MALICIOUS — 76528449635.pdf
MALICIOUS — 76528449635.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3801e0fe5a6407322da628de33a939ed65639e85c8bc3844be64dcd00579e18c - SHA-1:
a1b32171d05401c8dcb4a3b7817874609b7999e0 - MD5:
97a3dd6e5130c0c0500ba041bfaca829 - ssdeep:
1536:jzWuh1oIy/6El81rJbU60ftJ+2kh7IoBaOZ02MjXGJoWpmiN+73icnWOpOaZ1IiR:/fzoT6El8Dbsnj6ufLG3m0c4aZ6Q - TLSH:
T17837C0F361A7ED4CA68F4B4739E520DC608BE7982466EA500588F67CE47C9BDBF00950 - Submitted as: 76528449635.pdf
- File type: pdf · Size: 74147 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://gsprojekt.eu/userfiles/files/xunubuzuxevunifatugegos.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://ei-windykacja.pl/upload/file/20005593436.pdf, http://singer-island-condos.com/userfiles/files/rofesifexesudebikoz.pdf, http://studiolorenzoni.eu/userfiles/files/wogubonegadigimelakugose.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/S30rS-6n6vg/uplcv?utm_term=bomag+bw120ad-3+parts+manual
- http://ei-windykacja.pl/upload/file/20005593436.pdf
- http://singer-island-condos.com/userfiles/files/rofesifexesudebikoz.pdf
- http://studiolorenzoni.eu/userfiles/files/wogubonegadigimelakugose.pdf
- http://www.pibmg.com.br/ckfinder/userfiles/files/files/20472402985.pdf
- http://www.ellisrasbetonwerke.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160c7b460643eb---jesilufilezoxulego.pdf
- http://ulrike-mayer.de/userfiles/files/44406628195.pdf
- http://www.maoles.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c9543cbb0fa---62338750811.pdf
- http://www.reroofingbrisbaneqld.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1611981d563d14---sezijivepogupavopexi.pdf
- http://ligneus.hu/upload/file/35223273988.pdf
- http://gsprojekt.eu/userfiles/files/xunubuzuxevunifatugegos.pdf
- http://trackeg.com/en/wp-content/plugins/formcraft/file-upload/server/content/files/1607b9964c658f---lobumusemidulodojopiwewer.pdf
- http://www.caslyn.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160731aace7be9---xewum.pdf
- http://karmand24.ir/basefile/ehotel724ir/files/najudepuzojabifitoga.pdf
- http://kleiberit.ru/files/file/vumok.pdf
- http://hutbephottaihaiphong24h.com/upload/files/lojidumamolijaxoke.pdf
- https://www.lang-mayer.de/wp-content/plugins/formcraft/file-upload/server/content/files/160a36a060dfa5---36107039357.pdf
- http://www.gradur.ba/wp-content/plugins/formcraft/file-upload/server/content/files/1607ed23b3a39b---71402737871.pdf
- http://redwoodpwr.com/wp-content/plugins/super-forms/uploads/php/files/gicmdv86r0sk6nogls8obqhec0/95222429591.pdf
- https://elnativocoffee.com/silver/upload/files/46913751075.pdf
- http://doktor-okonski.pl/uploadimg/file/bisarasibuwu.pdf
- https://lawpropertyconsultants.co.uk/wp-content/plugins/super-forms/uploads/php/files/li4ts2rrute5ooj0g9bfrcm6rb/raresilojide.pdf
- https://adepotcustom.com/UploadFiles/file/20210429121054130.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- ei-windykacja.pl
- singer-island-condos.com
- studiolorenzoni.eu
- www.pibmg.com.br
- www.ellisrasbetonwerke.co.za
- ulrike-mayer.de
- www.maoles.com
- www.reroofingbrisbaneqld.com.au
- gsprojekt.eu
- trackeg.com
- www.caslyn.co.za
- karmand24.ir
- kleiberit.ru
- hutbephottaihaiphong24h.com
- www.lang-mayer.de
- redwoodpwr.com
- elnativocoffee.com
- doktor-okonski.pl
- lawpropertyconsultants.co.uk
- adepotcustom.com
- www.w3.org
- purl.org
- ns.adobe.com
- ligneus.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report