MALICIOUS — 13298891036.pdf
MALICIOUS — 13298891036.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5b289cc2be041a8cc18ac8874498cd03b403e4baa8ca68a3b27b766185d6e6e0 - SHA-1:
a377e44ccb249d4f61df1d5f5c753b0d85ff3c6c - MD5:
63e0288cbb2245d2e3d735a495de62be - ssdeep:
1536:P8D0SEzDc7bRVB3Z75olKzWM6v0fjigRpW4fXuwq/AZAeF1oYqPwg:+HEzA7bRVBp9olKyM6v0bbZXuVe5FWYO - TLSH:
T16137CFF72167ED4CABCB6F0318F9405D658AD58C2232EAA40498BB6CC5BCB7C6E14911 - Submitted as: 13298891036.pdf
- File type: pdf · Size: 76593 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!63E0288CBB22
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://advancedbusiness.co/wp-content/plugins/super-forms/uploads/php/files/f7156a952db326961222bcb17d1c6fea/5875810150.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=nyquist+plot+solved+examples+pdf, http://cy2hand.com/userfiles/vodajiruxupep.pdf, https://drainscovers.com/wp-content/plugins/super-forms/uploads/php/files/a909f71dc8b631357d4fe2da8f0c02b5/86258775787.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pistant.ru/uplcv?utm_term=nyquist+plot+solved+examples+pdf
- http://cy2hand.com/userfiles/vodajiruxupep.pdf
- https://drainscovers.com/wp-content/plugins/super-forms/uploads/php/files/a909f71dc8b631357d4fe2da8f0c02b5/86258775787.pdf
- https://jnfarley.com/wp-content/plugins/super-forms/uploads/php/files/l1ror406hpfo1hioulcp77mad2/75784847084.pdf
- http://digemnd.com/UserFiles/file/lobaxewowipudo.pdf
- https://stakeoutllc.com/wp-content/plugins/super-forms/uploads/php/files/ae13f3488fcb53ccaa88b36500ade723/48867628480.pdf
- https://advancedbusiness.co/wp-content/plugins/super-forms/uploads/php/files/f7156a952db326961222bcb17d1c6fea/5875810150.pdf
- http://harasim.cz/uploaded/files/natotubuwu.pdf
- https://gbeequestriansurfaces.com/wp-content/plugins/super-forms/uploads/php/files/bvsv13od10g4cmli0dahqt9mle/bisakeliwozate.pdf
- https://bistro-8.com/wp-content/plugins/super-forms/uploads/php/files/ba6f413a8521c097c3578339d19ecec2/47610728921.pdf
- http://falerisztika.hu/tmp/65539445562.pdf
- https://popa.com.br/wp-content/plugins/super-forms/uploads/php/files/3b51176c5bed4b6181b739d421fdd445/64780994390.pdf
- https://ipcare.nl/wp-content/plugins/super-forms/uploads/php/files/n59hnonig40p4mg4m0tnhmtlm4/ximodev.pdf
- https://noble-worldwide.com/wp-content/plugins/super-forms/uploads/php/files/09ccd9226c5922002235ff4caf3eacc6/melimezenidekijukuvuvot.pdf
- http://lirealestatelitigator.com/wp-content/plugins/super-forms/uploads/php/files/6b91fbac08ccca7cebb172bf6215000e/79034323803.pdf
- https://directprocessors.com/wp-content/plugins/formcraft/file-upload/server/content/files/16087f76662364---6291535771.pdf
- https://qualitylightsolutions.com/wp-content/plugins/super-forms/uploads/php/files/bfa833390c3fab1a2a23e27ad81872be/petoniboka.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- pistant.ru
- cy2hand.com
- drainscovers.com
- jnfarley.com
- digemnd.com
- stakeoutllc.com
- advancedbusiness.co
- gbeequestriansurfaces.com
- bistro-8.com
- popa.com.br
- ipcare.nl
- noble-worldwide.com
- lirealestatelitigator.com
- directprocessors.com
- qualitylightsolutions.com
- www.w3.org
- purl.org
- ns.adobe.com
- harasim.cz
- falerisztika.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report