MALICIOUS — 61039899852.pdf
MALICIOUS — 61039899852.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
28164df019caf74a0fc2fc3322eff96dacef395460ddccea0ed096a00d413780 - SHA-1:
0e0da2675e801b581fe07cf64694a8616abb2a59 - MD5:
09a194f94ba8e6c78c86e84d048a7398 - ssdeep:
1536:vZv+S9NpOkHKdO3naV91KvYY6bPy5AyjSW6pOu2T5zJhWh79GWrHMXtZ:JpNIkqdOn+91KwHbaayj/u2NzJa1rsn - TLSH:
T1C838CFF3717BCE5C7B86CB0369E7112C9089E7886135EAA04588B67C697C8BEAF10550 - Submitted as: 61039899852.pdf
- File type: pdf · Size: 82258 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://stellabakingcompany.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613ac23046246---88146475097.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=grammar+and+translation+method, http://majortaylorride.info/images/uploaded/file/55112386309.pdf, https://stellabakingcompany.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613ac23046246---88146475097.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=grammar+and+translation+method
- http://majortaylorride.info/images/uploaded/file/55112386309.pdf
- https://stellabakingcompany.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613ac23046246---88146475097.pdf
- https://biocoils.com/img/file/bojoduvaxinijigodedaza.pdf
- https://ph2020.org/ckfinder/userfiles/files/23225331132.pdf
- http://ledins.lv/cms/file/61708434277.pdf
- https://xyoaa.org/sites/default/files/files/luwob.pdf
- https://badeluxe.com/userfiles/files/89096286992.pdf
- https://chorland-dining.com/webroot/editor-uploads/files/72476098081.pdf
- http://kythuatviet.vn/uploads/userfiles/file/zaloxokefawuxexisura.pdf
- http://grimastone.ru/files/51885895832.pdf
- http://devison-matras.com/upload/file/80774401749.pdf
- https://clic-essc.ch/ck/ckfinder/userfiles/files/keziliseputegulaboj.pdf
- http://panhongbo.com/ckfinder/userfiles/site_eachfun_com/files/31249022551.pdf
- http://klasykarozrywki.pl/public/images/fck/file/sotadalaxexakot.pdf
- http://sahcarpets.com/userfiles/file/86018598573.pdf
- http://localhomesales.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/161371b11203d6---dalerilobowukugagirizo.pdf
- https://mavibusiness.it/file/71065173818.pdf
- http://nakloboucku.cz/uploaded/file/13464618115.pdf
- http://studiotecnicodambra.eu/userfiles/files/wugutoxuxoviwekolujibu.pdf
- https://htlexpress.com/ckfinder/userfiles/files/35307382974.pdf
- https://pianotuningdarwin.com/userfiles/files/8066869940.pdf
- http://idolyokocho.com/js/ckfinder/userfiles/files/75876522103.pdf
- http://vipacademy.org/userfiles/file/68914572918.pdf
- http://www.ibadirect.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613aba2dcfebb---gejoxido.pdf
Embedded domains
- huntic.ru
- majortaylorride.info
- stellabakingcompany.com
- biocoils.com
- ph2020.org
- xyoaa.org
- badeluxe.com
- chorland-dining.com
- grimastone.ru
- devison-matras.com
- clic-essc.ch
- panhongbo.com
- klasykarozrywki.pl
- sahcarpets.com
- localhomesales.com.au
- mavibusiness.it
- studiotecnicodambra.eu
- htlexpress.com
- pianotuningdarwin.com
- idolyokocho.com
- vipacademy.org
- www.ibadirect.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report