MALICIOUS — 160c8cc1ea9a11---38138031417.pdf
MALICIOUS — 160c8cc1ea9a11---38138031417.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
5cac620774f5a77422dfd234ed556b63fe57c6a8bbe5a32b7bf6c8c02b80ac8a - SHA-1:
84c881dd717c982a750702418e433a3e87dfaf2d - MD5:
8461aba7553628b203174f7b5feee825 - ssdeep:
1536:yzUnRc/YSiYf/imZilCGEmRI3LH/FeZexGfq6Eqxfa9zNq/OIfz:5RuSYf/7imyI3Lf6ex/rcIM/Lz - TLSH:
T13D38D0F3244BED8CFA976B83B9E645B86059C348A072EB5441C8F62CD5786BCBF05811 - Submitted as: 160c8cc1ea9a11---38138031417.pdf
- File type: pdf · Size: 77026 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!8461ABA75536
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://crewmak.ru/uplcv?utm_term=cara+ubah+jpeg+ke+pdf, http://sjhrz.com/images/upload/File/bogefabidol.pdf, https://tectrongim.com/uploads/files/koripine.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crewmak.ru/uplcv?utm_term=cara+ubah+jpeg+ke+pdf
- http://sjhrz.com/images/upload/File/bogefabidol.pdf
- https://tectrongim.com/uploads/files/koripine.pdf
- https://www.enviedecrire.com/wp-content/plugins/formcraft/file-upload/server/content/files/160978204d1ede---62541232203.pdf
- http://bagpack.com.np/wp-content/plugins/formcraft/file-upload/server/content/files/1609088784380a---woriwivotagina.pdf
- https://eyestech.in/wp-content/plugins/super-forms/uploads/php/files/vimb0b7eb0ts4n2rkqfhg45anu/zetugoziji.pdf
- https://www.albispanaderia.com/wp-content/plugins/super-forms/uploads/php/files/395036789eb029512d3dc73b25e7807c/75351661726.pdf
- http://adanateknikservis.web.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16087bedbbee32---ruvakodubolinixovowifeler.pdf
- https://baodinhsolar.com/wp-content/plugins/super-forms/uploads/php/files/bsmoaavkctm2smt3j31cvh5p72/56545125559.pdf
- https://www.msolartop.cz/wp-content/plugins/formcraft/file-upload/server/content/files/1608cc430dc4f1---82473402041.pdf
- http://mobilesamara.com/img/files/file/3033990741.pdf
- https://coachtourbusrental.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607d1fdc554d3---92024686255.pdf
- http://www.hollyskauaicondo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160768d04e0318---tepasufejadafiluxono.pdf
- https://maydongy.com/wp-content/plugins/super-forms/uploads/php/files/s3pt8gotc5a5k4b46km7f4j9kp/bovavesigurumijas.pdf
- http://www.britocunhaadvocacia.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/160b810cca03fe---xedomeporusenev.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- crewmak.ru
- sjhrz.com
- tectrongim.com
- www.enviedecrire.com
- eyestech.in
- www.albispanaderia.com
- baodinhsolar.com
- mobilesamara.com
- coachtourbusrental.com
- www.hollyskauaicondo.com
- maydongy.com
- www.britocunhaadvocacia.com.br
- www.w3.org
- purl.org
- ns.adobe.com
- bagpack.com.np
- adanateknikservis.web.tr
- www.msolartop.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report