MALICIOUS — 74494569336.pdf
MALICIOUS — 74494569336.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
17fe2aaf2a044b421dac160415373d63468df7aea55d4695c127343edef98cf7 - SHA-1:
8c8fb91330c9e0889425ce98d94fa42fc7ca75a0 - MD5:
8ff7c07ddfe3192cf28337829242c1d8 - ssdeep:
1536:RSyIJvx2fyptfLTb83Qbsb9vpmzWWgoWPE6yX1OLv/VEUvWDiSQfk6WspORLoTKv:kyIJJIyPLTb83Qw9vpyWWgU6o1a/VEUW - TLSH:
T10139D0F330B7DD4C368BD74358E91168A5CADB04A126C65085CCB92CE4BC5BDBF206A1 - Submitted as: 74494569336.pdf
- File type: pdf · Size: 87247 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://ambulatorioveterinariomariani.it/userfiles/files/12362563283.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://rayanchem.com/d/files/31229494574.pdf, http://www.libroparlatolions.it/backoffice/ckfinder/userfiles/files/5095060442.pdf, https://santehsevast.ru/userfiles/files/kinofaxubobiwedetudut.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/LPIa9PGmDLg/uplcv?utm_term=how+to+remove+pin+from+android+lock+screen
- http://rayanchem.com/d/files/31229494574.pdf
- http://www.libroparlatolions.it/backoffice/ckfinder/userfiles/files/5095060442.pdf
- https://santehsevast.ru/userfiles/files/kinofaxubobiwedetudut.pdf
- http://nofatrans-int.com/userfiles/file/61108120215.pdf
- https://precisionautoandac.com/wp-content/plugins/super-forms/uploads/php/files/92f187c2feb46bd9b94f0596b2c77251/85939299791.pdf
- http://lotuscourtpune.com/wp-content/plugins/super-forms/uploads/php/files/016c2f0c277d1582f92b52e5b3c84a4c/ruxigafanezuvopudininep.pdf
- http://ambulatorioveterinariomariani.it/userfiles/files/12362563283.pdf
- http://odumakus.com/uploads/files/77274702849.pdf
- http://finemetal-cn.com/upload/files/zaxoxikamimadugofifatekik.pdf
- http://vicc.huh.hu/UserFiles/File/57111706868.pdf
- https://ph789.com/pinhsuan/files/file/76503356391.pdf
- http://timnhanhonline.com/upload/files/57256309742.pdf
- http://allegroescrow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613e561735bfe---95258291742.pdf
- http://manpukulivermore.com/uploads/files/72476334549.pdf
- http://dubilex.com/userfiles/files/selotewuguvavaxunomuxi.pdf
- https://aedwea.com/upload/foto/vovaripuvid.pdf
- http://vce34.ru/attachments/file/sevimugotip.pdf
- https://giriconsultancy.com/content_files/files/wixorenonuwalasamenanavod.pdf
- https://soalmatematik.com/userfiles/file/41430864362.pdf
- http://hexindechem.com/upload/files/27237036695.pdf
- https://aayams.com/userfiles/file/17709493143.pdf
- http://xn--oy2b9bv81anouola.com/upload/file/202109081729116997.pdf
- https://woodfur.in/userfiles/file/70914162345.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- rayanchem.com
- www.libroparlatolions.it
- santehsevast.ru
- nofatrans-int.com
- precisionautoandac.com
- lotuscourtpune.com
- ambulatorioveterinariomariani.it
- odumakus.com
- finemetal-cn.com
- ph789.com
- timnhanhonline.com
- allegroescrow.com
- manpukulivermore.com
- dubilex.com
- aedwea.com
- vce34.ru
- giriconsultancy.com
- soalmatematik.com
- hexindechem.com
- aayams.com
- xn--oy2b9bv81anouola.com
- woodfur.in
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report