MALICIOUS — 299809eb85a846728609b2eb492357fc125bd79bceb6f8d1eceb7495ea5729ff
MALICIOUS — 299809eb85a846728609b2eb492357fc125bd79bceb6f8d1eceb7495ea5729ff is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
299809eb85a846728609b2eb492357fc125bd79bceb6f8d1eceb7495ea5729ff - SHA-1:
b0704eb7452e436919ae3c9209dbd3b8466cf657 - MD5:
e4310e62a6dd243bcc447c04860bf89b - ssdeep:
1536:99hDxjMcmJu8RRV5dzP1fh3Cds7cjiWx0Pa3W8pO73Wjo8mC7F2+pqMzI:zpmcmJfH5dh3CpxoaK7uo8mIFvqr - TLSH:
T1CD39C0F3609BDD4CB3879B03ACF92169655AE7886262DEA0408C766CD4FC4BD7F04A11 - Submitted as: 299809eb85a846728609b2eb492357fc125bd79bceb6f8d1eceb7495ea5729ff
- File type: pdf · Size: 91155 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://oniceh.ru/uplcv?utm_term=shortcut+key+for+refresh+in+laptop, http://morgancountyoh.com/userimages/tatapegatosujina.pdf, https://www.taxikladis.gr/wp-content/plugins/formcraft/file-upload/server/content/files/16070dd5e6f8ce---52943782322.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oniceh.ru/uplcv?utm_term=shortcut+key+for+refresh+in+laptop
- http://morgancountyoh.com/userimages/tatapegatosujina.pdf
- https://www.taxikladis.gr/wp-content/plugins/formcraft/file-upload/server/content/files/16070dd5e6f8ce---52943782322.pdf
- http://leadershipcareer.kr/fckeditor/_upload/file/sovifatetagipilojidip.pdf
- https://mabuksusu.com/contents//files/12191684249.pdf
- https://socialchangefactory.org/wp-content/plugins/super-forms/uploads/php/files/0591f9a4f3e3554187957f3aa78057a7/45877316687.pdf
- http://centronegozi.com/public/rufobuxek.pdf
- https://hpx.com.ua/wp-content/plugins/super-forms/uploads/php/files/e5d3692f506cde92d9503a068987c685/78061928408.pdf
- https://www.lightingdynamics.com/wp-content/plugins/super-forms/uploads/php/files/4b4ede4a2f17e50a371ac9a0d267fb80/78085532311.pdf
- http://anhuizhkj.com/upload_fck/file/2021-5-5/20210505105859780164.pdf
- http://thienminhgroup.com/uploads/userfiles/file/lisikugagitedikaso.pdf
- http://mtcnx.com/upload/fckimagesfile/17120340117.pdf
- https://cplastik.cz/data/cms/file/defevule.pdf
- https://www.glasswindowequipment.com/wp-content/plugins/super-forms/uploads/php/files/aa131d457c745c7e41615f87fbc938b8/647483973.pdf
- http://www.saito-ken.jp/userdata/file/vubuliti.pdf
- http://getawaynewzealand.co.nz/wp-content/plugins/formcraft/file-upload/server/content/files/16094b1da2da1d---tujanazalovamowuwadem.pdf
- http://emilymillerlaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/betusesevejutemo.pdf
- http://www.kowel.com/ckfinder/userfiles/files/1626095309.pdf
- https://www.frankcapassoandsons.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a828b8c785---puzegujuwexixudirerof.pdf
- https://boumqueur-edition.com/upload/fckeditor/file/80216353802.pdf
- https://infoenergie-loire.org/userfiles/file/68117110324.pdf
- http://www.laterveer-biesenbeek.nl/ckfinder/userfiles/files/62356495973.pdf
- https://cruiseship.cruises/wp-content/plugins/super-forms/uploads/php/files/5ckub5l9e7999nkgf11s4ofhpb/60101886876.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- oniceh.ru
- morgancountyoh.com
- leadershipcareer.kr
- mabuksusu.com
- socialchangefactory.org
- centronegozi.com
- hpx.com.ua
- www.lightingdynamics.com
- anhuizhkj.com
- thienminhgroup.com
- mtcnx.com
- www.glasswindowequipment.com
- www.saito-ken.jp
- emilymillerlaw.com
- www.kowel.com
- www.frankcapassoandsons.com
- boumqueur-edition.com
- infoenergie-loire.org
- www.laterveer-biesenbeek.nl
- www.w3.org
- purl.org
- ns.adobe.com
- www.taxikladis.gr
- cplastik.cz
- getawaynewzealand.co.nz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report