MALICIOUS — 57772061522.pdf
MALICIOUS — 57772061522.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0361e701245e000b4648943e27a763733fb56c6c7af80b07bf87754e52a363e9 - SHA-1:
e7f4fa654e4cb24cb3c03409a4d2ac4392a00099 - MD5:
46536ed567dffc6ddfdf74ba4b258ac8 - ssdeep:
1536:KZdPTs7shG++Sh5ZD6meMfxHN7/xkxWm+lyWapOnDqQW4bDMmoN9SpJ2wjJ:Ym4r+SLZ+ept7+xn+lznDqQcTN9SJ - TLSH:
T1143AD1F362ABDD4C73979F43A8A511AC548ED3886523E6A0418C7B7C887CB7D7E14602 - Submitted as: 57772061522.pdf
- File type: pdf · Size: 95791 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ndc-group.ru/uploads/files/xosukunazoregebesokozup.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://www.maoles.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607aa9b747184---dajikuka.pdf, http://ndc-group.ru/uploads/files/xosukunazoregebesokozup.pdf, http://kunmobile.vn/files/uploaded/20210722/file/94689320573.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: js, uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/6naE_Nh8_CY/uplcv?utm_term=what+is+the+difference+between+shimano+deore+and+deore+xt
- http://www.maoles.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607aa9b747184---dajikuka.pdf
- http://ndc-group.ru/uploads/files/xosukunazoregebesokozup.pdf
- http://kunmobile.vn/files/uploaded/20210722/file/94689320573.pdf
- https://caribemed.com/userfiles/file/mukegazamus.pdf
- https://mamproducciones.es/wp-content/plugins/formcraft/file-upload/server/content/files/1609eff8016de6---govitix.pdf
- https://carstenrath.com/wp-content/plugins/super-forms/uploads/php/files/i6undke6k4bfs1641esefkegac/37403167388.pdf
- http://www.megasaludips.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c1110ca4428---95959614339.pdf
- http://brodart01.com/wp-content/plugins/super-forms/uploads/php/files/1fkm9g5gvsrt2lsu3rslo56kbq/22650502988.pdf
- http://siripanyalamphun.com/user_img/files/50649417449.pdf
- http://zawayakw.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ab8f9b40425---sutanuxugakusuvudu.pdf
- http://appletechsolutions.com/userfiles/file/86086126847.pdf
- http://giga.sk/storage/file/23159836924.pdf
- https://trunglamdecor.com/uploads/userfiles/file/luloz.pdf
- http://aeronautike.com/userfiles/file/zekidotamizomavut.pdf
- https://wojczak.pl/userfiles/file/monuzogof.pdf
- http://pinturasoltra.com/images/slider/files/58548674486.pdf
- https://apoc.com.au/wp-content/plugins/super-forms/uploads/php/files/4aec8c69d31430be51b4b79768c6a766/14776827236.pdf
- http://socialbomjesus.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/16072139b17d1b---68961768117.pdf
- https://www.web2business.pt/wp-content/plugins/formcraft/file-upload/server/content/files/160c93c1ca20d7---xapoj.pdf
- https://action-roofing.com/wp-content/plugins/super-forms/uploads/php/files/0d5cafd403e0b7fb632cc3c2c2da8172/99772013765.pdf
- http://kompletucetnictvi.cz/files/file/nutilofujiwabosipe.pdf
- https://agrotehholding.ru/wp-content/plugins/super-forms/uploads/php/files/d979ac018640ea9f117f666612716ef0/22693286451.pdf
- http://www.bridalchapel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608b1f754f413---nowixexunexakoreb.pdf
- http://adveotec.com/img/file/valegafu.pdf
Embedded domains
- feedproxy.google.com
- www.maoles.com
- ndc-group.ru
- caribemed.com
- mamproducciones.es
- carstenrath.com
- www.megasaludips.com
- brodart01.com
- siripanyalamphun.com
- zawayakw.com
- appletechsolutions.com
- trunglamdecor.com
- aeronautike.com
- wojczak.pl
- pinturasoltra.com
- apoc.com.au
- socialbomjesus.org.br
- action-roofing.com
- agrotehholding.ru
- www.bridalchapel.com
- adveotec.com
- www.w3.org
- purl.org
- ns.adobe.com
- kunmobile.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report