MALICIOUS — 30673794627.pdf
MALICIOUS — 30673794627.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
02c096d39883424b10560be9dbd110f48887bcbca5521c79e7434e51b8685383 - SHA-1:
3d381ce4a11b5dbdd2b8b48d84c3dbd1e15ff8bc - MD5:
fbc01d791a71acfac56bc92937c3f4f5 - ssdeep:
1536:bqfwwAbzwcVFZxNRo8A5c5ObkgCP2AyBMjca0Qkmo7/g3T8fWUkpjDseWIZjnWaB:SOzXVFZ7Ro8Ec5OYgC+/Xeho7/g3g9k5 - TLSH:
T14339C0F310A7CD4C768AAB476EE6155860CEE38D22A2EAD001C8B76C847D5FD3F04561 - Submitted as: 30673794627.pdf
- File type: pdf · Size: 87213 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://asr-net.ru/uploads/files/35020787578.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://xn--2o2b17g32e8xisqq.com/userData/board/file/14054440335.pdf, http://asr-net.ru/uploads/files/35020787578.pdf, http://fishtech.org/uploads/userfiles/file/file/kolosesovimetomufixux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=game+controller+2+touch+pro+mod+apk
- http://xn--2o2b17g32e8xisqq.com/userData/board/file/14054440335.pdf
- http://asr-net.ru/uploads/files/35020787578.pdf
- http://fishtech.org/uploads/userfiles/file/file/kolosesovimetomufixux.pdf
- https://tannhatviet.vn/upload/files/xazukesufibiji.pdf
- https://er-cardiff.com/eurostyl/photos/file/bijomapazizusiwajikumev.pdf
- http://www.gradur.ba/wp-content/plugins/formcraft/file-upload/server/content/files/1613cba0cbea8f---pubogopadupil.pdf
- http://archiw.gbpopatowiec.pl/img/upload/files/98775313545.pdf
- http://gammatradings.com/userfiles/file/remozoxunemuzesonegimavo.pdf
- https://vinaarc.com/app/webroot/files/ckfinder/userfiles/files/jezibonagakabo.pdf
- http://ayrh.internet-match.com/upload/files/42627769688.pdf
- https://kujainspectors.com/candyticket/uploads/page_images/files/vuvifabasogonawuxu.pdf
- https://sistemagestiondpr.co/userfiles/file/xomizirijusovetirakudakeb.pdf
- https://mancomunidadvaldizarbe.com/userfiles/files/kuxowaraguzupexi.pdf
- http://simonide.org/userfiles/file/19444004865.pdf
- http://bhartiyambeohari.in/userfiles/file/sewuritupesuvemuburunel.pdf
- http://filipdegreef.be/uploads/files/95405441285.pdf
- https://phase1acoustics.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613a5003da6ae---lujojarawakixakabonuwak.pdf
- http://www.520amis.com/upload/files/wopafu.pdf
- https://pima-alarms.eu/slicice/file/punajazixekegugogul.pdf
- http://ipjanah.ir/wp-content/plugins/super-forms/uploads/php/files/e362es5e2dioktghlpsc4u9ci5/kitomitanubafovepos.pdf
- https://iamluno.com/wp-content/plugins/formcraft/file-upload/server/content/files/161394fef90bd3---2639718682.pdf
- http://brcassociati.com/userfiles/files/rirukojirekazeke.pdf
- https://cheesykeju.com/contents/files/gowobu.pdf
- http://ilksolar.com/Images/Media/files/28726025642.pdf
Embedded domains
- feedproxy.google.com
- xn--2o2b17g32e8xisqq.com
- asr-net.ru
- fishtech.org
- er-cardiff.com
- archiw.gbpopatowiec.pl
- gammatradings.com
- vinaarc.com
- ayrh.internet-match.com
- kujainspectors.com
- sistemagestiondpr.co
- mancomunidadvaldizarbe.com
- simonide.org
- bhartiyambeohari.in
- filipdegreef.be
- phase1acoustics.com
- www.520amis.com
- pima-alarms.eu
- ipjanah.ir
- iamluno.com
- brcassociati.com
- cheesykeju.com
- ilksolar.com
- ramenhajimetustin.com
- bibliotheque.ville.deux-montagnes.qc.ca
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report