MALICIOUS — 20663189947.pdf
MALICIOUS — 20663189947.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
477d9311663df988fd5678840f4df9f29e85a473c138583dee045eafb8c314a2 - SHA-1:
fa9dcaf5411431e3f229ce46156058416b910cc8 - MD5:
3a16943d7f18d8892c461a6273ad53ce - ssdeep:
1536:50gxBNNh2Zyemjjg4n8M4ixzqPhHlmxB/fpWOpOaZEWyUKRT0HGt4I:KkCyemjjb8M4ixzqJCfiaZOU80HGJ - TLSH:
T13C3AD0F3515BCD4C774BDF0369BB1269A04ED388A162EB650044B7ACD47CAAE7E20D50 - Submitted as: 20663189947.pdf
- File type: pdf · Size: 95207 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://servis-hradec.cz/files/file/28218511233.pdf - network signal, weight 0.70, confidence 0.80
- Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=rubik%27s+cube+solution+manual, http://s292376414.onlinehome.fr/datas/imgmail/file/gugilekinovike.pdf, http://filtrydokoparek.pl/img/all/2005165395.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/uplcv?utm_term=rubik%27s+cube+solution+manual
- http://s292376414.onlinehome.fr/datas/imgmail/file/gugilekinovike.pdf
- http://filtrydokoparek.pl/img/all/2005165395.pdf
- http://kapalishakti.com/ckfinder/userfiles/files/20552745819.pdf
- http://servis-hradec.cz/files/file/28218511233.pdf
- https://loyallcanada.com/editor_files/file/1454472297.pdf
- https://ncsccalgary.com/userfiles/files/20542769087.pdf
- https://samarthanamparisara.org/apadmin/uploads/userfiles/files/94492231784.pdf
- http://formel1vermietung.de/userfiles/file/zivuxotiduf.pdf
- https://milorem-service.ru/userfiles/file/23393956347.pdf
- https://phnews.ro/files/file/zuvujurozikorisu.pdf
- https://prtl.pl/userfiles/file/94501863692.pdf
- https://kentacademymiango.com/userfiles/file/99521552722.pdf
- http://tourbusan.net/FileData/ckfinder/files/20210907_47C1639FDA813434.pdf
- https://rubin2000-distribuitorshop.ro/userfiles/file/70509310536.pdf
- https://www.bluegreenshouseboats.in/wp-content/plugins/formcraft/file-upload/server/content/files/16137520b9be36---kolam.pdf
- https://conrays.ru/f/data/87810512666.pdf
- http://tuttotop.com/userfiles/files/16444042171.pdf
- https://www.entornopublicitario.com/wp-content/plugins/super-forms/uploads/php/files/6742c4d2120d660ac0b45e9005868600/97288453675.pdf
- http://xn--zb0by3yusal20ak5lcidnwigi.com/ckfinder/userfiles/files/1630581113.pdf
- https://fablab808.com/nbloom/fckuploads/file/54379588326.pdf
- http://churchtextile.com/userfiles/file/79187970366.pdf
- http://asiadomainstore.com/userfiles/file/pediwudiwafowopu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- medvor.ru
- s292376414.onlinehome.fr
- filtrydokoparek.pl
- kapalishakti.com
- loyallcanada.com
- ncsccalgary.com
- samarthanamparisara.org
- formel1vermietung.de
- milorem-service.ru
- prtl.pl
- kentacademymiango.com
- tourbusan.net
- www.bluegreenshouseboats.in
- conrays.ru
- tuttotop.com
- www.entornopublicitario.com
- xn--zb0by3yusal20ak5lcidnwigi.com
- fablab808.com
- churchtextile.com
- asiadomainstore.com
- www.w3.org
- purl.org
- ns.adobe.com
- servis-hradec.cz
- phnews.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report