MALICIOUS — 77778504016.pdf
MALICIOUS — 77778504016.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4eb109ffe81ef0c85857b1c2a08beb66e41d77e8042ef930d3b58eb939b139ee - SHA-1:
1c94249e6fb4d1239f49ccf90bd7c61a56864942 - MD5:
b3c3e2fae99f57bae9eda01e0e866171 - ssdeep:
1536:/MDTi/1f8OfyIEdiLv3AdrxZkyNAnGDyoCWapOtQLgdZoWRe/crPIgH:6TE10+yIEdgv3A3NAnGuCtQW007H - TLSH:
T13C38CFF311A7DE1C774ACF47BABA2158514B97C92123EF608488E77C94BC6BEAE10501 - Submitted as: 77778504016.pdf
- File type: pdf · Size: 82837 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://dom-nenilovo.ru/wp-content/plugins/super-forms/uploads/php/files/1b67353fc67edcaf44792d2701476a1d/nutekiselakiximaver.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://irlanc.ru/uplcv?utm_term=the+four+hour+chef+pdf, http://mq-water.net/upload/kupujadizimubupomeb.pdf, https://frasertechno.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613333982908b---wusoboja.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://irlanc.ru/uplcv?utm_term=the+four+hour+chef+pdf
- http://mq-water.net/upload/kupujadizimubupomeb.pdf
- https://frasertechno.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613333982908b---wusoboja.pdf
- http://buren-kompanie.de/userfiles/files/xizid.pdf
- https://celebicatering.com/upload/ckfinder/files/19661443800.pdf
- https://hotelreviewreserve.com/basefile/hotelreviewreservecom/files/kiribominixe.pdf
- https://glycocalyx.nl/userfiles/image/file/19793068208.pdf
- https://irastuff.com/admin/ckfinder/uploads/files/pirunukezulivanu.pdf
- http://rollfactorytogo.com/uploads/files/12301759358.pdf
- http://dom-nenilovo.ru/wp-content/plugins/super-forms/uploads/php/files/1b67353fc67edcaf44792d2701476a1d/nutekiselakiximaver.pdf
- http://tajesink.com/Uploadfiles/files/pavilozijifom.pdf
- http://www.alfainstal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/16138685d7b7b1---77052876196.pdf
- https://halobysciton.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613245aa2b8f3---vugozifeganejev.pdf
- https://travelselection.us/wp-content/plugins/formcraft/file-upload/server/content/files/1613e601001ddc---rikedusujagakasema.pdf
- http://eortak.com/img/fck_temp/file/vadupusu.pdf
- http://simkoongschool.com/uploads/editer/files/jasax.pdf
- https://lionkingbali.com/uploads/file/88875661695.pdf
- https://pensiuneaselina.ro/userfiles/file/58859730098.pdf
- https://sma-dfgg.org/site/admin/file/pijab.pdf
- https://4wheelchile.cl/admin/uploads/file/pomifizaxuxefiwupuwu.pdf
- http://kirks-pool.com/wp-content/plugins/formcraft/file-upload/server/content/files/16138fba929998---xafumupisigepememu.pdf
- http://nickels.design/ckfinder/userfiles/files/xazumokamikinokabej.pdf
- http://coolscape.info/images/files/29842771558.pdf
- https://wronba.pl/uploads/wysiwyg/file/venapuraburinewapev.pdf
- https://anakmeong.com/contents/files/gulizazuwezugudikunal.pdf
Embedded domains
- irlanc.ru
- mq-water.net
- frasertechno.com
- buren-kompanie.de
- celebicatering.com
- hotelreviewreserve.com
- glycocalyx.nl
- irastuff.com
- rollfactorytogo.com
- dom-nenilovo.ru
- tajesink.com
- www.alfainstal.pl
- halobysciton.com
- travelselection.us
- eortak.com
- simkoongschool.com
- lionkingbali.com
- sma-dfgg.org
- kirks-pool.com
- coolscape.info
- wronba.pl
- anakmeong.com
- klasykarozrywki.pl
- www.femregenx.co.za
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report