MALICIOUS — 96611671034.pdf
MALICIOUS — 96611671034.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
7f3edd8941f0343450586bfb4478a3c04d77845492f02ce22c3247c6d2e08d9f - SHA-1:
b72368109067c12436e6d87d7daa1f6dc9e6c6cd - MD5:
d10a37fc714544fd514a629dbeda5962 - ssdeep:
1536:9yvMfWWSsETRHxLIuoYDt8Yr0QW1XNZj1isycsdWApO6L4F:4UfWWSfUuoYD50hXj1wU6S - TLSH:
T14637BFF361CBED8CB35F9F53A7AA056DA182D3481037DA5080887A7CD8BC57EAE14641 - Submitted as: 96611671034.pdf
- File type: pdf · Size: 71935 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://cructi.ru/uplcv?utm_term=nursing+and+midwifery+procedure+manual+pdf+download, http://hoclaixebinhthuan.com/upload/contentFile/file/tezosazasiruzedel.pdf, https://soroptimist.be/oldsite/intranet/ckeditor/ckfinder/userfiles/images/files/lakakuvorowurisenaj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cructi.ru/uplcv?utm_term=nursing+and+midwifery+procedure+manual+pdf+download
- http://hoclaixebinhthuan.com/upload/contentFile/file/tezosazasiruzedel.pdf
- https://soroptimist.be/oldsite/intranet/ckeditor/ckfinder/userfiles/images/files/lakakuvorowurisenaj.pdf
- http://clearlakesd.org/wp-content/plugins/formcraft/file-upload/server/content/files/16094153bddcc2---jogalevabuza.pdf
- http://lawrence-spruill.com/clients/42275/File/xeditigirewapo.pdf
- https://ural-aiti.ru/admin/ckfinder/userfiles/files/59548768902.pdf
- http://kino-profi.com/wp-content/plugins/super-forms/uploads/php/files/78778ec2505d2dfa02ffa1c1d742fb33/38912300040.pdf
- http://bitite.lv/media/txt/122/file/jakelojarem.pdf
- https://afd.me.uk/wp-content/plugins/super-forms/uploads/php/files/2eta9hn7fqmgmppptniea1tbud/tazobusivolexalusojolefe.pdf
- http://www.ncstarim.com.tr/wp-content/plugins/super-forms/uploads/php/files/odkjj4pki2v385p1357u94li64/beraxawexiwogajero.pdf
- http://skuplaptop.pl/wp-content/plugins/formcraft/file-upload/server/content/files/16076f55993ea1---tetafekutepowezaxod.pdf
- http://e-pisanie-prac.pl/famprojekt_z_serwera/images/file/7623276532.pdf
- https://mosallaesf.ir/uploads/ck/files/volurimojidet.pdf
- http://beloit1962.com/clients/8/83/8368a4f838dea3176655029ae9e337da/File/88194287130.pdf
- https://gbeequestriansurfaces.com/wp-content/plugins/super-forms/uploads/php/files/21rfssqlkhqftmu6f5r3ojhqhn/5727861481.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16093a867a519f---37831038153.pdf
- http://yonseri.org/userfiles/files/zupula.pdf
- https://boyanbolyarski.com/userfiles/file/nujugog.pdf
- https://intervalhousehamilton.org/ckfinder/userfiles/files/zufuvinubig.pdf
- https://fedico.ca/upload/editor/file/74888651474.pdf
- https://www.bbmnetlicitacoes.com.br/cms/ckfinder/upload/files/85039732690.pdf
- http://wsm.hk/images/uploadfiles/file/81818862448.pdf
- https://www.makathastaliklari.net/wp-content/plugins/formcraft/file-upload/server/content/files/16078665b26d20---tadazatajevimininuwizuz.pdf
- http://bakoca.hu/files/file/musetonox.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cructi.ru
- hoclaixebinhthuan.com
- soroptimist.be
- clearlakesd.org
- lawrence-spruill.com
- ural-aiti.ru
- kino-profi.com
- afd.me.uk
- skuplaptop.pl
- e-pisanie-prac.pl
- mosallaesf.ir
- beloit1962.com
- gbeequestriansurfaces.com
- www.1000ena.com
- yonseri.org
- boyanbolyarski.com
- intervalhousehamilton.org
- fedico.ca
- www.bbmnetlicitacoes.com.br
- wsm.hk
- www.makathastaliklari.net
- www.w3.org
- purl.org
- ns.adobe.com
- bitite.lv
File paths
- H:\Z2ZG
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report