MALICIOUS — 161475326e7329---17654920165.pdf
MALICIOUS — 161475326e7329---17654920165.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
441dbd9f4b3c83684cedd83af57bf4bce22a8563d890592d75067485c05c6fea - SHA-1:
d26cf0ad361c6d03577468511f56815415186fbe - MD5:
2741025a571767dbe03c2ac589391990 - ssdeep:
1536:j/XOWULLGeOQCmzLcrryNEYPoVNyU6aWxLI78ZW8pO+45M:rezGeObmzLAyXPo3j6fVY+T - TLSH:
T12A37BFF720D7EC9C778B8B43ADFB1299908AD3841272DA904488A67CC67C67DBF14941 - Submitted as: 161475326e7329---17654920165.pdf
- File type: pdf · Size: 70199 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ozkayalarlojistik.com/userfiles/file/71478163454.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://produktybhp.pl/pliki_user/File/7350805547.pdf, https://www.aifimm.it/admin/inc/ckfinder/userfiles/files/lalobudizaraguzovufeted.pdf, http://trieuduong.com/images/Download/zimibujevifomobo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/fzgW7-mxBc0/uplcv?utm_term=game+tabs+apk
- https://produktybhp.pl/pliki_user/File/7350805547.pdf
- https://www.aifimm.it/admin/inc/ckfinder/userfiles/files/lalobudizaraguzovufeted.pdf
- http://trieuduong.com/images/Download/zimibujevifomobo.pdf
- https://ijfbacknumber.com/editor_up/fuzonanofotupi.pdf
- https://www.yoursurveysurveyors.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/161365c09be143---1907779547.pdf
- http://ozkayalarlojistik.com/userfiles/file/71478163454.pdf
- https://kes-stv.ru/wp-content/plugins/super-forms/uploads/php/files/b9c4137c3c27662e4e154d8d0ce26c77/17338055200.pdf
- http://cs-web-design.de/ablage/userfiles/files/39203523747.pdf
- http://xn--rssx31a7tec6p.com/upload/userfiles/files/20210905171302.pdf
- https://www.wikiwebagency.it/wp-content/plugins/super-forms/uploads/php/files/df6d876660a276c967d5b08039c3f470/zasepobiparuzaxazunuda.pdf
- http://www.niziointerior.pl/upload/file/zusubuzuginuwu.pdf
- http://phuwangnam.com/user_file/file/37819042249.pdf
- https://ksi-system.pl/editorfiles/file/pivogumetegesolawem.pdf
- https://www.traveltimevipp.com/wp-content/plugins/super-forms/uploads/php/files/d1432e8e481b892a7009332463fdad6b/poremu.pdf
- http://patanjali.zohukum.com/ckfinder/userfiles/files/lubirejidipemumodanutane.pdf
- http://studioarclab.eu/userfiles/files/12954107941.pdf
- http://www.ciesol.com/ckfinder/userfiles/files/nogomumuvofukekoworopotad.pdf
- http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/16142372c24b8d---sutedagozibo.pdf
- http://violetstudio.in/userfiles/file/zebobepuberukoli.pdf
- https://ladangmimpi.com/contents/files/4245264153.pdf
- https://ifacemount.com/wp-content/plugins/super-forms/uploads/php/files/2qhdusot5j22ub50nr6gl6bm2o/xawabegat.pdf
- http://newgoodluckcrane.com/admin/uploadfiles/file/29172644313.pdf
- http://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1613b6f398cc3b---vaxopoxeborojijuw.pdf
- https://gauravkankariya.com/wp-content/plugins/super-forms/uploads/php/files/7c65bfe63ed9836d0845b7a1a662c744/guzitezoxagigipetuvo.pdf
Embedded domains
- feedproxy.google.com
- produktybhp.pl
- www.aifimm.it
- trieuduong.com
- ijfbacknumber.com
- www.yoursurveysurveyors.co.uk
- ozkayalarlojistik.com
- kes-stv.ru
- cs-web-design.de
- xn--rssx31a7tec6p.com
- www.wikiwebagency.it
- www.niziointerior.pl
- phuwangnam.com
- ksi-system.pl
- www.traveltimevipp.com
- patanjali.zohukum.com
- studioarclab.eu
- www.ciesol.com
- www.stockholmswingallstars.com
- violetstudio.in
- ladangmimpi.com
- ifacemount.com
- newgoodluckcrane.com
- gauravkankariya.com
- jca-t.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report