MALICIOUS — 24965672666.pdf
MALICIOUS — 24965672666.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6a4e1b0a5a7f4c8180de33cf00a61f9cbdaf99e3f654478be20a92b844024f73 - SHA-1:
5908e03d2313a31018349009ea1dbff0911207e3 - MD5:
7cb6eac30ffc9362837eafe4bd63e51f - ssdeep:
1536:OZKiSQX6dxWGhv+AnrVXPDuuWNB8M7c6Zy+Mlcfrw5lqNIAnJoIr5jxJ:YHSQX67LnVPSh0M74lcfrGlUnJoIr5n - TLSH:
T1C537E1F3B207CD9CB98BAB0364A201685496D2863033BB68554CF7ACC4F437DBE14952 - Submitted as: 24965672666.pdf
- File type: pdf · Size: 76202 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!7CB6EAC30FFC
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://bioident.pl/photos_fck/file/64626214033.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://thewentworthco.com/wp-content/plugins/super-forms/uploads/php/files/4abmluiv9dng47o4h7gddapqus/tadosovuxuxotuboruzuwij.pdf, https://www.sharpeningfactory.com/wp-content/plugins/formcraft/file-upload/server/content/files/16091f165e7e5e---jumetejisaj.pdf, http://www.pilonidalsinus.gen.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160708d6860705---gagum.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/A3Ryygt5BCM/uplcv?utm_term=beowulf+chapter+1-18+summary
- https://thewentworthco.com/wp-content/plugins/super-forms/uploads/php/files/4abmluiv9dng47o4h7gddapqus/tadosovuxuxotuboruzuwij.pdf
- https://www.sharpeningfactory.com/wp-content/plugins/formcraft/file-upload/server/content/files/16091f165e7e5e---jumetejisaj.pdf
- http://www.pilonidalsinus.gen.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160708d6860705---gagum.pdf
- http://bizbecho.com/pa/trainstation/uploads/image/file/wamitevimadisi.pdf
- http://bioident.pl/photos_fck/file/64626214033.pdf
- https://petala.gr/userfiles/file/vilog.pdf
- https://latework.cz/soubory/rawoxatepafugibifoziruta.pdf
- https://siphouse96.com/wp-content/plugins/super-forms/uploads/php/files/cbbf841b2a06f68b3728eee1108b6c6a/salatif.pdf
- https://www.ediliziaindustriale.com/wp-content/plugins/formcraft/file-upload/server/content/files/16094d6b21d553---zidog.pdf
- https://www.frontierexim.com/wp-content/plugins/super-forms/uploads/php/files/togee74jdrksh5ria8lsjtslsr/44919364775.pdf
- https://www.xcelsus.de/wp-content/plugins/formcraft/file-upload/server/content/files/160a8fa56946db---57514663082.pdf
- http://lycee-elm.org/userfiles/file/vexivosulipuwikasenozefi.pdf
- http://thehawthornnyc.com/wp-content/plugins/formcraft/file-upload/server/content/files/16081629a4ba09---21255011373.pdf
- https://braviengenharia.com.br/wp-content/plugins/super-forms/uploads/php/files/inffo6q6q1okbs51u0erulf656/pipukalematimaxopa.pdf
- https://www.ediliziaindustriale.com/wp-content/plugins/formcraft/file-upload/server/content/files/16081b29d31243---kujatelapo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- thewentworthco.com
- www.sharpeningfactory.com
- bizbecho.com
- bioident.pl
- siphouse96.com
- www.ediliziaindustriale.com
- www.frontierexim.com
- www.xcelsus.de
- lycee-elm.org
- thehawthornnyc.com
- braviengenharia.com.br
- www.w3.org
- purl.org
- ns.adobe.com
- www.pilonidalsinus.gen.tr
- petala.gr
- latework.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report