MALICIOUS — 69873411279.pdf
MALICIOUS — 69873411279.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3b2724578fd96ec0c4c988a7f4c23a0ebc4f0cfb5f2e68565095a3f2645f6f01 - SHA-1:
c809e605bca3b25237d861769537d8309db47086 - MD5:
b9bc66b7eb3bdb2663eeb1c5f9071956 - ssdeep:
1536:G8sLl6SPIh4CYxmKuvPiEF0VjShJo+zvRwWGpOKCWoyY+sXWKPhXHP:Psp6SPhCtKuvTF08hy+zvRFKBsXWKPhf - TLSH:
T1FE38C0F331DBDE8C774B9F0769A601D8B489E3C82272DB5051887A9C987C97DBE10611 - Submitted as: 69873411279.pdf
- File type: pdf · Size: 76805 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://betonkeritesek.eu/Content/files/mimedavezazuwinakisa.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=subway+surfers+for+pc+apk+download, https://www.elementstraining.co.uk/wp-content/plugins/super-forms/uploads/php/files/gjut8k0b2uqear1v4m6cf0gdhn/fujogezabuta.pdf, http://louisiana-arts.org.s150269.gridserver.com/siteuploads/editorimg/file/72580153414.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pistant.ru/uplcv?utm_term=subway+surfers+for+pc+apk+download
- https://www.elementstraining.co.uk/wp-content/plugins/super-forms/uploads/php/files/gjut8k0b2uqear1v4m6cf0gdhn/fujogezabuta.pdf
- http://louisiana-arts.org.s150269.gridserver.com/siteuploads/editorimg/file/72580153414.pdf
- http://westernstudioservice.com/admin/userfiles/file/dotawafimafiguwadumilefiw.pdf
- http://zadonskiy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16139f5df2ba3d---39335325556.pdf
- https://transcendenceit.com/wp-content/plugins/super-forms/uploads/php/files/577956cc118e3cc2c5a29cdad1188aed/xokixebatasenifeto.pdf
- http://pyroglobal.sk/app/webroot/files/userfiles/files/31501045534.pdf
- http://gz-theoutfit.com/UploadFiles/FCKeditor/20210913151139.pdf
- http://betonkeritesek.eu/Content/files/mimedavezazuwinakisa.pdf
- https://lazerom.pro/media/file/galewubokujajuxa.pdf
- https://ldoris.com/upfile/files/20210915174458.pdf
- https://idosekotthonaveresegyhaz.hu/files/files/pefekukitepejixozabofira.pdf
- https://www.gml.de/wp-content/plugins/formcraft/file-upload/server/content/files/16146a062f31b1---pozoforibis.pdf
- http://talentfuturesservices.com/sharpinstitute/images/files/18040445440.pdf
- https://ctcitsupport.com/media/files/lerimapedaxugotivafuponi.pdf
- https://jills.reviewz.eu/app/webroot/files/userfiles/files/juwogodidobipavujiviz.pdf
- http://hcvitamin.com/webroot/img/files/72121348462.pdf
- https://www.saltriot.com/wp-content/plugins/super-forms/uploads/php/files/a8097898bf7c83d53d368fb48aac67fe/35586459249.pdf
- http://personal.sut.ac.th/chantira/port/ckfinder/userfiles/files/58734852316.pdf
- http://traiteurluc.com/userfiles/file/94090727388.pdf
- http://agrocare.hu/ckfinder/userfiles/files/59266497317.pdf
- http://phamtrangia.site/upload/files/96111814905.pdf
- https://tsegypt.com/file/wabewuwiluxipege.pdf
- http://htbestcomputer.com/media/ftp/file/56837075168.pdf
- http://yearbookplus.com/uploads/ckfinder/files/17426039617.pdf
Embedded domains
- pistant.ru
- www.elementstraining.co.uk
- louisiana-arts.org.s150269.gridserver.com
- westernstudioservice.com
- zadonskiy.ru
- transcendenceit.com
- gz-theoutfit.com
- betonkeritesek.eu
- lazerom.pro
- ldoris.com
- www.gml.de
- talentfuturesservices.com
- ctcitsupport.com
- jills.reviewz.eu
- hcvitamin.com
- www.saltriot.com
- traiteurluc.com
- phamtrangia.site
- tsegypt.com
- htbestcomputer.com
- yearbookplus.com
- sunriverps.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report