MALICIOUS — 65694601345.pdf
MALICIOUS — 65694601345.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
759cd87434982d8989a10833c022712657dd4e0cf5695581035d011f47e14daa - SHA-1:
a1375b93691de345e2845dcab6b3461f5223cf0e - MD5:
67635d929e24f8c1ceb889f79d36a487 - ssdeep:
1536:kInBBh/gGNah2qjp1AuZzr7G33VjZUJ17+fWOpOaZo86kCXGWjNZWNUx+XfMk7k6:FBBh/E2q1Zzr6nVjZUJV+waZsLzE1k6 - TLSH:
T13738C0F761D7DECCB68B9B476ADA0058B056E3883162EF6015C4B72CE47C1BDBA00651 - Submitted as: 65694601345.pdf
- File type: pdf · Size: 79743 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://52fantasies.com/home/holly/public_html/ckfinder/userfiles/files/parojudaro.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://chcial.ru/uplcv?utm_term=human+inheritance+review+and+reinforce+answer+key, https://ka-base.no/images_content/file/3400288062.pdf, https://groupunsur3.com/contents/files/febaxufi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://chcial.ru/uplcv?utm_term=human+inheritance+review+and+reinforce+answer+key
- https://ka-base.no/images_content/file/3400288062.pdf
- https://groupunsur3.com/contents/files/febaxufi.pdf
- https://mandarinusa.com/userfiles/file/1633161580.pdf
- https://briljant-maleri.se/UserFiles/files/pebozivomowov.pdf
- http://isotope3.pm-ural.com/uploads/files/jedijevokefape.pdf
- http://abwcockeysville.com/uploads/files/radoluvaloxerowivevano.pdf
- https://bnbtravels.com/ckfinder/userfiles/files/fepopokifaz.pdf
- https://52fantasies.com/home/holly/public_html/ckfinder/userfiles/files/parojudaro.pdf
- http://gemcom.org/userfiles/file/kawubanetugazipumireko.pdf
- https://guitarenko.fr/img/files/31587710120.pdf
- http://robwalker.net/fckupload/file/telorokoxagigixif.pdf
- https://lingchuanfloor.com/app/webroot/userfiles/files/84727063292.pdf
- http://realtor-madrid.com/uploades/fckeditorfile/48847152931.pdf
- http://nemalipics.com/75151545217.pdf
- http://targhevaticane.it/userfiles/files/takixuwolewakujerufifikux.pdf
- https://www.histoiresdegroupes.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613e347cb4193---61394292759.pdf
- https://exclusivelimoservice.com/ckfinder/userfiles/files/seganujenip.pdf
- http://dealershop.es/userfiles/file/52656392876.pdf
- https://myparrotfood.com/user_files/files/30440281356.pdf
- http://architettotamborra.eu/userfiles/files/pejex.pdf
- http://spl-designs.com/ckfinder/userfiles/files/lugevod.pdf
- http://srcchaika.ru/files/uploads/files/jerugero.pdf
- http://mevlanaasm.com/resimler/files/4277146819.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- chcial.ru
- ka-base.no
- groupunsur3.com
- mandarinusa.com
- briljant-maleri.se
- isotope3.pm-ural.com
- abwcockeysville.com
- bnbtravels.com
- 52fantasies.com
- gemcom.org
- guitarenko.fr
- robwalker.net
- lingchuanfloor.com
- realtor-madrid.com
- nemalipics.com
- targhevaticane.it
- www.histoiresdegroupes.com
- exclusivelimoservice.com
- dealershop.es
- myparrotfood.com
- architettotamborra.eu
- spl-designs.com
- srcchaika.ru
- mevlanaasm.com
- p.br
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report