MALICIOUS — 93197009748.pdf
MALICIOUS — 93197009748.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
11e24720519c340b35619defa9df4f4cc80605411734a8f2967555ce4039daa2 - SHA-1:
007fc9035e99ba2037f95661ebea6109a3220ec8 - MD5:
3aedb45ec5a15577b0f8552424d75c71 - ssdeep:
1536:zdVzehlD4XGWbfaH1NHGFBa6aC2obPDSI1W+xf3LXGjIYrkW8pO7KMx:/yhlDsGF3HGn2obPDSIjbGsYr37j - TLSH:
T11039E0F3609BEC4D768B4F036CA61565A0C5D7CC5612D7948088FA1CD4BCABEBF00A51 - Submitted as: 93197009748.pdf
- File type: pdf · Size: 88550 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://dom-nenilovo.ru/wp-content/plugins/super-forms/uploads/php/files/33344b3af8d0dc89dee7a90afa9d09e3/61281627325.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://liniagdanskzydowo.pl/files/niviposorekat.pdf, http://recamonde.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160742609b03bb---vuvelagukuvul.pdf, http://dom-nenilovo.ru/wp-content/plugins/super-forms/uploads/php/files/33344b3af8d0dc89dee7a90afa9d09e3/61281627325.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1KS0DP0cxss/uplcv?utm_term=dengue+on+the+rise
- https://liniagdanskzydowo.pl/files/niviposorekat.pdf
- http://recamonde.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160742609b03bb---vuvelagukuvul.pdf
- http://dom-nenilovo.ru/wp-content/plugins/super-forms/uploads/php/files/33344b3af8d0dc89dee7a90afa9d09e3/61281627325.pdf
- https://paroles-vives.com/ckfinder/userfiles/files/71840944549.pdf
- https://sport-jicin.cz/dokumenty/nerilarogotawilokise.pdf
- http://blackshirts1962.com/clients/f/f2/f245580d3072b78cda2271cf7a7e3f61/File/96324546181.pdf
- http://tubietelbar.hu/uploadfile/14320038857.pdf
- https://luxmarketing.agency/wp-content/plugins/super-forms/uploads/php/files/plur9n66m1u3bos0lu6b3jhpl0/17210422432.pdf
- http://maidnheaven.com/wp-content/plugins/formcraft/file-upload/server/content/files/16088f4ef65998---56053430257.pdf
- http://asustainable.com/global/file/zododexosazitifesoxujo.pdf
- https://travelselection.us/wp-content/plugins/formcraft/file-upload/server/content/files/160e00f1f98a0e---82132136938.pdf
- http://www.majoriscambio.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160b1bcc8c6f15---lakuvegade.pdf
- http://bamt.be/wp-content/plugins/formcraft/file-upload/server/content/files/1607002fcd8748---kawibi.pdf
- https://alcc.vn/wp-content/plugins/super-forms/uploads/php/files/ddd2j0kvjv5ueqn8qq4vofah03/15883387312.pdf
- https://idfusionllc.com/wp-content/plugins/super-forms/uploads/php/files/9acf585719b877f57b63745f8d0b330a/73590891369.pdf
- http://krevue.cz/UserFiles/File/41416265488.pdf
- https://afriqueitnews.com/wp-content/plugins/super-forms/uploads/php/files/bbd11514bd33a408d9a06215a02b8190/90711323858.pdf
- http://jandebruijn.com/uploadimages/files/buloxo.pdf
- http://finsura-lifedirect.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1609ac9d55f46a---vonujujuridemofuwogaxi.pdf
- http://cuatro-pr.org/sites/default/files/file/sonaxukivenojegurisojawi.pdf
- https://actaviaserica.org/board/file/files/lasomutujexitisipovurefa.pdf
- https://caravanandre.it/wp-content/plugins/super-forms/uploads/php/files/9641a586cfdb75aa9a6ed44cb9c0a406/55664426427.pdf
- https://ewastexperts.com/userfiles/files/ratebeleda.pdf
- http://ivepe-elearning.gr/assets/UserFiles/mainHome/file/tujev.pdf
Embedded domains
- feedproxy.google.com
- liniagdanskzydowo.pl
- recamonde.com.br
- dom-nenilovo.ru
- paroles-vives.com
- blackshirts1962.com
- maidnheaven.com
- asustainable.com
- travelselection.us
- www.majoriscambio.com.br
- bamt.be
- idfusionllc.com
- afriqueitnews.com
- jandebruijn.com
- finsura-lifedirect.com.au
- cuatro-pr.org
- actaviaserica.org
- caravanandre.it
- ewastexperts.com
- flygarfield.net
- www.w3.org
- purl.org
- ns.adobe.com
- sport-jicin.cz
- tubietelbar.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report