MALICIOUS — 35807231272.pdf
MALICIOUS — 35807231272.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
67cb30a801147e792fe54c7efe545f78d8d045a1b87638fea982cd05ae7c37ea - SHA-1:
f67ebd1ed447ddbf98092e94228008166a251bec - MD5:
7301c83c3342e26983e771b5f1ef2d87 - ssdeep:
1536:XrkRYYNOBY9hvFoJn/uYHF4CaVHi7VXxs+WCpOVi8KU3WO8G2uZoOl:sjNEcdFAWYIHIVXxsTVi8KU/R2uZD - TLSH:
T13E38C0F7528BDD5C7B978F9369AB00A9944BE3C86223DB914188723CD4BC9BCEB00551 - Submitted as: 35807231272.pdf
- File type: pdf · Size: 81153 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.goataxiservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1610410595c3d6---wipomuxavuz.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://krisoc.ru/uplcv?utm_term=acids+and+bases+worksheet+%231, http://kommunikator.nu/demo/userfiles/file///raxanol.pdf, http://cameradungphat.com/uploads/files/52239249042.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://krisoc.ru/uplcv?utm_term=acids+and+bases+worksheet+%231
- http://kommunikator.nu/demo/userfiles/file///raxanol.pdf
- http://cameradungphat.com/uploads/files/52239249042.pdf
- http://zulaikhatextile.com/userfiles/files/nosotozijipazotuzoriku.pdf
- http://xboxheerlen.nl/userfiles/file/nigugu.pdf
- https://aokman-drive.com/d/files/33513561809.pdf
- http://audiomaster.se/wp-content/plugins/formcraft/file-upload/server/content/files/160d26807e0f4e---87839448525.pdf
- http://iltorg.ru/upload/file/guzuno.pdf
- http://www.goataxiservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1610410595c3d6---wipomuxavuz.pdf
- http://alanaf.ru/userfiles/files/mofopot.pdf
- http://chinamakina.com/userfiles/file/22889935196.pdf
- http://adabaskimerkezi.com/upload/file/98212812598.pdf
- https://ehotelgateway.com/bot/ckfinder/uf/files/pimolosiguwifolelowa.pdf
- http://rayanchem.com/d/files/27769067447.pdf
- http://taeguektour.com/FileData/ckfinder/files/20210628_1EB6B0F4FA96C87A.pdf
- https://vmkstroi.ru/wp-content/plugins/super-forms/uploads/php/files/47300216258880e533952d0b044b6ced/86830696525.pdf
- http://mamtomchabahai.com/uploads/files/files/mafurafivegidimesevetu.pdf
- https://www.hinogas.com/wp-content/plugins/super-forms/uploads/php/files/et7m0uahoe9rljko29qb0054cv/jiwurijixijirugizato.pdf
- http://skuplaptop.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160a4c5fd3b9a7---3431072379.pdf
- https://esteticarcare.com/wp-content/plugins/super-forms/uploads/php/files/a303e8e942a87516c8ad0cdb0b26e25d/ketigiserelabejosimofa.pdf
- https://bahceneryaman.net/public/content-images/files/6802892412.pdf
- http://sugarfree-gelato.com/upload/file/58444257179.pdf
- https://smarttactic.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16083b504c1f50---88536456827.pdf
- http://gewoongroen.eu/app/webroot/files/userfiles/files/mikudoxoxinubod.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160825f2a99dd0---nizofet.pdf
Embedded domains
- krisoc.ru
- cameradungphat.com
- zulaikhatextile.com
- xboxheerlen.nl
- aokman-drive.com
- audiomaster.se
- iltorg.ru
- www.goataxiservice.com
- alanaf.ru
- chinamakina.com
- adabaskimerkezi.com
- ehotelgateway.com
- rayanchem.com
- taeguektour.com
- vmkstroi.ru
- mamtomchabahai.com
- www.hinogas.com
- skuplaptop.pl
- esteticarcare.com
- bahceneryaman.net
- sugarfree-gelato.com
- gewoongroen.eu
- www.1000ena.com
- spherule.org
- bellevuecommunityfoodbank.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report