MALICIOUS — 49372502550.pdf
MALICIOUS — 49372502550.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
4c8a69f28979e8bf094235c20bdbca0b526db595621445d3c59124b006db2afd - SHA-1:
4e82b205e19f99bde7f2b0e1a4a1963fc0cd181b - MD5:
25c61c9600c76262126f1ebc42944fee - ssdeep:
1536:QY9R6QIypkr2ACTifrW/UQavkm9u0cOblgYxWiBT8ByE03+CWW8pO7C/XOB5J:n9R/XpiZDW/UQavkm87uBTvE0OC17C/s - TLSH:
T10539C0F7229BDD4C7B974B437AA611AC6087D38931329680958CBB7CC57C67CAF10A41 - Submitted as: 49372502550.pdf
- File type: pdf · Size: 85802 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://b2bircruise.travflex.com/bot/ckfinder/uf/files/69879821995.pdf, http://portableandcool.com/files/files/bufosinegomip.pdf, http://digilit.ir/basefile/digilitir/files/tugixifegirewidusitix.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/ngfLrbzwjls/uplcv?utm_term=france+vs+portugal+free+live+stream
- https://b2bircruise.travflex.com/bot/ckfinder/uf/files/69879821995.pdf
- http://portableandcool.com/files/files/bufosinegomip.pdf
- http://digilit.ir/basefile/digilitir/files/tugixifegirewidusitix.pdf
- https://indoshaolinkungfusociety.com/ckfinder/userfiles/files/tuxaluwisiw.pdf
- http://espacioschillout.es/images/admin/file/43193618597.pdf
- http://rosabaum.de/web/editor/files/50963700852.pdf
- http://bienbao.org/uploads/files/xozewukofudilebozog.pdf
- http://photou.cc/ckfinder/userfiles/files/9514059907.pdf
- http://cuacuonnhanh.vn/Images_upload/files/funerowokudepitobumiruga.pdf
- http://luijkzonwering.nl/image/file/34908248096.pdf
- https://pmrmhss.com/userfiles/file/pokiwopudiv.pdf
- http://www.elsecretodelolivo.com/wp-content/plugins/formcraft/file-upload/server/content/files/16133c1932fcd9---gafabozuwezoza.pdf
- https://www.ksmt.edu.np/assets/ckfinder/userfiles/files/70895261571.pdf
- https://centrumschoolka.pl/photos/file/bubakelevagap.pdf
- http://nzozkrowodrza.pl/uploads/editor/file/gibavinukikap.pdf
- http://argol-editions.fr/userfiles/file/19650141450.pdf
- https://www.leadercaravans.com.au/application/third_party/ckfinder/userfiles/files/pelirekadapexilev.pdf
- http://okna-dvere-online.cz/media/upload/upload/file/2555609634.pdf
- http://rrmkaryacollege.org/rrmkarya/userfiles/file/39595347803.pdf
- http://brodart01.com/wp-content/plugins/super-forms/uploads/php/files/e3qhbe36sk7tmornptbk2804v2/41795323644.pdf
- https://renebeumer.nl/userfiles/file/bibasunizewupuxisevawunu.pdf
- http://ontis.sk/editor_uploads/system/files/58201638733.pdf
- http://zjgjqmr.com/v15/Upload/file/2021951828441070.pdf
- http://generaldistco.com/images/file/81315654181.pdf
Embedded domains
- feedproxy.google.com
- b2bircruise.travflex.com
- portableandcool.com
- digilit.ir
- indoshaolinkungfusociety.com
- espacioschillout.es
- rosabaum.de
- bienbao.org
- photou.cc
- luijkzonwering.nl
- pmrmhss.com
- www.elsecretodelolivo.com
- centrumschoolka.pl
- nzozkrowodrza.pl
- argol-editions.fr
- www.leadercaravans.com.au
- rrmkaryacollege.org
- brodart01.com
- renebeumer.nl
- zjgjqmr.com
- generaldistco.com
- ruiguoex.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report