MALICIOUS — 54353722030.pdf
MALICIOUS — 54353722030.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
1fe0d99435f4741c4568f85eb8e4ddebf94ffa45f0f0a50e3a4ef4ea803f707f - SHA-1:
9e72ea7335b4d78529d38492785034bb52e7f83c - MD5:
6ffeeca5ed8bb2d2eccd89552a12d277 - ssdeep:
1536:oLpkGR9OLVXGRUeV6JBx7GdJa6mVqWZ2TziwU+kpc3LQm/YzRbnaottQ/vwUHtRO:dGbOLV2XUAcqEwUHpcbYzpa2uvTHtRHu - TLSH:
T19037D0F31147CC4C698B6B037FA925DD748AD389A036E2C15884B79C84FC5BD7E249A1 - Submitted as: 54353722030.pdf
- File type: pdf · Size: 76212 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!6FFEECA5ED8B
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://www.nestroots.com/wp-content/plugins/super-forms/uploads/php/files/l5ilmvgctvtqoih5k9gq7oc506/mazebafesodosupomajunag.pdf, http://cambresisemploi.fr/ckfinder/userfiles/files/65338412101.pdf, https://craftsmancuttingdies.com/wp-content/plugins/super-forms/uploads/php/files/053a133cd2d859b2a5636df988da9d18/35688611166.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/ngfLrbzwjls/uplcv?utm_term=family+feud+questions+and+answers+tagalog
- https://www.nestroots.com/wp-content/plugins/super-forms/uploads/php/files/l5ilmvgctvtqoih5k9gq7oc506/mazebafesodosupomajunag.pdf
- http://cambresisemploi.fr/ckfinder/userfiles/files/65338412101.pdf
- https://craftsmancuttingdies.com/wp-content/plugins/super-forms/uploads/php/files/053a133cd2d859b2a5636df988da9d18/35688611166.pdf
- https://www.cr-sdc.org/wp-content/plugins/super-forms/uploads/php/files/1703978238c7884e8c614fadaf0190a2/fezediza.pdf
- http://antwerp-rentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c188f83d03d---disubomopubu.pdf
- https://ivanda-commerce.hr/userfiles/file/23862778862.pdf
- http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/nbfidoc43l29bamskuug2crt31/33357728202.pdf
- https://www.rath-catering.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609cb24ab5ebf---vubiponibubizekiwazuti.pdf
- http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1607e5ce98c106---84761468608.pdf
- http://houselandia.ru/files/34154478709.pdf
- http://mesotects.com/wp-content/plugins/formcraft/file-upload/server/content/files/160743c2bc7270---60427566447.pdf
- http://www.thelawchamber.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b982e67cb83---badoramopog.pdf
- http://nicenpos.com/userData/board/file/93812274677.pdf
- https://robertmatzuzi-massagetherapist.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160741edaea137---55141152208.pdf
- http://mesterek.net/tmp/43482107734.pdf
- https://www.helpforbusymums.com/wp-content/plugins/super-forms/uploads/php/files/b9d48340aa4d78cff8842a15aac6fe6c/kufika.pdf
- http://forter.vn/hinhanh/file/tiroromunoleta.pdf
- https://floorco.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/526cd3400e33d7fe4c9c0f9c4ed161f4/71710079462.pdf
- https://thetitangroup.ca/wp-content/plugins/super-forms/uploads/php/files/1afac66e2a7344ee1fc505829dd9f0de/22041207136.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- feedproxy.google.com
- www.nestroots.com
- cambresisemploi.fr
- craftsmancuttingdies.com
- www.cr-sdc.org
- antwerp-rentals.com
- www.sunarnuricomuisvealisverismerkezi.com
- www.rath-catering.de
- prodesign31.ru
- houselandia.ru
- mesotects.com
- www.thelawchamber.com
- nicenpos.com
- robertmatzuzi-massagetherapist.co.uk
- mesterek.net
- www.helpforbusymums.com
- floorco.allianceflooring.net
- thetitangroup.ca
- www.w3.org
- purl.org
- ns.adobe.com
- ivanda-commerce.hr
- forter.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report