MALICIOUS — 94923216790.pdf
MALICIOUS — 94923216790.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
41073896aebe3a1dc5c18a056ea51e044d680e77e8268fcc69e71d31d7422909 - SHA-1:
60f95728454bb38aaf047b1813aae7d459634302 - MD5:
a20a4716326ee8bed51201cc3dc28b86 - ssdeep:
1536:RsJqDcMl0FMenlfwsB8u5pvycWPLLgtfnk5BLhYW4g3zzWxApOGzWjDf04OLtDI:9Dcq9sB8T7P/tG4zc3GAf0VB0 - TLSH:
T1AE38CFF72087DE8C674BDB036CFA146EE49AC6C81161EB904188766DC4BCABD7F04A51 - Submitted as: 94923216790.pdf
- File type: pdf · Size: 83665 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://a-range.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1613a7908a94df---10462179765.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://kodcomputers.ro/2664/uploads/54835703565.pdf, https://cantarefides.ro/admin/userfiles/file/murokob.pdf, http://a-range.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1613a7908a94df---10462179765.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1KS0DP0cxss/uplcv?utm_term=retrieve+call+log+android
- https://kodcomputers.ro/2664/uploads/54835703565.pdf
- https://cantarefides.ro/admin/userfiles/file/murokob.pdf
- http://a-range.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1613a7908a94df---10462179765.pdf
- https://pataniforum.com/admin/jquery/ckfinder/userfiles/files/12945949045.pdf
- http://britishcytology.org.uk/ckfinder/userfiles/files/keluzutug.pdf
- http://www.medicellbank.com/userfiles/files/60827791689.pdf
- https://quangtriasianwindow.com/uploads/image/files/87203373497.pdf
- https://faceless.me/userfiles/files/xojupodelukiwuro.pdf
- https://vietnamairlinescorp.org/js/ckfinder/userfiles/files/10059079230.pdf
- http://miyozenemeryville.com/uploads/files/sovojupifajamoli.pdf
- http://nawooelcs.com/upload/userfiles/2021/09/files/210910213234.pdf
- http://nzozkrowodrza.pl/uploads/editor/file/80789491425.pdf
- http://ck-kutnahora.cz/gais/image/file/jajimebilasewad.pdf
- http://devison-matras.com/upload/file/kanitivepo.pdf
- https://1sis.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613bd1a20cc25---1246321812.pdf
- http://mcenterdk.ru/fck_editor_files/files/xuriz.pdf
- http://colleges-in-tamilnadu.com/FCKeditor/userfiles/file/rolofininumobixi.pdf
- https://stauber.lt/images/files/36332516452.pdf
- https://www.bocamvigliesrooms.com/wp-content/plugins/super-forms/uploads/php/files/202bca9508758fecbaf624331c89198f/vajivitifenosoxefelur.pdf
- http://holdemigny.fr/ckfinder/userfiles/files/kidole.pdf
- http://www.moyekolodin.com/files/fasufizorobodiparupulu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- a-range.ru
- pataniforum.com
- britishcytology.org.uk
- www.medicellbank.com
- quangtriasianwindow.com
- faceless.me
- vietnamairlinescorp.org
- miyozenemeryville.com
- nawooelcs.com
- nzozkrowodrza.pl
- devison-matras.com
- 1sis.com
- mcenterdk.ru
- colleges-in-tamilnadu.com
- www.bocamvigliesrooms.com
- holdemigny.fr
- www.moyekolodin.com
- www.w3.org
- purl.org
- ns.adobe.com
- kodcomputers.ro
- cantarefides.ro
- ck-kutnahora.cz
- stauber.lt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report