MALICIOUS — 46300451529.pdf
MALICIOUS — 46300451529.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6a9cc38a7f2e0bd8063063054f0ccd1cf122798e1137e590d128eb24b583e214 - SHA-1:
ed9d376a6d6efce4d48416378cb4b996ae58559d - MD5:
fb4c47486fee230f1050a72fb0ed93aa - ssdeep:
1536:BkKJRlGZh61X0cnDcbtbDEfC9PiQBtrRe3tG66/f1mkWwrYRq3Wf3Ga2UPdW8pOG:kD69ZnQbtbwCJiOrRe3tGd93WvG3SM+L - TLSH:
T17838C0F311DBDC8C764F8F4768BA1595B489D3883522AE9091C8BB7C887CABD7E01941 - Submitted as: 46300451529.pdf
- File type: pdf · Size: 81995 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://joesservicecenternj.com/userfiles/files/wukujarexasavuzolirezum.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://joesservicecenternj.com/userfiles/files/wukujarexasavuzolirezum.pdf, http://custom-mugs-factory.com/uploadfile/files/89213783635.pdf, https://www.bbmnetlicitacoes.com.br/cms/ckfinder/upload/files/musivefamugiwu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/cv9VXjIrmdE/uplcv?utm_term=android+tv+play+store+update
- http://joesservicecenternj.com/userfiles/files/wukujarexasavuzolirezum.pdf
- http://custom-mugs-factory.com/uploadfile/files/89213783635.pdf
- https://www.bbmnetlicitacoes.com.br/cms/ckfinder/upload/files/musivefamugiwu.pdf
- http://xn--4k0b43gkwo4gn.com/upload/editor/file/89982323805.pdf
- https://atamergranit.com/userfiles/file/nuzusovixozemunenudeviv.pdf
- http://highdesertrent.com/newsite/images/uploads/file/wegixulilumekosutezodidu.pdf
- http://pulsrmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132b00f38091---67015243095.pdf
- http://studioiulianella.it/userfiles/files/xikitiwivorafofusadika.pdf
- http://texinpack.com/uploadfile/file///2021092223122164.pdf
- http://czernavendeghaz.hu/admin1/file/99610524400.pdf
- http://adhunikjewellers.com/ckfinder/userfiles/files/gezotimurilatajepenu.pdf
- https://ewms.vn/wp-content/plugins/super-forms/uploads/php/files/pmes4vrbkm9fm01c5tp2q382fk/53461467185.pdf
- https://avflash.nl/upload/files/satavororozuxutowi.pdf
- http://ulv-fogger.ru/d/files/10914334922.pdf
- http://subventionsbetrug.de/wp-content/plugins/super-forms/uploads/php/files/4tib8bh2br4rrmcll208qs6jc4/97048527623.pdf
- http://www.bridalchapel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613a6430c0e60---toboxuzobowupini.pdf
- https://manage3.realtourvision.com/rtv/ckfinder/userfiles/images/files/2188789309.pdf
- http://tropo-design.com/ckfinder/userfiles/files/baravozezojubizuro.pdf
- http://congseng.com/uploadfile/files/11684999463.pdf
- http://moscowballet.ru/userfiles/file/40193742201.pdf
- http://camonetinternational.com/files/file/savulakisaxumu.pdf
- https://ptkas.com/kingkong/userfiles/files/zulilanofebanozogovijale.pdf
- http://adacu.org/userfiles/file/20210918172102.pdf
- http://garage-ys.info/js/upload/files/26730532299.pdf
Embedded domains
- feedproxy.google.com
- joesservicecenternj.com
- custom-mugs-factory.com
- www.bbmnetlicitacoes.com.br
- xn--4k0b43gkwo4gn.com
- atamergranit.com
- highdesertrent.com
- pulsrmedia.com
- studioiulianella.it
- texinpack.com
- adhunikjewellers.com
- avflash.nl
- ulv-fogger.ru
- subventionsbetrug.de
- www.bridalchapel.com
- manage3.realtourvision.com
- tropo-design.com
- congseng.com
- moscowballet.ru
- camonetinternational.com
- ptkas.com
- adacu.org
- garage-ys.info
- zoltysnieg.pl
- ineke-ott.nl
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report