MALICIOUS — 160a1234679697---96618147287.pdf
MALICIOUS — 160a1234679697---96618147287.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
03437cb0d11d8ed891a57089102bf642a72b66d8453fa286fa6085436404271f - SHA-1:
8f6ef35b23a76e7b2c351202206416a28eb098c9 - MD5:
f141cae23d425f617b95ac0dfa1ec074 - ssdeep:
1536:bm/cBuwhC+Ii282SXX+EjoiU6DclWJCM78WSoEJvAovs4FVn6eu9RnCh2ymiA:OOE+IV8ZNjM6DclWhnSo29vsQuXCh2y0 - TLSH:
T19939D0F321CBDD8C3ACA5B035AE1107C658AC7483572AAA014C4F76DCCAC6BEAD05A51 - Submitted as: 160a1234679697---96618147287.pdf
- File type: pdf · Size: 89439 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F141CAE23D42
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.carlosfunes.es/wp-content/plugins/formcraft/file-upload/server/content/files/1606fe53858b38---sewegavamisagukifudo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://allytemp.ru/uplcv?utm_term=aluminium+sheet+suppliers+in+al+quoz, https://indacphuc.com/wp-content/plugins/super-forms/uploads/php/files/bifgo65i7d2efk6fg416sgrvv6/somomasasasajosekepoje.pdf, https://www.andeanskyline.com/wp-content/plugins/formcraft/file-upload/server/content/files/160887ec1b5a65---96606698091.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://allytemp.ru/uplcv?utm_term=aluminium+sheet+suppliers+in+al+quoz
- https://indacphuc.com/wp-content/plugins/super-forms/uploads/php/files/bifgo65i7d2efk6fg416sgrvv6/somomasasasajosekepoje.pdf
- https://www.andeanskyline.com/wp-content/plugins/formcraft/file-upload/server/content/files/160887ec1b5a65---96606698091.pdf
- https://www.carlosfunes.es/wp-content/plugins/formcraft/file-upload/server/content/files/1606fe53858b38---sewegavamisagukifudo.pdf
- https://baxsporthorses.com/userfiles/file/fejibuziwisobamaf.pdf
- https://accesoriosalmayor.com/images/userfiles/file/norafutirokuzaxajulika.pdf
- http://aarogyamedico.com/userfiles/file/67074647775.pdf
- http://www.adatechotomasyon.net/wp-content/plugins/formcraft/file-upload/server/content/files/1606ced45d819e---34136661052.pdf
- https://ehblending.com/wp-content/plugins/super-forms/uploads/php/files/960f39f6a1227895119adc70f3f08d0b/7530087751.pdf
- http://www.akutrans.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609aae9d837ae---22308636409.pdf
- http://adhdadvisory.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d4ffe13a25---poxolidubixitajigali.pdf
- https://t4g.nasscomfoundation.org/wp-content/plugins/super-forms/uploads/php/files/jor01e74jq3f2tbco13kdo51d3/tisexidizusovobakixofese.pdf
- http://aiswaryamatrimonials.com/fck_uploads/file/32856346411.pdf
- https://namastehealth.in/wp-content/plugins/super-forms/uploads/php/files/nukaqug78it8cupd2b2nlh1k4m/fifujamin.pdf
- https://webhostmurah.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608e2a053d2fe---kudajejiwime.pdf
- https://themodernla.com/wp-content/plugins/super-forms/uploads/php/files/eaf09c5370beed439c09e8b2f16e3d13/sajatukiwoliweroza.pdf
- https://www.scilights.com/wp-content/plugins/super-forms/uploads/php/files/1b57a38155fb13250bec04a9c8918d88/97205238050.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- allytemp.ru
- indacphuc.com
- www.andeanskyline.com
- www.carlosfunes.es
- baxsporthorses.com
- accesoriosalmayor.com
- aarogyamedico.com
- www.adatechotomasyon.net
- ehblending.com
- www.akutrans.com
- adhdadvisory.com
- t4g.nasscomfoundation.org
- aiswaryamatrimonials.com
- namastehealth.in
- webhostmurah.com
- themodernla.com
- www.scilights.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report