MALICIOUS — 66031656299.pdf
MALICIOUS — 66031656299.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
71bc91b60b7adc1d223319a339f306c82dd4e6a8805bd2738dcb0d1b53284188 - SHA-1:
acff5e2e674debe58254eb468bc9347db566cbcd - MD5:
986a8aa5bb3d7accea47bb8a0ef04dd1 - ssdeep:
1536:QEF1Q6bmSgn1xFIIogCVRC2w88t+a1buRhH3PyK6MHvWOpOwr3blkWY/pIG/jPYJ:rF1Q66xFDogsR9ta1bG/yKGwr3blipI3 - TLSH:
T1C139DFF76197DD4CB68BDB03656A109C648AE78C2132EEA0544C7B7CC8BC5BEAE00640 - Submitted as: 66031656299.pdf
- File type: pdf · Size: 85424 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://rosritual.su/app/webroot/js/ckfinder/userfiles/files/68127759907.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://rosritual.su/app/webroot/js/ckfinder/userfiles/files/68127759907.pdf, https://lecormier-menuiserie.com/www/upload/files/97083601906.pdf, https://tipresentoio.it/images/file/mazimovewelasilapojuxa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/zMnd8XtcwSM/uplcv?utm_term=addison-wesley+publishing+company+worksheet+answers+for+science
- http://rosritual.su/app/webroot/js/ckfinder/userfiles/files/68127759907.pdf
- https://lecormier-menuiserie.com/www/upload/files/97083601906.pdf
- https://tipresentoio.it/images/file/mazimovewelasilapojuxa.pdf
- https://www.caesarstravel.com/wp-content/plugins/formcraft/file-upload/server/content/files/16087785356653---75708501284.pdf
- https://rffsev.ru/wp-content/plugins/super-forms/uploads/php/files/e764211516259e72a3031144227cfa94/gewirarafi.pdf
- http://banning64reunion.com/clients/a/a7/a71e9339640f4be667ed55590a288245/File/86055243244.pdf
- https://maydongy.com/wp-content/plugins/super-forms/uploads/php/files/51v30sfhgj8vu05j9ig6st4don/61596909966.pdf
- http://giaexploring.it/userfiles/files/89292704605.pdf
- https://zemiigori.com/uploads/file/97660916870.pdf
- http://www.jcca.co.in/wp-content/plugins/formcraft/file-upload/server/content/files/160a2158e15e7f---13410861082.pdf
- http://exoticland.bg/upload/files/files/kulabafixewemomodise.pdf
- https://goldenlinejsc.com/userfiles/file/43820736632.pdf
- http://divapharma.com/uploaded/file/36177583177.pdf
- https://cspdental.com/wp-content/plugins/super-forms/uploads/php/files/571a177ee3a9c1df1f6abba1e27104d7/nulagotifanopojukulo.pdf
- https://www.ideaklinik.com/wp-content/plugins/formcraft/file-upload/server/content/files/160782d98eeadf---22341548502.pdf
- http://stroynerud-sm.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1609380a14d2c3---xelufogopusobisiviz.pdf
- https://diversified-nj.com/wp-content/plugins/super-forms/uploads/php/files/6022f47cabac65a2a32236e3cb4252ff/zenejatawifuvusixiwunakor.pdf
- http://apartmany.cucoriedka.sk/data/files/melitajajisil.pdf
- https://hoovermaids.com/wp-content/plugins/super-forms/uploads/php/files/b9cfe4de08e34cf5b109754f1ca3a738/85744316086.pdf
- https://tort-art.ru/userfiles/file/dodikutafanavodirogik.pdf
- http://triumphtoday.org/wp-content/plugins/formcraft/file-upload/server/content/files/160757e4f6aa7f---ruzusotagovig.pdf
- http://abpaluso.com/upload/file/54265613608.pdf
- https://sharzh-ufa.ru/wp-content/plugins/super-forms/uploads/php/files/89ea31268b459b5bb64cccae13d9e071/xifoze.pdf
- https://greyquotient.com/wp-content/plugins/super-forms/uploads/php/files/65097d5d07fbb547629c376e2916f0ae/fewuzetizapafi.pdf
Embedded domains
- feedproxy.google.com
- rosritual.su
- lecormier-menuiserie.com
- tipresentoio.it
- www.caesarstravel.com
- rffsev.ru
- banning64reunion.com
- maydongy.com
- giaexploring.it
- zemiigori.com
- www.jcca.co.in
- goldenlinejsc.com
- divapharma.com
- cspdental.com
- www.ideaklinik.com
- stroynerud-sm.ru
- diversified-nj.com
- hoovermaids.com
- tort-art.ru
- triumphtoday.org
- abpaluso.com
- sharzh-ufa.ru
- greyquotient.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report