MALICIOUS — 95203850347.pdf
MALICIOUS — 95203850347.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3d5ac531ece67806afe40da545b96eb952eaa3fab3c244a430c2a83866dc1400 - SHA-1:
f8e57e2ae0cf36823136ac77817916d87d464ba6 - MD5:
eb2ee7bfbcaa7e2cfc4de69c3a2c4572 - ssdeep:
1536:Y7q94+iiQ/OKapeGkfNFGb/v3Poo8WjxH1DXZWbpONiZ+5:yqi+0/OKR7GbIoxVDXbNiS - TLSH:
T19D38C1F3619BED8C7B5B8B0379BA006C644AD74C6222DB50418CF62CD5FC9BDAE14A11 - Submitted as: 95203850347.pdf
- File type: pdf · Size: 81574 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://cuboni.com/uploadfile/hong202109091632308399.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gamma-electronics-eg.com/userfiles/files/73291531560.pdf, http://ekmeta.lt/failai/file/wezufu.pdf, https://gameclub.by/uploads/files/mufuzikilatulebovevadekes.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BvfzZFkJO3s/uplcv?utm_term=wwe+2k20+download+mod+apk
- https://gamma-electronics-eg.com/userfiles/files/73291531560.pdf
- http://ekmeta.lt/failai/file/wezufu.pdf
- https://gameclub.by/uploads/files/mufuzikilatulebovevadekes.pdf
- http://halongbaycruises.org/upload/files/54944310068.pdf
- https://premiersuli.hu/files/files/59099738065.pdf
- http://marta-galan.com/files/varios/file/11881434221.pdf
- http://www.wallisandemmanuel.com/wp-content/plugins/formcraft/file-upload/server/content/files/161479b221d522---70736123351.pdf
- http://pasaru.com/upload/files/6217802707.pdf
- http://cuboni.com/uploadfile/hong202109091632308399.pdf
- https://learn-atdi.com/uploads/files/kopimuxa.pdf
- http://www.anieliasfx.com/uploads/textareas/file/gejelod.pdf
- http://csc0512.com/userfiles/file/20210920050732_4ovtzk.pdf
- https://bursac.net/userfiles/file/lanarabugirolexede.pdf
- http://sonsuadogo.org/Images_upload/files/92022136838.pdf
- https://boucherienabli.com/uploads/FCK_files/file/42929915452.pdf
- https://sassanoproperties.com/FCKeditor/file/97814384427.pdf
- https://seedcambodia.org/htdocs/cljr/data/files/58759161545.pdf
- https://bodymart.in/ckfinder/userfiles/files/91284733492.pdf
- http://cx-gl.hu/images/files/fufudomuf.pdf
- https://www.penyembuhanholistikreiki.com/wp-content/plugins/formcraft/file-upload/server/content/files/161474fd317ce8---vibemumunij.pdf
- http://gruppocinofilomarsalese.com/userfiles/files/sobubesuzej.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- gamma-electronics-eg.com
- halongbaycruises.org
- marta-galan.com
- www.wallisandemmanuel.com
- pasaru.com
- cuboni.com
- learn-atdi.com
- www.anieliasfx.com
- csc0512.com
- bursac.net
- sonsuadogo.org
- boucherienabli.com
- sassanoproperties.com
- seedcambodia.org
- bodymart.in
- www.penyembuhanholistikreiki.com
- gruppocinofilomarsalese.com
- www.w3.org
- purl.org
- ns.adobe.com
- ekmeta.lt
- gameclub.by
- premiersuli.hu
- cx-gl.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report