MALICIOUS — 14065636223.pdf
MALICIOUS — 14065636223.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1d7f3b0ab5a3e04efadad40abd6d579cc2eed6c35355912362ad5e3e5d92e2b8 - SHA-1:
1b1c9a5f4232d51979b5cbfd46046f9f2d105a8b - MD5:
83eea79a22d40d0acbead8ffa7b2442d - ssdeep:
1536:/AcpBVsrtiuUJhXu4avlKTDIKU9Q56F69gImck6WXpO/o2o+rhcWL87YDbE2:zBkiJhXuVNKTIC56pxcP/xX7V - TLSH:
T16339C0F3624FDD4CA64B8B036AFA11A9608AE68C7252EB50908C777CD4BC5BD3F04951 - Submitted as: 14065636223.pdf
- File type: pdf · Size: 89852 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://monacollection.ua/wp-content/plugins/super-forms/uploads/php/files/2a1d6516592ef938e4831f9be23c1a02/95353244131.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://teenvolunteerdallas.org/wp-content/plugins/super-forms/uploads/php/files/70b2ed285b0f4487f385a41d4a5dd399/bubukewidanarujujak.pdf, http://pensacolahigh1964.com/clients/1/1d/1d652d7f5bd5fd2f3712913460b20393/File/54389046649.pdf, https://slaterlighting.com/wp-content/plugins/super-forms/uploads/php/files/f262c0da03a6da4ac18c37893d627b8d/81424977929.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=ralph+waldo+emerson+famous+quotes+from+self+reliance
- https://teenvolunteerdallas.org/wp-content/plugins/super-forms/uploads/php/files/70b2ed285b0f4487f385a41d4a5dd399/bubukewidanarujujak.pdf
- http://pensacolahigh1964.com/clients/1/1d/1d652d7f5bd5fd2f3712913460b20393/File/54389046649.pdf
- https://slaterlighting.com/wp-content/plugins/super-forms/uploads/php/files/f262c0da03a6da4ac18c37893d627b8d/81424977929.pdf
- http://terrietanaka.com/library/files/mubadazitexurodux.pdf
- http://sushikyototogo.com/uploads/files/28196007910.pdf
- http://mya1fc.com/files/ckuploads/files/vokelafuguwago.pdf
- https://webhostmurah.com/wp-content/plugins/formcraft/file-upload/server/content/files/160944a538f104---vararolejedarur.pdf
- http://grandfiltr.com/files/file/16895266589.pdf
- https://monacollection.ua/wp-content/plugins/super-forms/uploads/php/files/2a1d6516592ef938e4831f9be23c1a02/95353244131.pdf
- https://www.chauffeur-prive-nice.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1607252288bfa3---62857970791.pdf
- http://pansophers.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b745a8bb1cc---16315033463.pdf
- https://ludifrance.fr/userfiles/file/rololira.pdf
- https://tvmreza.tv/ckfinder/userfiles/files/kolufolirerefafoxe.pdf
- http://limobebe.com/userfiles/files/kuzunawufujabep.pdf
- https://mosaicopeoplecorporation.com/ckfinder/userfiles/files/93670323679.pdf
- http://rentbucharest.net/images/userfiles/famivejemeb.pdf
- https://mbzgogo.xyz/web/img/podborky/files/53426624287.pdf
- https://himalmanpower.com/ckfinder/userfiles/files/kirutesinoxapabuwoduvi.pdf
- http://tomaszfilipczak.pl/userfiles/file/43193842087.pdf
- http://www.fliesen-brill.de/wp-content/plugins/formcraft/file-upload/server/content/files/160cd5391c8f1f---69832655390.pdf
- http://amghanoi.com/images/ckeditor/files/87779320390.pdf
- http://asja-doll.ru/userfiles/file/timumenug.pdf
- http://ud2-140.com/files/97723822276.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- teenvolunteerdallas.org
- pensacolahigh1964.com
- slaterlighting.com
- terrietanaka.com
- sushikyototogo.com
- mya1fc.com
- webhostmurah.com
- grandfiltr.com
- monacollection.ua
- www.chauffeur-prive-nice.fr
- pansophers.com
- ludifrance.fr
- tvmreza.tv
- limobebe.com
- mosaicopeoplecorporation.com
- rentbucharest.net
- mbzgogo.xyz
- himalmanpower.com
- tomaszfilipczak.pl
- www.fliesen-brill.de
- amghanoi.com
- asja-doll.ru
- ud2-140.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report