://erbilsunhotel.com/wp-content/plugins/super-forms/uploads/php/files/53jfm9rvjpq5nj85norj8bdga4/93827952983.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- janeunchained.com
- www.abaco-engineering.it
- discoverapartmentsforrent.com
- mattstergamer.com
- hart-metale.pl
- apparel.allianceflooring.net
- championsforchildren.org
- kindliving.org
- www.etbsupplies.com
- estigotours.com
- www.escon.it
- www.energetisch-therapeut-estie.nl
- erbilsunhotel.com
- www.w3.org
- purl.org
- ns.adobe.com
- daleel.global
- nowbali.co.id
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report