MALICIOUS — 24b388b86ad984c74a3a99c33f144fb7c8d397e88da14ba531b9499471774e00
MALICIOUS — 24b388b86ad984c74a3a99c33f144fb7c8d397e88da14ba531b9499471774e00 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
24b388b86ad984c74a3a99c33f144fb7c8d397e88da14ba531b9499471774e00 - SHA-1:
eb287bac716f5ea7156431c54ca8f67ed18e091a - MD5:
5b5f89ad0c68bf828f3296b835ae6b1a - ssdeep:
1536:9p73TqIpdLNPS77nkkGueXd4E+o7hB39SDy9WW0Y8D8vV2kWspORGh9:37lpdLu7NZetZbJ9/8KV2fRe - TLSH:
T1C739D0B370DBDE8C258BDB5359EA026CA09AD7992123EBA101CCA76CC43C53E7F10951 - Submitted as: 24b388b86ad984c74a3a99c33f144fb7c8d397e88da14ba531b9499471774e00
- File type: pdf · Size: 87553 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=types+of+oil+wells+pdf, http://podhoru.cz/userfiles/file/pexila.pdf, http://ibookingkr.com/FileData/ckfinder/files/20210713_53BB439FD9203211.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=types+of+oil+wells+pdf
- http://podhoru.cz/userfiles/file/pexila.pdf
- http://ibookingkr.com/FileData/ckfinder/files/20210713_53BB439FD9203211.pdf
- https://adlinefor.com/home/webagen/public_html/korn/data/file/beparizoxadixovadodamejuj.pdf
- http://yuha.be/_files/file/26961324232.pdf
- https://fwullong.com/upfiles/editor/files/wumokikekumeraxovolujateg.pdf
- http://www.cuerpomenteyespiritu.es/wp-content/plugins/formcraft/file-upload/server/content/files/160868f4295e56---xobasixi.pdf
- http://alituncer.com/userfiles/file/webupaw.pdf
- https://hmv.ir/wp-content/plugins/formcraft/file-upload/server/content/files/1609a66f95facf---nizoteranez.pdf
- http://tasteofruraleurope.eu/upload/File/21650929141.pdf
- https://sellerflows.com/wp-content/plugins/super-forms/uploads/php/files/34d9e26ac36578697250a44e8a949805/tuxuwuriviwip.pdf
- https://fidelishospice.com/ckfinder/userfiles/files/konifofe.pdf
- http://www.communityheroesproject.org/wp-content/plugins/formcraft/file-upload/server/content/files/160e662a0b9d26---72488078846.pdf
- http://www.hj-bouwt.be/wp-content/plugins/formcraft/file-upload/server/content/files/16085cf78d7850---10404194948.pdf
- https://makemycake.gr/wp-content/plugins/super-forms/uploads/php/files/5b6n54oa9kanc88si2dnmhqtro/woboju.pdf
- http://www.zav-mito.si/wp-content/plugins/formcraft/file-upload/server/content/files/16096025daac21---67662569643.pdf
- http://burchiellati.com/file_fck/file/94752549390.pdf
- https://nanyangtextile.com/userfiles/file/97729985271.pdf
- http://www.rkcomdesignservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/16073ada58c27d---69938658897.pdf
- https://kicksomeglass.com/wp-content/plugins/super-forms/uploads/php/files/42c58a39cbaf56da03ffb8b927920852/30229429639.pdf
- http://standartbio.com/fckfiles/file/mokafaz.pdf
- https://www.fecomerciomg.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/1609ca072bdbb5---5600217274.pdf
- http://sacmacbook.net/userfiles/file/lofenabudamanurited.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- huntic.ru
- ibookingkr.com
- adlinefor.com
- yuha.be
- fwullong.com
- www.cuerpomenteyespiritu.es
- alituncer.com
- hmv.ir
- tasteofruraleurope.eu
- sellerflows.com
- fidelishospice.com
- www.communityheroesproject.org
- www.hj-bouwt.be
- burchiellati.com
- nanyangtextile.com
- www.rkcomdesignservices.com
- kicksomeglass.com
- standartbio.com
- www.fecomerciomg.org.br
- sacmacbook.net
- www.w3.org
- purl.org
- ns.adobe.com
- podhoru.cz
- makemycake.gr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report