MALICIOUS — satajedulil.pdf
MALICIOUS — satajedulil.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
35a23f4ce50f7d6b5fc392a14e17959cb93aa5fbf096fae6f49d6b2287c2588a - SHA-1:
55beb9ddef74b4bf342e7e929f898ee680f70398 - MD5:
67c2cf7ce7317e779c82404320bf79fa - ssdeep:
1536:yLgdxYeHoH+czPfhYNMvxUUIIjGbG96GpdQQDBjKBy:bdWjzn6NMZUUI2GbQ6OdQQDBjl - TLSH:
T18737DFF36147DE5C3BCBAF4399E6116D208BD1482027D7B80488B37CC5B8ABE6E54A51 - Submitted as: satajedulil.pdf
- File type: pdf · Size: 71029 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!67C2CF7CE731
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://velvetskin.pl/wp-content/plugins/super-forms/uploads/php/files/3ad09d397837fa6bb99d1b01199b8333/13092679288.pdf, http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080e456ac677---44084737300.pdf, https://lostsoulsmemorialnj.org/wp-content/plugins/super-forms/uploads/php/files/3d993197f1272268f98af8681f6dd48b/jegolura.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/fzgW7-mxBc0/uplcv?utm_term=is+there+a+hotspot+app
- https://velvetskin.pl/wp-content/plugins/super-forms/uploads/php/files/3ad09d397837fa6bb99d1b01199b8333/13092679288.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080e456ac677---44084737300.pdf
- https://lostsoulsmemorialnj.org/wp-content/plugins/super-forms/uploads/php/files/3d993197f1272268f98af8681f6dd48b/jegolura.pdf
- https://proff-doors.ru/wp-content/plugins/super-forms/uploads/php/files/ec2d809a863a265cefcb216f9e831b97/guxumugufejurixo.pdf
- https://churchosonline.com/wp-content/plugins/super-forms/uploads/php/files/8fffdc9842f4c327c136e81ffd02e025/61416150024.pdf
- https://www.mozartcantat.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607b73151e22c---luxodomijorirenomulaxiv.pdf
- https://www.chinacimctrailer.com/wp-content/plugins/super-forms/uploads/php/files/69f63edabe2e6fa48d4d26f325e902ef/nenebajefewupipubowexan.pdf
- http://www.191seo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a0166f43770---69925109326.pdf
- https://sckprime.com/wp-content/plugins/super-forms/uploads/php/files/f6fbba31b15f4cbb0decdb8304b1d2dd/68863852475.pdf
- https://aliencosmicexpo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607216b927674---tabovesabogisinobakokafut.pdf
- http://dynamic1984.com/user_file/file/8768133052.pdf
- http://www.molinoag.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607560c58a893---joxug.pdf
- http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/b4e553184e871d0435657d5101f6d8ea/rofupegiz.pdf
- http://anaminfo.com/attachfile/file/80433379934.pdf
- http://www.kissdocs.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16070a86ddd01d---4212789539.pdf
- https://maxim-catering.de/wp-content/plugins/super-forms/uploads/php/files/f9puugkv3fpt902mi956fskfdl/pinikarin.pdf
- http://www.191seo.com/wp-content/plugins/formcraft/file-upload/server/content/files/16083b90f089a3---15548229926.pdf
- https://landlorddebtadvisory.com/wp-content/plugins/super-forms/uploads/php/files/93273be04h2mbv05i801qotsp3/rurexebiwituwijusorux.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- velvetskin.pl
- www.1000ena.com
- lostsoulsmemorialnj.org
- proff-doors.ru
- churchosonline.com
- www.mozartcantat.nl
- www.chinacimctrailer.com
- www.191seo.com
- sckprime.com
- aliencosmicexpo.com
- dynamic1984.com
- www.molinoag.com
- chagatea.ru
- anaminfo.com
- www.kissdocs.com.au
- maxim-catering.de
- landlorddebtadvisory.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report