MALICIOUS — 46128171919.pdf
MALICIOUS — 46128171919.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0610f3f3782f885b5ae6f74186ffa4254df5cae81efc50fdcb2bab2d775c3750 - SHA-1:
19cabe2cf86582a375f6a556bb8dcc8922aea3ed - MD5:
e37f0ddaa433643ddbdb77e1a27b8451 - ssdeep:
1536:imVT04X/UkqdsFo8skdkVlXOR9cLUKz2jxpCdsWOpOaZEWQqeJsT7qw3+PaBNNpN:ZTjXGsFo8rGVleC1aZMhWT5OPaBNV - TLSH:
T1AA38D0F3615BCD8C75878B439AFA11A9A086D7881261FBA0018C776CD8BC4FDBF10A51 - Submitted as: 46128171919.pdf
- File type: pdf · Size: 84181 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.dgtrans.co.th/login/ckfinder/userfiles/files/80614855563.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://garglob.ru/uplcv?utm_term=among+us+12.9+download, https://purpleleafestatebuyers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613574d4ca9a1---52077081878.pdf, http://mspchicagolaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/31555015119.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://garglob.ru/uplcv?utm_term=among+us+12.9+download
- https://purpleleafestatebuyers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613574d4ca9a1---52077081878.pdf
- http://mspchicagolaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/31555015119.pdf
- https://mysilo.com/upload/ckfinder/files/53136075223.pdf
- http://www.dgtrans.co.th/login/ckfinder/userfiles/files/80614855563.pdf
- https://vibangthuaphatlai.net/uploads/files/79412165153.pdf
- https://easypayindia.in/userfiles/file/raxokapunilediwopopuw.pdf
- http://www.plain-pied.com/editeur/ckfinder/userfiles/files/97587753615.pdf
- https://amt-alarmy.pl/userfiles/file/72356550991.pdf
- http://droneducational.com/admin/userfiles/file/20767768166.pdf
- http://consoles-a-gagner.com/fckeditor/userfiles/file/bekawexuremulowawotub.pdf
- https://petribax.nl/userfiles/file/besitosimubi.pdf
- http://primaria-ciocirlia.ro/media/file/40639580432.pdf
- https://betalinktech.com/blmedia/file/74252841678.pdf
- https://dmshospital.com/mm_engg/files/23149888541.pdf
- http://arqing.es/ckfinder/userfiles/files/kugigirajatizakudo.pdf
- http://tsg-vaganovskoe.ru/ckfinder/userfiles/files/35681081568.pdf
- http://www.europesolidaire.eu/userfiles/files/39282723679.pdf
- http://cetis156.neutronds.com/assets/js/ckfinder/userfiles/files/zenixebolamidenam.pdf
- https://trexanh.net/upload/files/55196877195.pdf
- http://dreiseengrundschule.de/files/disojugirugexagavukadozo.pdf
- https://cms.blauraum.com/wp-content/plugins/super-forms/uploads/php/files/b05ba9afb45d5b6bab9ece8799477741/73930858258.pdf
- https://ringid.vn/ckfinder/userfiles/files/24606195377.pdf
- https://ptogel1.com/contents/files/69286271221.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- garglob.ru
- purpleleafestatebuyers.com
- mspchicagolaw.com
- mysilo.com
- vibangthuaphatlai.net
- easypayindia.in
- www.plain-pied.com
- amt-alarmy.pl
- droneducational.com
- consoles-a-gagner.com
- petribax.nl
- betalinktech.com
- dmshospital.com
- arqing.es
- tsg-vaganovskoe.ru
- www.europesolidaire.eu
- cetis156.neutronds.com
- trexanh.net
- dreiseengrundschule.de
- cms.blauraum.com
- ptogel1.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.dgtrans.co.th
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report