MALICIOUS — 62139023193.pdf
MALICIOUS — 62139023193.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3d249a82ec18d8d6c8a04d0769579f3297dcd3c560ff13634c2b71e4345e13cd - SHA-1:
95ac4319319b3c176281ad60d68b079001d44757 - MD5:
64fd5dd39d05f952e24ef31554d1d266 - ssdeep:
1536:wWHKyKbc82b9+oHVUy6Yi+QANye7gaUvGHIR+lcR81k6oJVJzigQKRWYCOn1:5qlx69VHWci257Uj9RD6yViTKRbCO1 - TLSH:
T11838C0F3118FDD8C7B82DB47ABEA552C748AD24C213296AD0488E66CC47C6BD7E10B51 - Submitted as: 62139023193.pdf
- File type: pdf · Size: 82030 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!64FD5DD39D05
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://gf-location.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1609cfa965ac6b---gubisodarofukaredupufivol.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://www.actionconstructionjax.com/wp-content/plugins/super-forms/uploads/php/files/d750f98e42562f6aefa3c949e7d71470/vuvamonapebusiw.pdf, http://blpest.com/UserFiles/file/99414599466.pdf, http://gf-location.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1609cfa965ac6b---gubisodarofukaredupufivol.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/PmAiG5ZyT-k/uplcv?utm_term=important+static+gk+topics+for+bank+exams
- https://www.actionconstructionjax.com/wp-content/plugins/super-forms/uploads/php/files/d750f98e42562f6aefa3c949e7d71470/vuvamonapebusiw.pdf
- http://blpest.com/UserFiles/file/99414599466.pdf
- http://gf-location.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1609cfa965ac6b---gubisodarofukaredupufivol.pdf
- https://www.crossfitparamaribo.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075a898d03a2---vifotetitulumezizolil.pdf
- http://sad-azov.ru/wp-content/plugins/super-forms/uploads/php/files/69f6643bdb5509c6a5068fc3f491377d/fodubadelexano.pdf
- https://flycam.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1609103118b16c---10539597161.pdf
- https://www.18fire.com/wp-content/plugins/super-forms/uploads/php/files/958dba1636d7959fc7cbca5537c38c11/81061940526.pdf
- http://svenstavik.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b51b1055d51---61734037219.pdf
- https://evg-prague.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16084c1c01fcd5---jaduse.pdf
- https://sygimportaciones.com/wp-content/plugins/super-forms/uploads/php/files/1nta6spbkoofqlho5c1np8bdv8/68242493996.pdf
- https://adbetelparaguay.com/wp-content/plugins/super-forms/uploads/php/files/477f254fd5e547305c07f6a951482700/55015133723.pdf
- https://wscnaturalhealings.com/wp-content/plugins/super-forms/uploads/php/files/dbe10f0d2d3f8fcded4909ba62eebbd8/36688267027.pdf
- http://www.melodypods.com/wp-content/plugins/formcraft/file-upload/server/content/files/16084f02ae873c---zubasiwitanaje.pdf
- http://www.petersmetalstitching.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1606c83108eca4---pegato.pdf
- https://uaqbakery.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a01cc158287---vekisunilap.pdf
- https://www.darrellstuckey.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a8e39d162f9---53172686903.pdf
- https://www.escon.it/wp-content/plugins/super-forms/uploads/php/files/dc6db61672fb9cb5a70a0dc0187f2702/liravowonozodubegumolofe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- www.actionconstructionjax.com
- blpest.com
- gf-location.fr
- www.crossfitparamaribo.com
- sad-azov.ru
- www.18fire.com
- svenstavik.com
- evg-prague.fr
- sygimportaciones.com
- adbetelparaguay.com
- wscnaturalhealings.com
- www.melodypods.com
- www.petersmetalstitching.co.za
- uaqbakery.com
- www.darrellstuckey.com
- www.escon.it
- www.w3.org
- purl.org
- ns.adobe.com
- flycam.com.tr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report