MALICIOUS — 4986472614.pdf
MALICIOUS — 4986472614.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
67702b893f745df29d3da9176089ecb43288209d145c28c83337773cd03975db - SHA-1:
e1d6774a8fd04d48ac81728091507b496f91cb1f - MD5:
0fa592e9a5c16c2e7b01851c8707fd16 - ssdeep:
1536:5aO7LMB/Y962RDqi+zi4o8PqknwhMQCrtEKR1FzWOpOwrKWcwEJQsgBq+10wHbt:kOPMa62Ahzin8PqkwhMQC5//Qwr2wAbW - TLSH:
T16538CFF3619BDD4CBB8B970719BB11AC644AD3C86271DBC04184B76C89BC97DBE10A20 - Submitted as: 4986472614.pdf
- File type: pdf · Size: 81754 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://jkbprivateiti.com/userfiles/file/pikajogurijugenonozafuj.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://smidgel.ru/uplcv?utm_term=rome+total+war+2+download+android, https://butzbacher.turnpoint.jo/app/webroot/upload/files/tezowemos.pdf, http://sgyscom.com/upload_fck/file/2021-9-5/20210905005442147497.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://smidgel.ru/uplcv?utm_term=rome+total+war+2+download+android
- https://butzbacher.turnpoint.jo/app/webroot/upload/files/tezowemos.pdf
- http://sgyscom.com/upload_fck/file/2021-9-5/20210905005442147497.pdf
- http://jkbprivateiti.com/userfiles/file/pikajogurijugenonozafuj.pdf
- http://metzpaintings.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612eaca0f15a1---51131787632.pdf
- http://dulichtantai.com/files/uploaded/files/90063701977.pdf
- https://atputasbazes.lv/images/userfiles/files/2043996454.pdf
- http://norilskgu.ru/userfiles/file/98821974713.pdf
- http://gamax-moto.cz/data/dokumenty/68298108585.pdf
- http://shimamura-mail-order.com/userfiles/file/84778114511.pdf
- http://1137.jp/app/webroot/js/ckfinder/userfiles/files/givopuzulowuj.pdf
- http://178.62.148.222:300/ckeditor/ckfinder/userfiles/files/dunalawupufiwugawemagelu.pdf
- http://merlegdoktor.hu/tmp/20751235682.pdf
- http://tcyy88.com/userfiles/file/2021090305263373499.pdf
- http://imobilestore.de/userfiles/file/73454718097.pdf
- https://doanhnghiepvietnam.niengiamdoanhnghiep.vn/img_duhoc/files/pazuduruviwatix.pdf
- https://wisestudentz.com/userfiles/file/kipojuwadunasuwixa.pdf
- http://quocteanviet.com/img-chamthi/files/80519254449.pdf
- https://husvagnsexpo.se/wp-content/plugins/formcraft/file-upload/server/content/files/16136fe8901423---wujarataladufeb.pdf
- https://dongphuchuytai.com/upload/files/fetebigezolile.pdf
- https://pearproperties.in/userfiles/file/28975833102.pdf
- http://linhkienhunganh.vn/luutru/files/kibosudoviboze.pdf
- https://antoinepanau.com/wp-content/plugins/super-forms/uploads/php/files/9d62fb875adf608536cf41e78e50f7b5/47468205873.pdf
- http://l-max.ru/userfiles/file/geraxefelagowusozel.pdf
- http://cioccolatogallucci.it/userfiles/file/fenerajuvonawejimilotipaf.pdf
Embedded domains
- smidgel.ru
- sgyscom.com
- jkbprivateiti.com
- metzpaintings.com
- dulichtantai.com
- norilskgu.ru
- shimamura-mail-order.com
- 1137.jp
- tcyy88.com
- imobilestore.de
- wisestudentz.com
- quocteanviet.com
- husvagnsexpo.se
- dongphuchuytai.com
- pearproperties.in
- antoinepanau.com
- l-max.ru
- cioccolatogallucci.it
- limpiasol.com
- www.w3.org
- purl.org
- ns.adobe.com
- butzbacher.turnpoint.jo
- atputasbazes.lv
- gamax-moto.cz
Embedded IP addresses
- 178.62.148.222
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report