MALICIOUS — 202109031621129964.pdf
MALICIOUS — 202109031621129964.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
47f6fbc5faece94feeefda0ed0d149255e0356fa770bc4d0d7c0f9cf4dcdb606 - SHA-1:
6f1001963b32237027659076fcae5741197735ca - MD5:
39815470c6c110576493f4ef3e64d913 - ssdeep:
1536:DnmktCaUTrEJmLIT4JwZcPRfM8osCjh8WEs/OBxmjajsJVWOpOwrqS75XH:DCaUKmsewZclM5hHjjRJSwr5F - TLSH:
T17837C0F311D7DE8CB79A9F436FA621A9908ED7C852729B50048C731CE478ABD3E14A50 - Submitted as: 202109031621129964.pdf
- File type: pdf · Size: 74864 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://davnosti.ru/upload/mupulo.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://drafthe.ru/uplcv?utm_term=kitchen+tips+in+tamil+pdf, https://davnosti.ru/upload/mupulo.pdf, https://langumeistras.lt/i/File/xukemegipivusuvevise.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://drafthe.ru/uplcv?utm_term=kitchen+tips+in+tamil+pdf
- https://davnosti.ru/upload/mupulo.pdf
- https://langumeistras.lt/i/File/xukemegipivusuvevise.pdf
- https://daluxerealty.com/wp-content/plugins/super-forms/uploads/php/files/896df2a8886a654094a02eb2b4cfb907/xitiwafikafof.pdf
- http://loscogliodifavignana.it/userfiles/files/70752057723.pdf
- http://brilsports.ro/userfiles/file///xefuwujo.pdf
- http://nedvizhimost-v-sharm-el-sheikhe.ru/uploads/files/gizikufolopo.pdf
- https://fellowpeo.com/wp-content/plugins/super-forms/uploads/php/files/28d7f48738ceb355a9cbc32a81c0aa4e/xefalusatam.pdf
- http://www.sunarsurdurulebilir.com/wp-content/plugins/super-forms/uploads/php/files/ovk8m4rvu878nb3epam4f5cea3/9306006046.pdf
- http://www.circoloaletrium.it/wp-content/plugins/formcraft/file-upload/server/content/files/160b4c07783f8c---befero.pdf
- http://www.bordadoindustrial.com/ckfinder/userfiles/files/peranudo.pdf
- http://hig-hegmann.de/userfiles/file/57061412042.pdf
- https://refour.eu/wp-content/plugins/super-forms/uploads/php/files/eae9b47fd79f4833f631d4f22f3efcca/dudiz.pdf
- https://abril.pe/wp-content/plugins/super-forms/uploads/php/files/j7p6nnti8t3q1m885h57vkb1k6/naxepasutugepoko.pdf
- http://mistralizmiryonetim.com/uploads/file/49854850901.pdf
- https://www.sblending.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160a0ce7a3fa65---94957388620.pdf
- http://aggengr.com/uploads/CMS/file/mopobemosebamuwixowi.pdf
- https://travels-ukraine.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b0b872a3963---20115218428.pdf
- http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/a7f51198e46e69c6a02113957359fe3f/38273777007.pdf
- https://nguyenhungstone.com/uploads/image/files/nenulokopajaro.pdf
- https://rpitrade.com/ckfinder/userfiles/files/loxuzel.pdf
- http://kolesnikov.pro/ckfinder/userfiles/files/rapipegobavopojawulireb.pdf
- http://language-coach.pl/uploads/files/tovukojezejalotizedumijo.pdf
- https://avphunter.ro/ckfinder/userfiles/files/77121851494.pdf
- http://numere-mopede.ro/mm/file/45105462654.pdf
Embedded domains
- j.ga
- drafthe.ru
- davnosti.ru
- daluxerealty.com
- loscogliodifavignana.it
- nedvizhimost-v-sharm-el-sheikhe.ru
- fellowpeo.com
- www.sunarsurdurulebilir.com
- www.circoloaletrium.it
- www.bordadoindustrial.com
- hig-hegmann.de
- refour.eu
- mistralizmiryonetim.com
- www.sblending.com.au
- aggengr.com
- travels-ukraine.com
- asirius.su
- nguyenhungstone.com
- rpitrade.com
- kolesnikov.pro
- language-coach.pl
- www.w3.org
- purl.org
- ns.adobe.com
- langumeistras.lt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report