MALICIOUS — 48779871397.pdf
MALICIOUS — 48779871397.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3cc4e9431834b7c98e4af7771fe59f0c8c6a8013b37ec3afb997a0c66265d91d - SHA-1:
557ff81628122082f569f8fccae812c758fb1e62 - MD5:
dfd54649588c0b39032673ee44ef8a0f - ssdeep:
1536:QCg2qyikTgNHcKWpNupdU4Oo0FqvQ0O0jWVELS+AndDVOzYx9HiWspO2RRI:VgUW8KWpEd/J0FFqC+AndUU3Hp2E - TLSH:
T1E537C0F311E3CE4C7B869B836EF6219C904BE3586132DA6084887A7CD57C6BEBE04551 - Submitted as: 48779871397.pdf
- File type: pdf · Size: 71213 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://amatnieks.lv/pictures/image/17077682541.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://oniceh.ru/uplcv?utm_term=twin+stick+shooter+ps4, http://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613b8487b4b86---95094583847.pdf, https://virtrade.gr/userfiles_lybo/file/rodivakowefitonuvuno.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oniceh.ru/uplcv?utm_term=twin+stick+shooter+ps4
- http://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613b8487b4b86---95094583847.pdf
- https://virtrade.gr/userfiles_lybo/file/rodivakowefitonuvuno.pdf
- https://amatnieks.lv/pictures/image/17077682541.pdf
- https://rescue.bg/wp-content/plugins/formcraft/file-upload/server/content/files/16150ef88dcdb3---noxutivujegu.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613188b8ed673---jozutuxoxibadizuboru.pdf
- http://nuocmambason.com/upload/fckimagesfile/6fbca5eb891cb275ea51e7b769641275.pdf
- https://qualitycountscleaning.com/wp-content/plugins/super-forms/uploads/php/files/aa439b4a940fb14be86a7f5853c4158c/13924640790.pdf
- https://btcauction.vn/hinhanh/file/rawatuvipasifex.pdf
- https://wspaperbag.com/userfiles/file/82928200837.pdf
- http://tradotel-riviera.com/file/50797613763.pdf
- https://donnasalon.ru/wp-content/plugins/super-forms/uploads/php/files/759a0821ad8e73c2d8c7bbd3b602affc/45294059355.pdf
- http://special-pharma.com/upload/files/41695782194.pdf
- http://dexgerm.com/data/file/userfiles/files/75893330086.pdf
- http://kyea.org/imageuploads/popuji.pdf
- http://squash-fitness.cz/userfiles/file/gewovesi.pdf
- http://pobierzplik.pl/uploads/files/manit.pdf
- https://gencerenerji.com/resimler/files/21367891535.pdf
- https://adverto.ee/userfiles/file/98164292315.pdf
- http://laptopplus.be/app/webroot/files/userfiles/files/vutebajidexademul.pdf
- http://frutapac.com/ckfinder/userfiles/files/zodafevanil.pdf
- https://bellcera.60km.com/upload/files/tujon.pdf
- http://libertyquad72.fr/userfiles/file/jezowefarojipedajeta.pdf
- http://abwessex.com/uploads/files/45532702072.pdf
- http://studiozammuner.eu/userfiles/files/voxeguduzuzopudamewi.pdf
Embedded domains
- oniceh.ru
- klingende-zeder.de
- www.1000ena.com
- nuocmambason.com
- qualitycountscleaning.com
- wspaperbag.com
- tradotel-riviera.com
- donnasalon.ru
- special-pharma.com
- dexgerm.com
- kyea.org
- pobierzplik.pl
- gencerenerji.com
- laptopplus.be
- frutapac.com
- bellcera.60km.com
- libertyquad72.fr
- abwessex.com
- studiozammuner.eu
- www.w3.org
- purl.org
- ns.adobe.com
- virtrade.gr
- amatnieks.lv
- rescue.bg
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report