MALICIOUS — 92669628908.pdf
MALICIOUS — 92669628908.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3892104e5ec60b1b052a6d02cb2f05007b620908e519e8e541973d23f85629a5 - SHA-1:
b9bb74c11bd79f2d9e3663204db52bcc05df8e92 - MD5:
623ca41dc4923e018dc89ccf05a3e1c2 - ssdeep:
1536:7Ja1FWhHPU2XhHwCWitGAnEZYvrhRS4Dzz9bmBKudsWogUWGpOKCWMZhQ1MbRytf:YFWh82CNirEZYvrhR19yBKudsWouKMhW - TLSH:
T16339D0A360A7ED4C7B876B4359FB21ACA08AE3847136E6508188B76CD87C5BC7F14950 - Submitted as: 92669628908.pdf
- File type: pdf · Size: 88026 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.travelticket.com.au/wp-content/plugins/super-forms/uploads/php/files/np0bp1pfbi18bdpmqg3t7qmcos/pesozudiworizugojuleva.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://begemot-rus.com/uploadfiles/file/2021052521172273499.pdf, http://www.pirac.org/wp-content/plugins/super-forms/uploads/php/files/04544d425061e62d2113aaf82c3f5b51/vipezafofojuj.pdf, http://zzsz.hu/user/file/39352249313.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/6naE_Nh8_CY/uplcv?utm_term=how+to+lower+spin+rate+on+driver
- http://begemot-rus.com/uploadfiles/file/2021052521172273499.pdf
- http://www.pirac.org/wp-content/plugins/super-forms/uploads/php/files/04544d425061e62d2113aaf82c3f5b51/vipezafofojuj.pdf
- http://zzsz.hu/user/file/39352249313.pdf
- http://www.ibadirect.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607ea005c04d7---42400686359.pdf
- https://fuchscars.com/wp-content/plugins/super-forms/uploads/php/files/bf729f05138ae370c8357753358bae6e/44336806246.pdf
- http://www.airportlimofortlauderdale.net/wp-content/plugins/formcraft/file-upload/server/content/files/16087d6719ff54---bisusorusimegavok.pdf
- https://www.travelticket.com.au/wp-content/plugins/super-forms/uploads/php/files/np0bp1pfbi18bdpmqg3t7qmcos/pesozudiworizugojuleva.pdf
- http://malbreil.com/userfiles/file/xikofarusovatifomoku.pdf
- http://structurecreative.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a87e00dd55e---tixalosudivodusanivuvap.pdf
- https://christembassyromford.org/wp-content/plugins/super-forms/uploads/php/files/6a4b333388baf4472d6b9fcf9388ec2d/bemilajurarafexe.pdf
- https://www.tctnanotech.com/wp-content/plugins/super-forms/uploads/php/files/78f10bfa21aa089c584975f3e42e2d98/78077292125.pdf
- https://www.projectorrentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bf4df15ab16---bipanobivi.pdf
- http://www.dramayaramendes.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16076136a70d6c---87409218823.pdf
- https://siroyensao.com/upload/files/nemifededakuramuw.pdf
- https://fitnessrev.net/wp-content/plugins/super-forms/uploads/php/files/ea76i92vh6hnb9h70adqa2hh8p/74089109547.pdf
- https://dispomydeal.com/wp-content/plugins/super-forms/uploads/php/files/2af5cee47ff2a7cc8ce8c2344bf98568/90505438651.pdf
- http://rethabise.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160a47b07a127d---84631798623.pdf
- https://www.alphaveneers.com/wp-content/plugins/super-forms/uploads/php/files/76376702e9878e36fba0ae06da278856/tivevaduvarigiwububu.pdf
- https://myphi.biz/nbloom/fckuploads/file/wumugavukitinedixu.pdf
- http://centralcogtc.com/uploads/file/dufetabisikosowepebip.pdf
- http://www.urbanwaterways.info/files/71573876832.pdf
- https://www.sabiamente.es/wp-content/plugins/formcraft/file-upload/server/content/files/16091555926b14---zewibupoperulexino.pdf
- http://www.injamal.es/nueva/ckfinder/userfiles/files/66468931139.pdf
- https://catequesisnavarra.org/guiarte_userfiles/files/vodirazagofed.pdf
Embedded domains
- feedproxy.google.com
- begemot-rus.com
- www.pirac.org
- www.ibadirect.com
- fuchscars.com
- www.airportlimofortlauderdale.net
- www.travelticket.com.au
- malbreil.com
- structurecreative.com
- christembassyromford.org
- www.tctnanotech.com
- www.projectorrentals.com
- www.dramayaramendes.com.br
- siroyensao.com
- fitnessrev.net
- dispomydeal.com
- rethabise.co.za
- www.alphaveneers.com
- myphi.biz
- centralcogtc.com
- www.urbanwaterways.info
- www.sabiamente.es
- www.injamal.es
- catequesisnavarra.org
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report