MALICIOUS — 22312124775.pdf
MALICIOUS — 22312124775.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1c0277784f825f95ff9c4ae9d949ee3b327b579e1c5b6d38432d5e7996e27511 - SHA-1:
55d8980e4450f8d4e8351548e2f39bf499753671 - MD5:
c42e81cc4333e5fcd9e79d48564c6437 - ssdeep:
1536:F3jYUTO6xpdizREF4JsrJ5NZXLSYXzq3aY2JLLG1lWXKPWOpOaZEWVKY9AHuvkR2:ainPnNSYDqqxLYlkKgaZhbIY - TLSH:
T12038C0F321A7DC4C77CACF4369EA12A85486D3886122EB6111CCBA6CC5BC5BC7E50D91 - Submitted as: 22312124775.pdf
- File type: pdf · Size: 80329 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://fszhenjia.com/upfolder/e/files/20210904131847.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://kalatranslation.co.uk/wp-content/plugins/super-forms/uploads/php/files/61ib0ftk4r2gsk8lv9s74oc716/fimedug.pdf, http://jenan.com/ckfinder/userfiles/files/17430629378.pdf, https://storage-in-motion.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f8f3f40652---65887253474.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/1xuhb7AK25c/uplcv?utm_term=print+protected+pdf+mac
- https://kalatranslation.co.uk/wp-content/plugins/super-forms/uploads/php/files/61ib0ftk4r2gsk8lv9s74oc716/fimedug.pdf
- http://jenan.com/ckfinder/userfiles/files/17430629378.pdf
- https://storage-in-motion.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f8f3f40652---65887253474.pdf
- http://secretinvitation.net/images/files/noxopiwe.pdf
- https://bleikss.com/userfiles/file/bozodogejedav.pdf
- http://fogathajtohirek.hu/fckfiles/file/4533977322.pdf
- http://fszhenjia.com/upfolder/e/files/20210904131847.pdf
- http://uhy-th.com/image/upload/files/94799002915.pdf
- https://relaxbotanika.cz/ckfinder/userfiles/files/godewomixuwuronemamutufan.pdf
- http://divodizain.ru/ckfinder/userfiles/files/jegeberadexumolijeluji.pdf
- http://marcelponjee.nl/ponjeefiles/file/45518204491.pdf
- https://jjpremiers.com/files/lunewobuze.pdf
- http://puntolinea.org/userfiles/files/20833179606.pdf
- http://rjt1.org/upload/files/22682234918.pdf
- http://www.majbrno.cz/uploads/files/92470510727.pdf
- http://innotec-industrie.be/userfiles/file/94966648911.pdf
- https://njsolarpower.com/wp-content/plugins/super-forms/uploads/php/files/930eb63dd5e62123b98c5a942dd69a1b/18696154892.pdf
- https://www.bouldersudbury.org/wp-content/plugins/formcraft/file-upload/server/content/files/16138b8ca7a0a5---mudevonagunikuvatesinod.pdf
- http://dichvutheapec.com/upload/FCK/file/xolidagategazo.pdf
- http://linpus.com/app/webroot/userfiles/files/fizamuxajofanofemuki.pdf
- http://shbaicun.com/userfiles/file/2021090512561173499.pdf
- http://www.lukoilmarine.com/ckfinder/userfiles/files/pawikoramigosisuvelowero.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- kalatranslation.co.uk
- jenan.com
- storage-in-motion.com
- secretinvitation.net
- bleikss.com
- fszhenjia.com
- uhy-th.com
- divodizain.ru
- marcelponjee.nl
- jjpremiers.com
- puntolinea.org
- rjt1.org
- innotec-industrie.be
- njsolarpower.com
- www.bouldersudbury.org
- dichvutheapec.com
- linpus.com
- shbaicun.com
- www.lukoilmarine.com
- www.w3.org
- purl.org
- ns.adobe.com
- fogathajtohirek.hu
- relaxbotanika.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report