MALICIOUS — 48840346752.pdf
MALICIOUS — 48840346752.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3438b2ea63e9a7e21cf0ac98d3b39b9114da8ff10b9e1a0ff03089541212c9e9 - SHA-1:
4b2ddb12211a332904018800273967f2748faaf4 - MD5:
939757e0e357392505418fa731b27615 - ssdeep:
1536:NjFVeaGTh+wUUmcYfP1a2KiOSOdN2ELlSWYeQxwWz7ve0an+d7DJ0W8pO7dJ5:TVemwPmcYX1azigd+xeOa+dfJH7R - TLSH:
T19538BEF36147DD8CAB5A5F0369EB10A9A144D7846272EA6090C8737CD97C6BEBF10E40 - Submitted as: 48840346752.pdf
- File type: pdf · Size: 78144 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://nomayaku.com/userfiles/file/zeguxidobodutap.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://nusratali.com/userfiles/files/3637753892.pdf, http://www.laterveer-biesenbeek.nl/ckfinder/userfiles/files/nivuvejixasamebogevotoda.pdf, http://breakevenpoint.pl/uploads/editor/file/30655860927.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BvfzZFkJO3s/uplcv?utm_term=the+house+next+door+streaming
- http://nusratali.com/userfiles/files/3637753892.pdf
- http://www.laterveer-biesenbeek.nl/ckfinder/userfiles/files/nivuvejixasamebogevotoda.pdf
- http://breakevenpoint.pl/uploads/editor/file/30655860927.pdf
- http://aedelsur.com/contenido/files/wigekuburawa.pdf
- https://408of53crownstreet.com/assets/media/files/pupugularudupomofofogimun.pdf
- http://rayer.cn/d/files/movexosu.pdf
- https://leonardscopysystems.com/home/leonards/public_html/ckfinder/userfiles/files/nozuwufikabixowobilaj.pdf
- http://nomayaku.com/userfiles/file/zeguxidobodutap.pdf
- http://bptramptour.pl/files/file/49611890502.pdf
- http://auto4-spb.ru/public/images/ckfinder/files/96268380440.pdf
- https://middletonchambers.com/ckfinder/userfiles/files/levedenuzezifa.pdf
- http://agisma.ru/files/pages/files/79886851040.pdf
- http://albarossa.jp/js/upload/files/fatutukexegipaf.pdf
- http://gtlmarinefuel.com/userfiles/file/tagasekavumajirov.pdf
- https://www.asoriofrio.org/ckfinder/userfiles/files/vatarepazenabidudajedunas.pdf
- http://roocenter.ru/upload/file/50636949419.pdf
- http://teaterskolen-efteruddannelsen.dk/ckfinder/userfiles/files/31238456448.pdf
- http://magogaralbamoble.com/galeria/files/wuwerulipelil.pdf
- https://5udua.com/contents/files/81215308918.pdf
- https://holycrosshealthcare.com/userfiles/files/23946305435.pdf
- http://delve-cr.com/uploads/50767253853.pdf
- http://thuexedanang247.com/uploads/image/files/78301603170.pdf
- https://canoe.ro/Extras/ckfinder/userfiles/files/36461258722.pdf
- https://hotellemaritime.com/hotel/upload/files/juzabefijemaga.pdf
Embedded domains
- feedproxy.google.com
- nusratali.com
- www.laterveer-biesenbeek.nl
- breakevenpoint.pl
- aedelsur.com
- 408of53crownstreet.com
- rayer.cn
- leonardscopysystems.com
- nomayaku.com
- bptramptour.pl
- auto4-spb.ru
- middletonchambers.com
- agisma.ru
- albarossa.jp
- gtlmarinefuel.com
- www.asoriofrio.org
- roocenter.ru
- magogaralbamoble.com
- 5udua.com
- holycrosshealthcare.com
- delve-cr.com
- thuexedanang247.com
- hotellemaritime.com
- 52963566.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report