MALICIOUS — 92945388751.pdf
MALICIOUS — 92945388751.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
24c7b3794374e73f76deac144d30b358196af934796aa22398d24c68a126ca2e - SHA-1:
e4abb7e637e1fe9ab1d435c801508c37d89ea71d - MD5:
8c0bb0ebff8ca55d9eed0f90331571ff - ssdeep:
1536:hMU1EvWT+PighHrBsQIvPyqhiNRgmSsP8bZo8LTPYpmJn:yh+T+hvojhU6mOZo8LTYS - TLSH:
T1A437CFF36657ED8CBD836B536AE6242C2016F78C2033EA640484BB6CD8B47BD3E14955 - Submitted as: 92945388751.pdf
- File type: pdf · Size: 70621 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!8C0BB0EBFF8C
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://www.benvenutialmare.com/wp-content/plugins/formcraft/file-upload/server/content/files/160783b74f1383---27601453847.pdf, https://interesttour.com/wp-content/plugins/super-forms/uploads/php/files/c37499ce9fdf1c4ced4f4bc9d0b5bcd0/muradepifepaxatuxar.pdf, https://www.dazzlingdecor.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16082d850b1eb8---labufiwipalunelajap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/6naE_Nh8_CY/uplcv?utm_term=grade+6+math+review+printable+worksheets
- http://www.benvenutialmare.com/wp-content/plugins/formcraft/file-upload/server/content/files/160783b74f1383---27601453847.pdf
- https://interesttour.com/wp-content/plugins/super-forms/uploads/php/files/c37499ce9fdf1c4ced4f4bc9d0b5bcd0/muradepifepaxatuxar.pdf
- https://www.dazzlingdecor.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16082d850b1eb8---labufiwipalunelajap.pdf
- http://www.redactordecontenidos.eu/wp-content/plugins/formcraft/file-upload/server/content/files/16074f7f19dd16---vudaxawimirujapeginilolul.pdf
- http://anhbanglaw.com/userfiles/file/kuvufavokuvixisefogonoju.pdf
- http://www.gcsystem.pl/wp-content/plugins/formcraft/file-upload/server/content/files/16073f35b708c2---72308707242.pdf
- https://pikewallis.no/wp-content/plugins/formcraft/file-upload/server/content/files/1606f5264a04b9---42703262968.pdf
- http://deurwater.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d639c75ee9---70871802653.pdf
- http://inspirationallabels.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1607474bed324d---82720722041.pdf
- http://creativeindustries.ru/uploads/userfiles/file/14973423697.pdf
- https://powermailer.in/userfiles/file/10971341661.pdf
- http://www.hydro-tg.pro/upload/file/89913421998.pdf
- https://formapolis.it/wp-content/plugins/super-forms/uploads/php/files/93c73621d4a8a1105809c8280ab87ed7/poxezipa.pdf
- https://www.geosuiteonline.de/wp-content/plugins/formcraft/file-upload/server/content/files/160837941669f6---lironevipamasog.pdf
- https://trsbarriersdirect.com/wp-content/plugins/super-forms/uploads/php/files/vdc5rg3odhlp2fsi7n67d8irum/71142472080.pdf
- https://takiminsahada.com/wp-content/plugins/super-forms/uploads/php/files/8v57da73fpsnpm4dlucnmd895v/gojatituravakuritoju.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- www.benvenutialmare.com
- interesttour.com
- www.dazzlingdecor.co.uk
- www.redactordecontenidos.eu
- anhbanglaw.com
- www.gcsystem.pl
- pikewallis.no
- deurwater.com
- inspirationallabels.co.uk
- creativeindustries.ru
- powermailer.in
- www.hydro-tg.pro
- formapolis.it
- www.geosuiteonline.de
- trsbarriersdirect.com
- takiminsahada.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report