MALICIOUS — 21105896621.pdf
MALICIOUS — 21105896621.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
65085ae80d238e1b81ddc505c6be6189bff52cf275734ca92d0f569a98313ab9 - SHA-1:
ff38c3b8a13c2f656dec60200c905df61c1ef9f5 - MD5:
7da1567993eb012e2bc676e41371851a - ssdeep:
1536:oq6ezeEnoxpM/+FBYfAycJjyR4pZiph/UhxWdKALhWkpOT0nC:TheEnBZfA9JY8hI3LITN - TLSH:
T13239CFF361A7CD4CB28EDB437DFA2258158DE7886133AA801188777C85BC67EAF00951 - Submitted as: 21105896621.pdf
- File type: pdf · Size: 85744 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.hotel-margherita.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b18d671f43---21608195734.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://www.hotel-margherita.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b18d671f43---21608195734.pdf, http://massimobertoarchitetto.com/userfiles/files/suzefebopo.pdf, https://maxim-catering.de/wp-content/plugins/super-forms/uploads/php/files/rql8f21p2ojl9o2q39tcmihn5q/zoragutusuteserubez.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/BkSY9tpko7c/uplcv?utm_term=how+can+we+compress+pdf+file
- http://www.hotel-margherita.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b18d671f43---21608195734.pdf
- http://massimobertoarchitetto.com/userfiles/files/suzefebopo.pdf
- https://maxim-catering.de/wp-content/plugins/super-forms/uploads/php/files/rql8f21p2ojl9o2q39tcmihn5q/zoragutusuteserubez.pdf
- https://nexapos.com/upload/files/wisexorirojolixog.pdf
- http://test.uebersetzungen-nesselberger.de/wp-content/plugins/formcraft/file-upload/server/content/files/160bc1462a6757---42855660590.pdf
- http://mkngsp.ru/upload/files/podesafogeziraxefuxomeje.pdf
- http://www.trotasierra.com/plugins/ckfinder/userfiles/files/47750310182.pdf
- http://yanarfabrics.com/firma/files/zipunotaperisabigafexu.pdf
- https://alternativecarrepair.com/userfiles/file/9425916305.pdf
- http://heizler.hu/files/file/94843909057.pdf
- https://tlpnw.com/wp-content/plugins/super-forms/uploads/php/files/2650549869d50ee052469dfac089b44f/62000976453.pdf
- http://www.infranetltd.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b8af57c8e25---65923363254.pdf
- http://gemaeldeundobjekte.de/uploads/files/56576841566.pdf
- http://szyldkj.com/luodan/images/userfiles/file/87842412391.pdf
- http://stadiumhighschoolclassof1965.com/clients/0/00/0080f9a3d0f10e930bcfc39f0a940e94/File/20554419243.pdf
- https://notrepanierbio.ch/userfiles/file/mabewokesiraguxoja.pdf
- http://gapoom.com/upload/fckeditor/file/tevuredilobuvusibatanig.pdf
- http://harc-ias.vn/Images_upload/files/59254254615.pdf
- http://meruzhankhachatryan.com/app/webroot/files/file/87012117872.pdf
- https://ehblending.com/wp-content/plugins/super-forms/uploads/php/files/4750b7e6028675877a573e2a9dffad7d/66541321916.pdf
- http://studioaeditecne.it/userfiles/file/36472707654.pdf
- http://hongdanhaudio.com/luutru/files/63300663679.pdf
- http://4grd.com/cmsimages/file/53767342997.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- www.hotel-margherita.com
- massimobertoarchitetto.com
- maxim-catering.de
- nexapos.com
- test.uebersetzungen-nesselberger.de
- mkngsp.ru
- www.trotasierra.com
- yanarfabrics.com
- alternativecarrepair.com
- tlpnw.com
- www.infranetltd.com
- gemaeldeundobjekte.de
- szyldkj.com
- stadiumhighschoolclassof1965.com
- notrepanierbio.ch
- gapoom.com
- meruzhankhachatryan.com
- ehblending.com
- studioaeditecne.it
- hongdanhaudio.com
- 4grd.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report