MALICIOUS — 80136048602.pdf
MALICIOUS — 80136048602.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
09374881fdb8342f023ace5cbe4e4d57d5a40b4aed8f31d4b42508d809630d20 - SHA-1:
385d8862d7fca51d0b3e7daaf59b0fb73c7033f2 - MD5:
120a3d0f9c944256e45c2484ab610b7d - ssdeep:
1536:oO7x0gj7CCeDoMRppv7ZB8iWGgTftJh9QCjQch7pxq8OClNXWqZWbpONiWPYzSdg:ggj6fX7Zu1TFf9JFhPOClcqbNyGdK9 - TLSH:
T1F83AD0F31067DD8C7647DF435ABB12A9B08AD6482123F59041CCB66CE2BCABDAF04564 - Submitted as: 80136048602.pdf
- File type: pdf · Size: 93237 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://wastran.ru/uplcv?utm_term=how+to+hack+a+pubg+mobile, https://www.karavanlakesfet.com/wp-content/plugins/super-forms/uploads/php/files/1e0414f46564294f8ae99bad26c0a308/72985304493.pdf, http://webursitet.org/Files/file/59897963179.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://wastran.ru/uplcv?utm_term=how+to+hack+a+pubg+mobile
- https://www.karavanlakesfet.com/wp-content/plugins/super-forms/uploads/php/files/1e0414f46564294f8ae99bad26c0a308/72985304493.pdf
- http://webursitet.org/Files/file/59897963179.pdf
- http://austria-ex.com/images/blog//file/wegovefirerimizemuguxixik.pdf
- https://polinagerz.ru/wp-content/plugins/super-forms/uploads/php/files/o7q4cgu64m3dr4g3jpfn76masf/11644404243.pdf
- http://aqbnb.com/uploadfile/file/teluwawuxalipot.pdf
- http://www.yourhealthyourchoice.org/wp-content/plugins/formcraft/file-upload/server/content/files/1609062cc43cda---lifizutakelos.pdf
- https://alnahamgroup.com/userfiles/file/36051203521.pdf
- https://www.burit.net/wp-content/plugins/formcraft/file-upload/server/content/files/1606c83cb9e95b---16848917085.pdf
- http://dobryremont.pl/ebobas/portal/app/webroot/img/tmp/file/16208086318945.pdf
- https://www.physioaktivkramer.de/wp-content/plugins/formcraft/file-upload/server/content/files/160c14dc4c9e46---porapewogesorigimasut.pdf
- https://ols.lighting/wp-content/plugins/super-forms/uploads/php/files/599105820ccf658cb7c11a4789aaa6e5/midadaromodaridodisum.pdf
- http://www.medical-psychology.gr/wp-content/plugins/formcraft/file-upload/server/content/files/160dbdbe908d11---dojeguxukavupuwot.pdf
- http://matrixuniverzum.eu/wp-content/plugins/formcraft/file-upload/server/content/files/160ab58ae228a0---loxexesofowav.pdf
- http://aa-nusd.jp/takuzilaxevewaxe.pdf
- https://purebodycare.courses/wp-content/plugins/super-forms/uploads/php/files/ac4t3rh68j7gperod4h59elj8i/10860956041.pdf
- http://skiflogistics.ru/userfiles/file/fisikafudokukukugovizeta.pdf
- https://cspdental.com/wp-content/plugins/super-forms/uploads/php/files/df3457095821afb5193a1d1bc72297d6/20312948095.pdf
- https://astek-telem.fr/userfiles/file/63114156390.pdf
- http://szao-spb.ru/images/news/file/70026639371.pdf
- https://www.carlosfunes.es/wp-content/plugins/formcraft/file-upload/server/content/files/160b5c54c59ce2---zigozamowabotekodiwa.pdf
- http://www.zopfitravel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c306231cbeb---59275672582.pdf
- https://janeunchained.com/wp-content/plugins/super-forms/uploads/php/files/a0sjuu8bk2r2mhq9iqlo2pkhq7/673049446.pdf
- http://www.hj-bouwt.be/wp-content/plugins/formcraft/file-upload/server/content/files/160b8cf31edd07---nukiganabibo.pdf
- http://parkhighclassof60.com/clients/871169/File/vubikovazesoruperoxix.pdf
Embedded domains
- wastran.ru
- www.karavanlakesfet.com
- webursitet.org
- austria-ex.com
- polinagerz.ru
- aqbnb.com
- www.yourhealthyourchoice.org
- alnahamgroup.com
- www.burit.net
- dobryremont.pl
- www.physioaktivkramer.de
- matrixuniverzum.eu
- aa-nusd.jp
- skiflogistics.ru
- cspdental.com
- astek-telem.fr
- szao-spb.ru
- www.carlosfunes.es
- www.zopfitravel.com
- janeunchained.com
- www.hj-bouwt.be
- parkhighclassof60.com
- www.alertgy.com
- antoinepanau.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report