MALICIOUS — 94091843693.pdf
MALICIOUS — 94091843693.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
19ac9b1b038e406639892bbf9e624d9b9f6f04f34b2c43b2ecb99c0b89f47d13 - SHA-1:
519467fab72d9fe1d6701caf166237ad9f69ea60 - MD5:
3624248aefc9c7a25dd41a79d7ee9e2c - ssdeep:
1536:LEavH/T5haJHENmt9izzeJIsuiakDdV4VHWehaWapOtQ0rfM0IWuDsb:1th7obizzeusdakDd6hHtQ0jITg - TLSH:
T14137BEF7608BDD8C7B8FDB0369D611AE6489D78922629B40048877BC917D87DBF40E20 - Submitted as: 94091843693.pdf
- File type: pdf · Size: 75453 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://zwickerfoto.hu/_user/file/zupunabe.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://garglob.ru/uplcv?utm_term=2012+subaru+legacy+2.5i+manual, https://protechlighting.com/wp-content/plugins/super-forms/uploads/php/files/b7aa4377b9284a8f924f8ee104b02360/kupufekuxadufugavoga.pdf, https://www.sadcmedia.com/wp-content/plugins/super-forms/uploads/php/files/2hehea8dr9eoak06ejo5i2ensr/vatamuripedirokanarexa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://garglob.ru/uplcv?utm_term=2012+subaru+legacy+2.5i+manual
- https://protechlighting.com/wp-content/plugins/super-forms/uploads/php/files/b7aa4377b9284a8f924f8ee104b02360/kupufekuxadufugavoga.pdf
- https://www.sadcmedia.com/wp-content/plugins/super-forms/uploads/php/files/2hehea8dr9eoak06ejo5i2ensr/vatamuripedirokanarexa.pdf
- https://vegastel.eu/components/com_mijoshop/opencart/image/data/files/45596691761.pdf
- http://speed-r.com/js/upload/files/89761253836.pdf
- http://scea.edu.mn/ckfinder/userfiles/files/jirorisetinanufafukutol.pdf
- https://newat.ru/wp-content/plugins/super-forms/uploads/php/files/dbc151b604661eba7be1a570446db5b8/47973950220.pdf
- https://www.sir.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160893b38cee9b---2366785729.pdf
- http://zwickerfoto.hu/_user/file/zupunabe.pdf
- https://bcbc3399.com/upload/files/wuseremesiguru.pdf
- http://proxima-design.cz/files/file/bejogo.pdf
- https://noihoithanhtuan.com/media/ftp/file/tuvudatirufufajiwuduna.pdf
- http://www.primalegal.eu/wp-content/plugins/super-forms/uploads/php/files/i70ui5tk9n46li35cdo58feie6/33448276952.pdf
- http://wypelnienia.kratex.pl/wp-content/plugins/super-forms/uploads/php/files/f637120e889d3fe44456054177415793/nilemopagegaziragoko.pdf
- https://www.fecomerciomg.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/160ad51e8be12c---90321655839.pdf
- https://euroquimicadistribucion.com/zabaleta/data/imagenes_contenidos/file/32806490696.pdf
- https://aadhaarretail.com/administrator/imagetemp/file/39007955000.pdf
- https://polytex.de/sites/default/files/zefen.pdf
- http://vetcasatenovo.it/userfiles/files/73021918220.pdf
- https://www.andimoda.com/wp-content/plugins/super-forms/uploads/php/files/36de50746e4aacbc6d39ab4c4bf1cd37/pasekezelofizebi.pdf
- http://csc020.com/userfiles/file/20210704124153_cr6p9o.pdf
- http://sjar-tech.com/uploadfile/file///2021051721502163.pdf
- https://coloreverything.love/wp-content/plugins/super-forms/uploads/php/files/0c74b1e3a619d0c182b39e8ab43e0ec7/26142703241.pdf
- https://daquin-ferriere.fr/userfiles/file/ravixurifumelagum.pdf
- http://amwordpress.org/wp-content/plugins/formcraft/file-upload/server/content/files/16089c0367ce82---95389585599.pdf
Embedded domains
- garglob.ru
- protechlighting.com
- www.sadcmedia.com
- vegastel.eu
- speed-r.com
- newat.ru
- www.sir.co.uk
- bcbc3399.com
- noihoithanhtuan.com
- www.primalegal.eu
- wypelnienia.kratex.pl
- www.fecomerciomg.org.br
- euroquimicadistribucion.com
- aadhaarretail.com
- polytex.de
- vetcasatenovo.it
- www.andimoda.com
- csc020.com
- sjar-tech.com
- daquin-ferriere.fr
- amwordpress.org
- lecachet.fr
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report