MALICIOUS — 8532994380.pdf
MALICIOUS — 8532994380.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0c8b55de82014a698608ce9e6bc416c61fe24821f2b48a544c4930bf0a6e38c8 - SHA-1:
68b4944fbe9d926e6692c6d354c8dfd055d15834 - MD5:
a185281d1d63b3eadf3bcb91899d0339 - ssdeep:
1536:qO4XYkgyHlSJ1bZwfqK8McrKQIZVyUWz1KOuZjxYWSRsWkNpOPaWeIA7ZQnVcNS5:F4XtgK8J8ZVyUWzruhoPM2nVcwKa - TLSH:
T1E539D1F320EBED4CB68B9B47697B11AC705ED6882172F710444876ACC0BC67EBE14661 - Submitted as: 8532994380.pdf
- File type: pdf · Size: 92149 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://callhfelectric.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d7a8039f603---84860133134.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://irlanc.ru/uplcv?utm_term=how+to+remove+permanent+marker+from+polyester+fabric, http://biotop-zamosc.pl/userfiles/file/juvamewitagikebam.pdf, https://maydongy.com/wp-content/plugins/super-forms/uploads/php/files/2plctbbmnc6se8lidnf5c3r5ke/28305774537.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://irlanc.ru/uplcv?utm_term=how+to+remove+permanent+marker+from+polyester+fabric
- http://biotop-zamosc.pl/userfiles/file/juvamewitagikebam.pdf
- https://maydongy.com/wp-content/plugins/super-forms/uploads/php/files/2plctbbmnc6se8lidnf5c3r5ke/28305774537.pdf
- https://tkpmission.org/wp-content/plugins/formcraft/file-upload/server/content/files/160a6217941b1e---fisukadigogo.pdf
- http://delshadian.com/public/userfiles/file/sesobarojurapapajesizurur.pdf
- http://www.k-24.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609677204e256---68371596975.pdf
- http://globeksa.com/ckfinder/userfiles/files/42597802156.pdf
- https://benjamindreyer.com/wp-content/plugins/super-forms/uploads/php/files/8a04ebfbdea6e0c4876aee54c9a439bf/pojubaxurejizuwivuramavar.pdf
- https://proff-doors.ru/wp-content/plugins/super-forms/uploads/php/files/bc90870a336712a2642871b26ee7e283/81698318593.pdf
- https://callhfelectric.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d7a8039f603---84860133134.pdf
- https://alphacleanwashing.com/wp-content/plugins/super-forms/uploads/php/files/bb26442666f561f129c7b4da96448b36/57660590252.pdf
- https://gift-edu.ru/wp-content/plugins/super-forms/uploads/php/files/d09d3b136fef5b337146d6b07b615c67/jageval.pdf
- https://www.cdscabling.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160b74cd15e9c4---tebab.pdf
- http://uniondeautoescuelas.com/wp-content/plugins/formcraft/file-upload/server/content/files/16089b3c020143---50327503520.pdf
- https://wfca-czech.cz/temp/userfiles/files/24454673990.pdf
- https://inclinedigital.com/wp-content/plugins/formcraft/file-upload/server/content/files/16093a4e40a52b---rejojofibukufanimug.pdf
- https://www.kalirich.com/wp-content/plugins/super-forms/uploads/php/files/7kpd3q240v10bjimqohjqk4dg0/37630074698.pdf
- http://www.britocunhaadvocacia.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/16094dc6febf1c---11794569913.pdf
- https://astoriareiki.com/wp-content/plugins/super-forms/uploads/php/files/df7a8656518c88aabee753c493640da9/57595814402.pdf
- https://stopserv.ru/files/file/tosopinozigoxefa.pdf
- http://www.chicagoalphas.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a808dc53f74---nugupipijabojafugitaziral.pdf
- https://loan-financial.com/wp-content/plugins/super-forms/uploads/php/files/ab990604ccdfa38e22b1f88bc2ad8b18/42642497683.pdf
- https://aokman-drive.com/d/files/zifamosagazutokumubolur.pdf
- http://veiligheidsslot.nl/ckfinder/userfiles/files/bebexovefajifo.pdf
- http://zdrowejaja.com/Upload/file/napuf.pdf
Embedded domains
- irlanc.ru
- biotop-zamosc.pl
- maydongy.com
- tkpmission.org
- delshadian.com
- www.k-24.com
- globeksa.com
- benjamindreyer.com
- proff-doors.ru
- callhfelectric.com
- alphacleanwashing.com
- gift-edu.ru
- www.cdscabling.co.uk
- uniondeautoescuelas.com
- inclinedigital.com
- www.kalirich.com
- www.britocunhaadvocacia.com.br
- astoriareiki.com
- stopserv.ru
- www.chicagoalphas.com
- loan-financial.com
- aokman-drive.com
- veiligheidsslot.nl
- zdrowejaja.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report