MALICIOUS — 53052555577.pdf
MALICIOUS — 53052555577.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
423e0a5e1b5f0e475be8a6f3bc399b4d8b377c7e73cce060835b3ff36ee6c14d - SHA-1:
6e78d7c86abb6bfe84757b55a9ff40e52202e91e - MD5:
d9b0856337ac583bf73b1b0109054742 - ssdeep:
1536:gaUla6ek3jxKQIBXTa42OBUakwu4oedVuEH43:CFQBXJOakv43dkEE - TLSH:
T19938D1F37357DC8C7E47BB93A6A66258704BD78832309AA44088F6DCC4782AD5F71A41 - Submitted as: 53052555577.pdf
- File type: pdf · Size: 81049 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D9B0856337AC
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://oniceh.ru/uplcv?utm_term=contest+legal+disclaimer+template, https://cal.lighting/wp-content/plugins/super-forms/uploads/php/files/f7060ca3948f8b5187a702a82d1fcb7b/boxufamidibawur.pdf, http://lilit-realty.com/wp-content/plugins/super-forms/uploads/php/files/9efcf29d3kfjdq0sdkfh1ls4u6/80702135069.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oniceh.ru/uplcv?utm_term=contest+legal+disclaimer+template
- https://cal.lighting/wp-content/plugins/super-forms/uploads/php/files/f7060ca3948f8b5187a702a82d1fcb7b/boxufamidibawur.pdf
- http://lilit-realty.com/wp-content/plugins/super-forms/uploads/php/files/9efcf29d3kfjdq0sdkfh1ls4u6/80702135069.pdf
- http://www.chicagoalphas.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ca6643a0d3---luvazazagexaxurewewul.pdf
- https://www.brunosistemi.com/wp-content/plugins/formcraft/file-upload/server/content/files/16086c9646dc91---wetiziliwijuda.pdf
- http://www.northeastmarquees.com/wp-content/plugins/super-forms/uploads/php/files/b6ac512d05c75ecf864f0f7726ae803b/dosuwebutuzo.pdf
- https://agatanorek.com/files/file/16520257040.pdf
- https://parklanehotel.asia/userfiles/file/1868430399.pdf
- https://alignerco.com/wp-content/plugins/super-forms/uploads/php/files/d8973c7f416145ea22220d69ca84a34c/sifodik.pdf
- https://stewsites.com/wp-content/plugins/super-forms/uploads/php/files/5326d1fbab3936f3c40efb368e708850/19770351953.pdf
- https://sancarspune.com/wp-content/plugins/super-forms/uploads/php/files/d9766182d20d1e46b159e10d0131d1e2/lukafojesojavoxazu.pdf
- https://sketchup360.vn/wp-content/plugins/super-forms/uploads/php/files/2jcpr27mouvur0i6j1vhr6eucm/lakalajivajefapabowebani.pdf
- https://www.qbuildsoftware.com/wp-content/plugins/super-forms/uploads/php/files/1bfec41bad337a65281756e44b90de38/85988828112.pdf
- https://amesmedicalservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/160773d3ac01f4---87844472440.pdf
- http://blog.crowdly.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609812c84cb3f---18997446279.pdf
- https://militarynetwork.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16085a60e7de20---26834692002.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- oniceh.ru
- lilit-realty.com
- www.chicagoalphas.com
- www.brunosistemi.com
- www.northeastmarquees.com
- agatanorek.com
- parklanehotel.asia
- alignerco.com
- stewsites.com
- sancarspune.com
- www.qbuildsoftware.com
- amesmedicalservices.com
- blog.crowdly.com
- militarynetwork.ca
- www.w3.org
- purl.org
- ns.adobe.com
- cal.lighting
- sketchup360.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report