MALICIOUS — 31906044241.pdf
MALICIOUS — 31906044241.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
6bbcb828d31ed590232fe4941d27efbd69fb9dd4b59823aa93e5692e6ea242c4 - SHA-1:
b084f97a5eae53a22b0a4e82acb17fc2c1d89d3f - MD5:
59cc258b970aba6c234b1ddb2c16e6f4 - ssdeep:
1536:A37Iq4EeTiXJq7gUbk4sVGB0emdtiEB2nE9Wk4qkbiqtZHOKrPM:OXLZJP8EGB0eY3cKkHtZHW - TLSH:
T15F37D0F361D7DC4C6ACAAF1769BB102D541AD2A81162AB94948CFB5CC1BCBBC7E14C10 - Submitted as: 31906044241.pdf
- File type: pdf · Size: 73417 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!59CC258B970A
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://www.orhancoskun.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e95ed239f8---gafateroz.pdf, http://sinara.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/1609a8722330ad---nimuvalamome.pdf, https://jaunimodienos.lt/wp-content/plugins/super-forms/uploads/php/files/hjjf6b4ccbekhk9e1tsjdthnfo/mupopatejowapifibotig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/PmAiG5ZyT-k/uplcv?utm_term=diesel+vs+petrol+engine+performance
- http://www.orhancoskun.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e95ed239f8---gafateroz.pdf
- http://sinara.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/1609a8722330ad---nimuvalamome.pdf
- https://jaunimodienos.lt/wp-content/plugins/super-forms/uploads/php/files/hjjf6b4ccbekhk9e1tsjdthnfo/mupopatejowapifibotig.pdf
- https://glowskincare.net/wp-content/plugins/super-forms/uploads/php/files/3cb0602505f6a11a8965dda7c3eec2e2/98917501759.pdf
- https://grafitpoint.ru/wp-content/plugins/super-forms/uploads/php/files/0b62b43fadff35658aecad889762c42d/72061070579.pdf
- https://roadtoring.com/wp-content/plugins/super-forms/uploads/php/files/d418d6b32a089279915710cf434ae0f8/lajiv.pdf
- http://absolutelyneon.com/userfiles/file/wuwusav.pdf
- https://home18.ru/wp-content/plugins/super-forms/uploads/php/files/cc39224d7f110886caa77e8d72a8abf2/89829063247.pdf
- http://amtusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cc9cc7fe2b---79339528996.pdf
- http://mwflower.com/upimagesfile/%5C/82675808542.pdf
- https://centrobrands.com/wp-content/plugins/super-forms/uploads/php/files/6281cee4e23b44d3bf0c5c609ffc7040/92007250518.pdf
- https://graffitipaintstudio.com/wp-content/plugins/super-forms/uploads/php/files/747f66e024fa833a42e562e0a4b38020/nijelulofofevivazakuko.pdf
- https://www.accidentinjurylascruces.com/wp-content/plugins/super-forms/uploads/php/files/16em97g2lcaj9ncqjm7q4n48ov/jilawererowafifobofijozek.pdf
- https://k-kompany.ru/wp-content/plugins/super-forms/uploads/php/files/43ab9beaa3add87d66091e4162916939/gagenuvofuduk.pdf
- https://ecef-groupe.com/wp-content/plugins/super-forms/uploads/php/files/dglbl12flg73f1n91ee4bcfpr0/sufuj.pdf
- http://artmetinc.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607cca1dd86a3---lefexasutumukugotaka.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- www.orhancoskun.com
- sinara.org.br
- glowskincare.net
- grafitpoint.ru
- roadtoring.com
- absolutelyneon.com
- home18.ru
- amtusa.com
- mwflower.com
- centrobrands.com
- graffitipaintstudio.com
- www.accidentinjurylascruces.com
- k-kompany.ru
- ecef-groupe.com
- artmetinc.com
- www.w3.org
- purl.org
- ns.adobe.com
- jaunimodienos.lt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report