MALICIOUS — 70752057723.pdf
MALICIOUS — 70752057723.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
601bfff2267cc7aaece89f12ca377ba4eef254c8c1f8773396058baa3dea0882 - SHA-1:
632f1f27fc954461c234a9538a121acb58c3e8f1 - MD5:
d23b143708d1f29c79130ea5e7450416 - ssdeep:
1536:LpkBFx1Ejy+M+x1HnvSXZKxqHihTm0cT+chzXWwfOv5VOWypOlWWx2qdqI/V1pDm:wbkzUZiqHihTHcTZzMlDquVFjZy - TLSH:
T1D33AC0F3306BDE5C2B478B43A9EB1169B04AD7987172EB601408B76C98BC5BD7F10452 - Submitted as: 70752057723.pdf
- File type: pdf · Size: 93957 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://suemsas.com/wp-content/plugins/super-forms/uploads/php/files/8ceus5r11r02ouqvrvbld6dt82/34627418398.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://suemsas.com/wp-content/plugins/super-forms/uploads/php/files/8ceus5r11r02ouqvrvbld6dt82/34627418398.pdf, https://kvartira-zalog.ru/wp-content/plugins/super-forms/uploads/php/files/b307c767ed68818014d23a9efb8d282f/63012762553.pdf, https://www.chauffeur-prive-nice.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16097af9ba3f35---rubemezegesiwewovusapimi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/GLLx1DTH0VQ/uplcv?utm_term=do+you+really+need+a+college+education+to+be+successful
- https://suemsas.com/wp-content/plugins/super-forms/uploads/php/files/8ceus5r11r02ouqvrvbld6dt82/34627418398.pdf
- https://kvartira-zalog.ru/wp-content/plugins/super-forms/uploads/php/files/b307c767ed68818014d23a9efb8d282f/63012762553.pdf
- https://www.chauffeur-prive-nice.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16097af9ba3f35---rubemezegesiwewovusapimi.pdf
- http://c2mag.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e2e937ae59f---zazepojojipukosijuroropa.pdf
- http://www.cuadernos.in/wp-content/plugins/formcraft/file-upload/server/content/files/160cbbdaeef899---3819714980.pdf
- http://wildpflanzen-planung.de/file/54826985213.pdf
- https://monacollection.ua/wp-content/plugins/super-forms/uploads/php/files/19cdd7f2ca3c1b3aed3b98ff213769b3/buxegope.pdf
- http://www.a-fairys-choice.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cfa66006c53---fetelavuruvunuku.pdf
- http://xn--rssx31a7tec6p.com/upload/userfiles/files/20210625182904.pdf
- https://www.ayersworthglen.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ad820558ad3---98382413217.pdf
- https://monyetjoget.com/contents//files/jekavi.pdf
- https://astoriareiki.com/wp-content/plugins/super-forms/uploads/php/files/cd81b18e56434aae4e71b83f3ca33210/66757317614.pdf
- https://angelsstaff.com/uploads/file/28361850974.pdf
- http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b2cf2ba8260---81155660908.pdf
- https://soyana.de/js/ckfinder/userfiles/files/41249433865.pdf
- https://canionglobal.com/FCKeditor/file/29229491265.pdf
- https://fmpride.com/wp-content/plugins/super-forms/uploads/php/files/58cbcb050a4c1f305ae6bd37b7fa60e8/92706319643.pdf
- https://flylights.pl/wp-content/plugins/super-forms/uploads/php/files/3u95nrilan7r89jfpc4oeall6l/61893818282.pdf
- http://hyderabadibiryanicorner.com/admin/images/file/52808298261.pdf
- http://xaydunghoangthanh.com/img_duhoc/files/37770965212.pdf
- http://aite-materials.com/upfiles/file/loxusireni.pdf
- http://gennarimaq.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1607d52b7cd9ef---dowapaxosororoxizek.pdf
- http://trackeg.com/en/wp-content/plugins/formcraft/file-upload/server/content/files/16083cfaa0c962---xinevajuf.pdf
- http://www.musicmaestrodiscos.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1607f94d01427b---71560435518.pdf
Embedded domains
- feedproxy.google.com
- suemsas.com
- kvartira-zalog.ru
- www.chauffeur-prive-nice.fr
- c2mag.com
- www.cuadernos.in
- wildpflanzen-planung.de
- monacollection.ua
- www.a-fairys-choice.com
- xn--rssx31a7tec6p.com
- www.ayersworthglen.com
- monyetjoget.com
- astoriareiki.com
- angelsstaff.com
- leap-egypt.com
- soyana.de
- canionglobal.com
- fmpride.com
- flylights.pl
- hyderabadibiryanicorner.com
- xaydunghoangthanh.com
- aite-materials.com
- gennarimaq.com.br
- trackeg.com
- www.musicmaestrodiscos.co.uk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report