MALICIOUS — 45510315186.pdf
MALICIOUS — 45510315186.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
69d17d245f6cbea0157c8952966fee41cceae95c675dd0890565d7604f7b559c - SHA-1:
5b5c083afc4727eba5bf80f7262ee640c7abd930 - MD5:
22c6e640d5eb3581b6b36ebb0cc42034 - ssdeep:
1536:wYtwigSNZZv9/4FuUU//ftR1roKbN6VQgN8rWg7IQGBPbWepOZ/lZ:uigSHZCFuUUVR1roKbNEQgN8RsQGBP8Z - TLSH:
T12638D0F331DBDD4CB24B9F8379BA1169A14DE7C45172EB508048B56C947CABDAF00681 - Submitted as: 45510315186.pdf
- File type: pdf · Size: 83143 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://studiosantese.eu/userfiles/files/xukijid.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://inwebjor.ru/uplcv?utm_term=high+rollers+word+whizzle, http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/5noqm3hliuvgo91t9bf4i85vd6/5353361599.pdf, https://www.straightmyteeth.com/wp-content/plugins/super-forms/uploads/php/files/4763a11cd3ee37373cb09ee474199d83/nusivalotununitudaxop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://inwebjor.ru/uplcv?utm_term=high+rollers+word+whizzle
- http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/5noqm3hliuvgo91t9bf4i85vd6/5353361599.pdf
- https://www.straightmyteeth.com/wp-content/plugins/super-forms/uploads/php/files/4763a11cd3ee37373cb09ee474199d83/nusivalotununitudaxop.pdf
- https://digireg.org/upload/zodokigibufufevuge.pdf
- https://firmabudowlanawalczak.pl/web/uploads/files/gejupebedo.pdf
- https://nikken-engineer.jp/export/sd205/www/jp/r/e/gmoserver/8/6/sd0748886/nikken-engineer.jp/fckeditor/upload/file/46034521982.pdf
- http://studiosantese.eu/userfiles/files/xukijid.pdf
- http://skiflogistics.ru/userfiles/file/rovunibaselarix.pdf
- http://apartmaji-zunicmile.com/uporabnik/file/47200726525.pdf
- https://robertbah.si/files/file/90201197793.pdf
- https://medtek.vn/storage/file/zebofonosajufipidi.pdf
- http://www.vivelamusica.es/wp-content/plugins/formcraft/file-upload/server/content/files/1611462671c6d6---97971183392.pdf
- http://mp-hd.de/data/aktualnosci_imgs/file/6951547566.pdf
- https://propbrains.com/wp-content/plugins/super-forms/uploads/php/files/e73fda9a9fa918282752e2125db9b887/61650379282.pdf
- https://ddriu.hu/wp-content/plugins/super-forms/uploads/php/files/2c3902a34f15a10c693fe446151cf2c3/zutesezigaferozagerewiza.pdf
- https://utilitydiscount.com/wp-content/plugins/formcraft/file-upload/server/content/files/16083df0739a36---xatudojawusoti.pdf
- https://www.havanasalsa-dance-tours.com/wp-content/plugins/super-forms/uploads/php/files/0f4126092b1f396bc90f10a75d3509f4/56279007380.pdf
- https://mkycc4.com/kycc4.com/userfiles/files/witetolujitipolizo.pdf
- http://apexibd.com/uploads/fck_uploads/file/dunaxumavibebiw.pdf
- http://inse.us/uploads/images//files/71753976913.pdf
- https://prolocolidodisavio.org/ckfinder/userfiles/files/12102800534.pdf
- https://wineart.online/userfiles/file/bagojuz.pdf
- https://avenirpourtous.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16074ade12813e---61083804645.pdf
- http://punaide.com/userfiles/files/tunorevegat.pdf
- https://doitsolutions.co/wp-content/plugins/super-forms/uploads/php/files/c27477a6eb98d89bb0e842d329e71d30/92597054826.pdf
Embedded domains
- inwebjor.ru
- www.sunarnuricomuisvealisverismerkezi.com
- www.straightmyteeth.com
- digireg.org
- firmabudowlanawalczak.pl
- nikken-engineer.jp
- studiosantese.eu
- skiflogistics.ru
- apartmaji-zunicmile.com
- www.vivelamusica.es
- mp-hd.de
- propbrains.com
- utilitydiscount.com
- www.havanasalsa-dance-tours.com
- mkycc4.com
- kycc4.com
- apexibd.com
- inse.us
- prolocolidodisavio.org
- wineart.online
- avenirpourtous.fr
- punaide.com
- doitsolutions.co
- hobbstownis100.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report