MALICIOUS — 29556866769.pdf
MALICIOUS — 29556866769.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
57dca6783a907b831e1eb0fe54798b2c532e8a62f36dd1fedac06904550c472b - SHA-1:
1551537159cdf87b66ac246b48a516f205f853be - MD5:
739f5808296cc8fb6d257947356e6962 - ssdeep:
1536:AnNQAR17L2YPY+T+bcToZN3ryVp/5IYfRWUpO7qWy61NpkbE5:YLhL2B+T+bcoZNGZIYfU7w613k6 - TLSH:
T16638BEF320A7DD4C334ACF4329F7219DA44AE7891172E7E19088B66C967C5BE6F00A51 - Submitted as: 29556866769.pdf
- File type: pdf · Size: 80238 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://dongzzang.com/userfiles/file///surijofotetafekajum.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://dongzzang.com/userfiles/file///surijofotetafekajum.pdf, https://alpasol.e-giant.net/upload/files/kuvol.pdf, http://cissi.it/userfiles/files/lewamoba.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/YTWXjIUwRh0/uplcv?utm_term=among+us+apk+update
- http://dongzzang.com/userfiles/file///surijofotetafekajum.pdf
- https://alpasol.e-giant.net/upload/files/kuvol.pdf
- http://cissi.it/userfiles/files/lewamoba.pdf
- http://guowangcable.com/d/files/4342884076.pdf
- http://bedrucken24.de/userfiles/file/xosunibisujejes.pdf
- http://www.findvoters.com/userfiles/file/tazopimidi.pdf
- http://climtech.com/files/files/salonudizililemol.pdf
- http://dolekkoyum.com/admin/UserFiles/file/5083961715.pdf
- https://www.tzounakos-insurance.gr/ckfinder/userfiles/files/sosimufim.pdf
- http://www.grifin.sk/files/78578825120.pdf
- https://cplastik.com/data/cms/file/50127141800.pdf
- http://servis-hradec.cz/files/file/waxew.pdf
- http://woonhuislift.info/wp-content/plugins/formcraft/file-upload/server/content/files/16135c2ba5ee11---tibijowupuv.pdf
- http://sun-green.be/ckfinder/userfiles/files/xakufekisoxemet.pdf
- https://calienglish.com/ckfinder/images_store/files/penanegulo.pdf
- http://architetturaurbanistica.it/userfiles/files/satawugivoxovadamidatimum.pdf
- http://grandioso.asia/editor_upload_image/file/94621613974.pdf
- http://prosquash.by/data/fivulum.pdf
- https://www.mobytec.com.br/mobytec/wp-content/plugins/formcraft/file-upload/server/content/files/1613baec714610---12129997492.pdf
- http://www.juthamasclinic.com/upload/finder/files/54526170203.pdf
- https://pharma-tools.pl/galeria/file/purapikog.pdf
- https://bharatceramics.in/ckfinder/userfiles/files/13179658052.pdf
- https://hfbee.tw/upload/ckfinder_temp/files/20210906010605.pdf
- http://zelene-centrum.cz/webpagebuilder/ckfinder/userfiles/files/mirakewegidijimudoj.pdf
Embedded domains
- feedproxy.google.com
- dongzzang.com
- alpasol.e-giant.net
- cissi.it
- guowangcable.com
- bedrucken24.de
- www.findvoters.com
- climtech.com
- dolekkoyum.com
- cplastik.com
- woonhuislift.info
- sun-green.be
- calienglish.com
- architetturaurbanistica.it
- grandioso.asia
- www.mobytec.com.br
- www.juthamasclinic.com
- pharma-tools.pl
- bharatceramics.in
- hfbee.tw
- www.maarsehoveniers.nl
- www.w3.org
- purl.org
- ns.adobe.com
- www.tzounakos-insurance.gr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report