MALICIOUS — 67969763905.pdf
MALICIOUS — 67969763905.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
3bd286cac9df1abb368ce56d6d28a47da7e6042c4247d3038b83103869614815 - SHA-1:
b1a4cbb2d5179ada7869e0eeb10a5405e1e88df1 - MD5:
3d6663e402a03f3c7525766f06a2d95b - ssdeep:
1536:z/bzTgFj1QItMxwIjLxxOt7zcRidgSn/QWkNpOPaW/rbwxTD8RscS7ri9:Dbzkp1XKDLxxOtPhuAPBwN8OpA - TLSH:
T1C439C0F321C7DC5C7A87AB0369AA116C6189E7882162EEA044CCB7ECD9BC47DFE04551 - Submitted as: 67969763905.pdf
- File type: pdf · Size: 86742 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://webtraffic.ch/wp-content/plugins/super-forms/uploads/php/files/g92b6c0mick5fpuhtm9omngvna/kukidi.pdf, https://gagiongvitgiong.com/ckfinder/userfiles/files/mefejarag.pdf, http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ede7a9f0ebf---xekirejar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/cv9VXjIrmdE/uplcv?utm_term=what+must+all+workers+do+under+the+regulations+for+manual+handling
- https://webtraffic.ch/wp-content/plugins/super-forms/uploads/php/files/g92b6c0mick5fpuhtm9omngvna/kukidi.pdf
- https://gagiongvitgiong.com/ckfinder/userfiles/files/mefejarag.pdf
- http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ede7a9f0ebf---xekirejar.pdf
- http://amfmeg.org/wp-content/plugins/formcraft/file-upload/server/content/files/160b881f187c31---laweguliponuxuvolomogamo.pdf
- http://youandisagenix.com/ckfinder/userfiles/files/rikesugarovimatewutobag.pdf
- http://www.playerclub.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160c6379c19216---tufuzeloribokimip.pdf
- https://feldmann-spedition.de/pics/userfiles/file/36416908044.pdf
- https://technok.cz/wp-content/plugins/super-forms/uploads/php/files/b5f91aa3f317a84f7e96a6aa197eea8f/tamuzipojaxaveze.pdf
- http://msamericapageant.com/clients/873634/File/27856730330.pdf
- https://www.coconutlodge.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607234bdad4f3---50850702474.pdf
- http://am-assets.com/aom/magnolia/userfiles/file/rekosirilub.pdf
- http://brenna-ski.pl/userfiles/file/xunavoboturatiwemuwexefiw.pdf
- https://epiphanych.com/images/file/14655917199.pdf
- http://maxitelt.no/wp-content/plugins/formcraft/file-upload/server/content/files/160802e7abf239---boruxinazanor.pdf
- http://www.opencalgary.org/wp-content/plugins/formcraft/file-upload/server/content/files/1609c27e74a01b---jawasuxetuka.pdf
- http://ikhmongol.mn/ckfinder/userfiles/files/lejikak.pdf
- https://inchirieriavioane.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160bee83dbfe88---janisifetixugik.pdf
- https://maximatrimony.com/ckfinder/userfiles/files/20313844423.pdf
- https://ethiquedevelopers.com/wp-content/plugins/super-forms/uploads/php/files/0fda1422737e9bda53df8f2b82c05feb/51887367774.pdf
- http://coeb.eu/userfiles/files/1063385562.pdf
- http://bitite.lv/media/txt/122/file/femel.pdf
- http://foire-fromages-et-vins.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d1afaf53e66---55938161503.pdf
- https://www.getfitcrew.com/wp-content/plugins/formcraft/file-upload/server/content/files/160afb93b4665a---jaxegonaku.pdf
- http://www.fullmooneye.com/wp-content/plugins/formcraft/file-upload/server/content/files/160881edda5b59---gowurapul.pdf
Embedded domains
- 8.ua
- feedproxy.google.com
- webtraffic.ch
- gagiongvitgiong.com
- hellnocancershow.com
- amfmeg.org
- youandisagenix.com
- feldmann-spedition.de
- msamericapageant.com
- www.coconutlodge.com
- am-assets.com
- brenna-ski.pl
- epiphanych.com
- maxitelt.no
- www.opencalgary.org
- maximatrimony.com
- ethiquedevelopers.com
- coeb.eu
- foire-fromages-et-vins.com
- www.getfitcrew.com
- www.fullmooneye.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.playerclub.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report