MALICIOUS — 24959923256.pdf
MALICIOUS — 24959923256.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
12a0206424ceddfe0b519289453dd59ae9c32cf99cec3866722e35582d9299a8 - SHA-1:
14dd60a3c641bd69a271653c4ab4941fa5186144 - MD5:
e5ae706b31454c947c2f40d907a7b7b3 - ssdeep:
1536:s0lsh9tHqviZgYaZtxJHt/3p8QN9PdcTJWOpOwrKWy9+lL4CgW3LK:0vqvEgd9t3pxXP6TGwr4gB4ClO - TLSH:
T10C38BFF321E7DD8CB78BDB472AE71164B0C5E38861A2D6544088B66C907CA7EBF50920 - Submitted as: 24959923256.pdf
- File type: pdf · Size: 80089 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: Trojan:PDF/Phish.SSSP!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://yuqiaohome.com/uploads/files/202109040646057157.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://yuqiaohome.com/uploads/files/202109040646057157.pdf, http://pretaporter-pegah.com/userfiles/file/7933785468.pdf, http://www.hzkontejnery.cz/ckfinder/userfiles/files/58439093671.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/zMnd8XtcwSM/uplcv?utm_term=teardown+para+android+apk
- http://yuqiaohome.com/uploads/files/202109040646057157.pdf
- http://pretaporter-pegah.com/userfiles/file/7933785468.pdf
- http://www.hzkontejnery.cz/ckfinder/userfiles/files/58439093671.pdf
- http://gnox.vn/upload/files/69562230405.pdf
- http://dintainoodle.com/uploads/files/91542697935.pdf
- http://optikametuje.cz/userfiles/file/wukujik.pdf
- https://www.ayersworthglen.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613a90a9bc944---23299750138.pdf
- https://www.opsclown.it/ckfinder/userfiles/files/nakaxidagepusofopugezomu.pdf
- http://taketty.xyz/js/ckfinder/userfiles/files/nojisewodubaxisura.pdf
- http://casier-a-bouteilles.fr/file/10198405321.pdf
- http://mn-print.ru/ckfinder/userfiles/files/5927831183.pdf
- http://irinaburmistrova.ru/files/92503827494.pdf
- http://alwaysshine.com/fileimage/file/22722395882.pdf
- https://activsport.ro/userfiles/file/jutozik.pdf
- http://daehnfeldt.com/userfiles/file/69502046343.pdf
- http://elsekmont.eu/userfiles/file/97677935187.pdf
- http://demenagements-remond.fr/userfiles/file/20210902120846.pdf
- http://jiachuankeji.com/upload_fck/file/2021-9-12/20210912055650590442.pdf
- http://zoekidsworld.com/userfiles/file/8335390914.pdf
- http://kientrucphatloc.com/upload/files/sawokebuvajat.pdf
- http://dxline.eu/userfiles/file/saradoninudovasuz.pdf
- https://www.colegiodomus.com.br/js/ckfinder/userfiles/files/42393374528.pdf
- http://ctmmaximoravenna.com/ckfinder/userfiles/files/57617832425.pdf
- http://bitite.lv/media/txt/122/file/47397363660.pdf
Embedded domains
- feedproxy.google.com
- yuqiaohome.com
- pretaporter-pegah.com
- dintainoodle.com
- www.ayersworthglen.com
- www.opsclown.it
- taketty.xyz
- casier-a-bouteilles.fr
- mn-print.ru
- irinaburmistrova.ru
- alwaysshine.com
- daehnfeldt.com
- elsekmont.eu
- demenagements-remond.fr
- jiachuankeji.com
- zoekidsworld.com
- kientrucphatloc.com
- dxline.eu
- www.colegiodomus.com.br
- ctmmaximoravenna.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.hzkontejnery.cz
- gnox.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report