MALICIOUS — 28720109805.pdf
MALICIOUS — 28720109805.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4a94a9745692fd6f19f6467a96fde4c27bffab0d940c7e30f6ab653f0069e786 - SHA-1:
2887d2b8c5f30d1b3c5d1717133055355ec3311e - MD5:
f009c5cb85d1525ba2d86d310ec5013c - ssdeep:
1536:LGUYRZ3tpRQuupYLhFr84Tor5xEpA7iPb4taRD7semAtaWepOyWWwxA2iv9eZTXa:iUYX3rRlu+zrfwEpA+M0Rfse9tbyGivf - TLSH:
T1083AD0F311A7DE4C7A8FDB53A8B611B8714AE7887021DAA044897B6DD67C1BC7F00261 - Submitted as: 28720109805.pdf
- File type: pdf · Size: 94210 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://scissortailfarms.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607d0b6c54f06---71280824628.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://laborke.ru/uplcv?utm_term=meaning+of+reproch, https://agenciaboom.com/wp-content/plugins/super-forms/uploads/php/files/k2n00aecda4k2onbstr3ihu2r5/tibodugabe.pdf, http://careerhack.net/wp-content/plugins/formcraft/file-upload/server/content/files/1612e05512d1b5---19069512915.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://laborke.ru/uplcv?utm_term=meaning+of+reproch
- https://agenciaboom.com/wp-content/plugins/super-forms/uploads/php/files/k2n00aecda4k2onbstr3ihu2r5/tibodugabe.pdf
- http://careerhack.net/wp-content/plugins/formcraft/file-upload/server/content/files/1612e05512d1b5---19069512915.pdf
- https://nomortiga.com/contents/files/wovuve.pdf
- http://wsp.pl/userfiles/file/dekuxebarizekepo.pdf
- https://areshin.ru/wp-content/plugins/super-forms/uploads/php/files/2bbb35645f58483f45c62f10e2be1561/44737967039.pdf
- http://namngonviet.vn/user-/files/rokenitawojavi.pdf
- http://www.hkwebdesign.com.hk/wp-content/plugins/formcraft/file-upload/server/content/files/160bf0239ed511---53244372786.pdf
- http://tamlaproject.com/userData/board/file/77189978891.pdf
- http://scissortailfarms.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607d0b6c54f06---71280824628.pdf
- https://www.sensiblemachines.com/ckfinder/core/connector/php/files/tokesiwasafajew.pdf
- https://mogilew.ru/userfiles/file/makofivagizopoj.pdf
- http://www.orarestauratorisaf.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607e5a17c424f---kemusoga.pdf
- https://www.grandiosa.is/wp-content/plugins/super-forms/uploads/php/files/3pom78j3h728u2umrfli488o33/xotas.pdf
- http://swaminarayangm.org/userfiles/file/tunurozawopizot.pdf
- http://sllight.ru/design/img/upload/file/tarexamugixikoxorodaji.pdf
- http://szentistvanpatika.hu/upload/file/sebapufexomosipuku.pdf
- http://cl-metalparts.com/d/files/lokuwetananuwoxeremizeb.pdf
- https://inchiriereelicoptere.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160e90308e5c5c---31766913497.pdf
- http://www.investing-in-women.com/wp-content/plugins/formcraft/file-upload/server/content/files/16099d2bc3c948---vagoziberawosemoduzijuxem.pdf
- https://www.le-domaine-de-hauterive.fr/ckfinder/userfiles/files/gokowijibe.pdf
- http://mottaing.eu/userfiles/files/59738367586.pdf
- https://mamproducciones.es/wp-content/plugins/formcraft/file-upload/server/content/files/160d6de8e3df1c---39797631513.pdf
- https://www.sadcmedia.com/wp-content/plugins/super-forms/uploads/php/files/v3hr2ej9pv6ej4ae18hq4o13fb/rosijijajexijopunofoduxe.pdf
- http://globomax.eu/userfiles/file/39828420956.pdf
Embedded domains
- laborke.ru
- agenciaboom.com
- careerhack.net
- nomortiga.com
- wsp.pl
- areshin.ru
- www.hkwebdesign.com.hk
- tamlaproject.com
- scissortailfarms.com
- www.sensiblemachines.com
- mogilew.ru
- www.orarestauratorisaf.it
- swaminarayangm.org
- sllight.ru
- cl-metalparts.com
- www.investing-in-women.com
- www.le-domaine-de-hauterive.fr
- mottaing.eu
- mamproducciones.es
- www.sadcmedia.com
- globomax.eu
- www.w3.org
- purl.org
- ns.adobe.com
- namngonviet.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report