MALICIOUS — 88390741782.pdf
MALICIOUS — 88390741782.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
442c94ea84a3268a269b5171d5f21dd7f6e2a4ec39e8ac59c2eb63ad02d358af - SHA-1:
7227ed42915c401fddd4d029902dbe7dc119a4c0 - MD5:
985153c8c901d8e35f36ac0d4c641c4c - ssdeep:
1536:NXTjxDxnhXe2aqWVnhRTmY48uLEDdUFsYicG6WtrXJlVeLWspO2mtZ4:xpxxe2aqWthRTTuwdys5cGbzJfeW2j - TLSH:
T17039D0F320DBDD5CBB478F43BD9911582149E748A121EBA005C8B76CD6BC9BDAB60580 - Submitted as: 88390741782.pdf
- File type: pdf · Size: 85908 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://labonguyenhoang.com/img-chamthi/files/72608402930.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://excore.hu/ckfinder/userfiles/files/rivalulederi.pdf, http://tidomusica.com/uploads/files/202109031621129964.pdf, https://www.chinacimctrailer.com/wp-content/plugins/super-forms/uploads/php/files/6033693fe9c16c69d1e6a4e8e9872e32/78240823570.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/YTWXjIUwRh0/uplcv?utm_term=solution+manual+fundamentals+of+fluid+mechanics+4th+edition
- https://excore.hu/ckfinder/userfiles/files/rivalulederi.pdf
- http://tidomusica.com/uploads/files/202109031621129964.pdf
- https://www.chinacimctrailer.com/wp-content/plugins/super-forms/uploads/php/files/6033693fe9c16c69d1e6a4e8e9872e32/78240823570.pdf
- http://szyldkj.com/luodan/images/userfiles/file/salunofolapigesavorinev.pdf
- https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/161323ba19ecdb---funamalezep.pdf
- http://mediedil.eu/userfiles/files/gojivejegi.pdf
- https://hotelangela.hu/userfiles/file/50646959798.pdf
- http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/16136fa3553829---68750383538.pdf
- http://labonguyenhoang.com/img-chamthi/files/72608402930.pdf
- https://i-intelli.com/ckfinder/userfiles/files/zevisaziroraz.pdf
- https://insolite.lu/img/userfiles/files/juburirok.pdf
- http://nensi.si/upload/file/57359899238.pdf
- http://elpijisystem.com/file/duzodi.pdf
- http://www.itidharamshala.in/images/uploads/files/14705334017.pdf
- http://mercuresamuichaweng.com/admin/file/41743622832.pdf
- http://pizzeriadevita.it/userfiles/files/21692411117.pdf
- http://wx-bm.cn/upload/ckimg/files/202109071346226405.pdf
- https://ceiling.holcom.vn/webroot/img/files/53811972856.pdf
- http://kimandyoo.com/userfiles/file/gaxanapaxakapokew.pdf
- https://inlandautorepairmurrietaca.com/wp-content/plugins/super-forms/uploads/php/files/1de1bac93734692c6e2cef88e354fa14/ninunukeko.pdf
- http://dfanchem.com/upload/files/40222677656.pdf
- http://ardeche.proximeo.com/ckfinder/userfiles/files/51848779440.pdf
- http://textingrights.com/userfiles/files/miwobemuri.pdf
- http://www.vivelamusica.es/wp-content/plugins/formcraft/file-upload/server/content/files/161314e5000b0a---kivitugaxafudenad.pdf
Embedded domains
- feedproxy.google.com
- tidomusica.com
- www.chinacimctrailer.com
- szyldkj.com
- nam.it
- mediedil.eu
- www.marsagri.com
- labonguyenhoang.com
- i-intelli.com
- elpijisystem.com
- www.itidharamshala.in
- mercuresamuichaweng.com
- pizzeriadevita.it
- wx-bm.cn
- kimandyoo.com
- inlandautorepairmurrietaca.com
- dfanchem.com
- ardeche.proximeo.com
- textingrights.com
- www.vivelamusica.es
- www.w3.org
- purl.org
- ns.adobe.com
- excore.hu
- hotelangela.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report