MALICIOUS — 68672992405.pdf
MALICIOUS — 68672992405.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
616ecb6521948f95a56024cc0298fd153d33da649fbb688ebd1246be558a46fb - SHA-1:
7c0c24f55326f5e0938708a2ae65371a243a5fae - MD5:
cb55166b6e335b3082c024aa167bf17e - ssdeep:
1536:VtIE514Q9ovyr81nkYs8kEVmuBYPEveDEsiHzhS5UWGpOKCWDMgLBcP8rjNsvWX/:/I8KAiyrmnJkk/GANHoZK9Mm8+sPfe7 - TLSH:
T1F039C0F361ABCD5CBB878B4368D606ECE04ED3841323EE946598B66C857CA7DEE00550 - Submitted as: 68672992405.pdf
- File type: pdf · Size: 91271 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.kindytennis.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078fdfb0f171---30879180892.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://nomylo.ru/uplcv?utm_term=not+exists+clause+in+sql, http://www.caslyn.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1607a14a839ec9---2898489497.pdf, http://www.kindytennis.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078fdfb0f171---30879180892.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nomylo.ru/uplcv?utm_term=not+exists+clause+in+sql
- http://www.caslyn.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1607a14a839ec9---2898489497.pdf
- http://www.kindytennis.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078fdfb0f171---30879180892.pdf
- https://hps-gruppe.com/wp-content/plugins/super-forms/uploads/php/files/abe8lkea6cnttorbmg1k33mboe/29956254716.pdf
- http://www.colegiometa.net/home/wp-content/plugins/formcraft/file-upload/server/content/files/1609db0f5de4fb---26661472977.pdf
- https://thietbidienmanhcuong.com/upload/files/ribelasok.pdf
- https://www.guestquesttravelmedia.com/wp-content/plugins/super-forms/uploads/php/files/00i38uagalkcn5aa7ag326tqpf/davusonibutixu.pdf
- http://www.adanakursmerkezi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cb9ab5e39db---dikixa.pdf
- http://turatabor.hu/media/xitenemuku.pdf
- http://ulrike-mayer.de/userfiles/files/wozukovujalupolekukix.pdf
- http://younewstoday.com/task/userimages/file/bafezuxugujeremitan.pdf
- http://www.chicagoalphas.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606fa34c06469---90884404366.pdf
- http://www.belladermeestetica.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160a5a46c88f8d---jetegom.pdf
- http://www.putnamtaxi.net/wp-content/plugins/formcraft/file-upload/server/content/files/160705ecaba547---27568959718.pdf
- http://raduzhniy.com/wp-content/plugins/formcraft/file-upload/server/content/files/160948991a2df4---49370038508.pdf
- https://www.alongsideasia.com/wp-content/plugins/super-forms/uploads/php/files/e710c8f91f500c8669bcb624828b73e9/semetavo.pdf
- https://buddingheights.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607caac90a590---57361512296.pdf
- http://i-dron.cz/data/file/joxidiwekozefe.pdf
- http://www.driftime.ee/wp-content/plugins/formcraft/file-upload/server/content/files/160a68f48dd9fc---dusepafukamujolesuwir.pdf
- https://devcons.org/uploads/userfiles/files/46605666583.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b29512e66e7---4259568458.pdf
- https://smoothnomad.com/wp-content/plugins/super-forms/uploads/php/files/obvuv0p15id3vm108cjrl0g5te/vanijirinamafakub.pdf
- https://www.parkgest.ch/wp-content/plugins/formcraft/file-upload/server/content/files/16085284123322---24570094337.pdf
- https://www.myjamaicais.com/wp-content/plugins/super-forms/uploads/php/files/071945c4fa94cc10831ef782ae22788a/93935138567.pdf
- http://raduzhniy.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ac1ed79ebb2---13801408535.pdf
Embedded domains
- nomylo.ru
- www.caslyn.co.za
- www.kindytennis.com
- hps-gruppe.com
- www.colegiometa.net
- thietbidienmanhcuong.com
- www.guestquesttravelmedia.com
- www.adanakursmerkezi.com
- ulrike-mayer.de
- younewstoday.com
- www.chicagoalphas.com
- www.belladermeestetica.com.br
- www.putnamtaxi.net
- raduzhniy.com
- www.alongsideasia.com
- buddingheights.org
- devcons.org
- www.1000ena.com
- smoothnomad.com
- www.parkgest.ch
- www.myjamaicais.com
- www.w3.org
- purl.org
- ns.adobe.com
- turatabor.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report