MALICIOUS — 61429951293.pdf
MALICIOUS — 61429951293.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
46773ed6c747915f1cc60aa7347ce21532c21d24e43236c8d7cfb3ccc1c60069 - SHA-1:
02a471c3420c37868b968cab683a2edd7fb08f2b - MD5:
270eb70deb1efc6516e55b7753e01c15 - ssdeep:
1536://49cPI7BqAqsvJzYFs9ohkwjh7KiOJ/xNQBQhpbW28yudKe/vWUpO7fPkdH5T:4CPI7BqJsBzYFsmhP7KiOJ/xWB0pf8yC - TLSH:
T1A839CFF36197EC4D775B9B137EEB15A9A085D3881123EA6090C8BB6C85BC5FE3E10601 - Submitted as: 61429951293.pdf
- File type: pdf · Size: 85065 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://antonio-pelella.eu/userfiles/files/farixusovekanogipe.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cructi.ru/uplcv?utm_term=game+driver+android+10+developer+options, https://eastmangroup.org/ckfinder/userfiles/files/78525460697.pdf, http://kino-profi.com/wp-content/plugins/super-forms/uploads/php/files/1b548db18a7f5500a4b6ef9cfbdbdcc5/12358945170.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cructi.ru/uplcv?utm_term=game+driver+android+10+developer+options
- https://eastmangroup.org/ckfinder/userfiles/files/78525460697.pdf
- http://kino-profi.com/wp-content/plugins/super-forms/uploads/php/files/1b548db18a7f5500a4b6ef9cfbdbdcc5/12358945170.pdf
- http://alhambra.kopanramen.com/uploads/files/witisufevokapenakom.pdf
- http://kryotherapie.net/neu/userfiles/file/65351988445.pdf
- http://tichdiem.surecare.vn/uploads/userfiles/file/55523290616.pdf
- http://antonio-pelella.eu/userfiles/files/farixusovekanogipe.pdf
- https://uslugiinzynierskie.com/eurostyl/photos/file/dixewumimisebuz.pdf
- http://sklenicky-obchod.cz/web/admin/fckeditor/userfiles/file/vovuzasesipememaxifused.pdf
- http://golfvillageonline.com/userfiles/file/jatofasebidarujufugax.pdf
- http://bsp-plovdiv.org/ckfinder/userfiles/files/46724886879.pdf
- http://bdsps.org/slbdavbatala/userfiles/file/popuzo.pdf
- http://scbczy.cn/up_files/file/20210911_014802.pdf
- http://usmleworkout.com/files/file/bemudetudepolalatekukariw.pdf
- https://rintrans.com/files/97354143659.pdf
- http://monikaknoblochova.com/userfiles/file/gupodazebubamef.pdf
- http://elektromig.pl/userfiles/file/25899395447.pdf
- http://wernersuarez.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/zitoduboz.pdf
- http://igigeothermal.jp/userfiles/file/tifek.pdf
- http://jplus-ag.com/upload/files/BodyFile__6131A1E51AEA4.pdf
- https://mercerapparelss.com/userfiles/files/wuvesed.pdf
- http://tdsns.ru/userfiles/file/libukixibuzosawero.pdf
- http://notar-frings.de/userfiles/file/71393661664.pdf
- https://china-glass-mosaic.vegner.com/userfiles/files/20210909_013354.pdf
- http://promocode.lu/userfiles/files/14390910555.pdf
Embedded domains
- cructi.ru
- eastmangroup.org
- kino-profi.com
- alhambra.kopanramen.com
- kryotherapie.net
- antonio-pelella.eu
- uslugiinzynierskie.com
- golfvillageonline.com
- bsp-plovdiv.org
- bdsps.org
- scbczy.cn
- usmleworkout.com
- rintrans.com
- monikaknoblochova.com
- elektromig.pl
- wernersuarez.com
- igigeothermal.jp
- jplus-ag.com
- mercerapparelss.com
- tdsns.ru
- notar-frings.de
- china-glass-mosaic.vegner.com
- carbonelite.ru
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report