MALICIOUS — 160aad3ce36cba---5634090043.pdf
MALICIOUS — 160aad3ce36cba---5634090043.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
70d089d52633fa3fff99d37889c9fb22030dd261b271e47bd202c40c91e676e9 - SHA-1:
b18c5928761939c23612e529589484206353e5a4 - MD5:
1601d937dfa78878512e304334071a89 - ssdeep:
1536:VhcfvSEbBA9S2kAP18uNqDXOAkDFsEp5mNhURdmBYMhu3ohmtpbn:HSNwSPAPVqDXyF1fmyMhpmn - TLSH:
T1C137D0F35147CC8C7B8777D359A621BCA086D3892122D75818C8B72CC5B8ABEBF24950 - Submitted as: 160aad3ce36cba---5634090043.pdf
- File type: pdf · Size: 76525 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!1601D937DFA7
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://nomylo.ru/uplcv?utm_term=minecraft+classic+unblocked+crazy+games, https://beautifullifeuk.com/wp-content/plugins/super-forms/uploads/php/files/5602cf4262823faf1e39f6552f520942/98599912005.pdf, https://kodeac.com/wp-content/plugins/super-forms/uploads/php/files/6pcopeq6j6bpa2gs0k631qcfmf/dunopex.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nomylo.ru/uplcv?utm_term=minecraft+classic+unblocked+crazy+games
- https://beautifullifeuk.com/wp-content/plugins/super-forms/uploads/php/files/5602cf4262823faf1e39f6552f520942/98599912005.pdf
- https://kodeac.com/wp-content/plugins/super-forms/uploads/php/files/6pcopeq6j6bpa2gs0k631qcfmf/dunopex.pdf
- http://cricalliance.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608a97034a481---malazugidugug.pdf
- https://al-farh-iq.com/upload/userfiles/file/75634533684.pdf
- https://olmitek.by/wp-content/plugins/super-forms/uploads/php/files/q7bcjfgg8moff9b76iu7747423/5942834396.pdf
- https://hsegroup.ru/wp-content/plugins/super-forms/uploads/php/files/rdhmgvhdvosdpusofrfnuv3i94/wupal.pdf
- https://jnfarley.com/wp-content/plugins/super-forms/uploads/php/files/u47o313uftnh0pdcj1kc9oo273/57925434780.pdf
- https://action-roofing.com/wp-content/plugins/super-forms/uploads/php/files/55068a873328126f3f7bb9397291e3a9/20671032293.pdf
- http://agcslohian.com/userfiles/file/fenijupopobo.pdf
- https://www.medicalart.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1606fb482dd0bb---31668755950.pdf
- http://sts-logistika.ru/wp-content/plugins/super-forms/uploads/php/files/3263eb9eb76a6919999aaf77f5825af3/voguz.pdf
- https://www.kadinlarsitesi.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608af39ea6609---pedunakafefefikuxupofezi.pdf
- http://villaturri.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607ea5275b29a---67116970598.pdf
- http://uniondeautoescuelas.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f3003ecc3e---90881004069.pdf
- https://veritiesinstitute.com/wp-content/plugins/super-forms/uploads/php/files/58e6297503b918ba395b70a1dca26b8a/ruvixiduzufapilafazute.pdf
- https://www.opdrrustukalac.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d0b07bd75c---65303440329.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- nomylo.ru
- beautifullifeuk.com
- kodeac.com
- cricalliance.com
- al-farh-iq.com
- hsegroup.ru
- jnfarley.com
- action-roofing.com
- agcslohian.com
- sts-logistika.ru
- www.kadinlarsitesi.org
- villaturri.com
- uniondeautoescuelas.com
- veritiesinstitute.com
- www.opdrrustukalac.com
- www.w3.org
- purl.org
- ns.adobe.com
- olmitek.by
- www.medicalart.com.tr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report