MALICIOUS — 91815319470.pdf
MALICIOUS — 91815319470.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
80bd30da46ffde3e29a85bd3d2ea7566562d10c74a4a01d9950653acf14d0b2e - SHA-1:
d43b47f0e41c70a70bd8c1f40dd19182a6e0ee69 - MD5:
5bce19d9b277575022d8f7c2c780febe - ssdeep:
1536:+vXRk+sanEbOyE5UYO8hTnH1XDSLN8GEXjWFL+CpGrWOpOwrKW0g4J/+J3T4z6Z+:AO+6bOyoUOH1Xkz9GIwrHm+Jj4z7 - TLSH:
T14039CFB32197ED4C728BAF0369BB01A9B04AE78C1172DBA0404CB56CD5BC6BD6F14E51 - Submitted as: 91815319470.pdf
- File type: pdf · Size: 88205 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://umrllc.com/userfiles/files/zaburuwudarux.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://laborke.ru/uplcv?utm_term=petty+cash+voucher+in+excel, https://asiarsolutions.com/userfiles/file/9533581941.pdf, http://umrllc.com/userfiles/files/zaburuwudarux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://laborke.ru/uplcv?utm_term=petty+cash+voucher+in+excel
- https://asiarsolutions.com/userfiles/file/9533581941.pdf
- http://umrllc.com/userfiles/files/zaburuwudarux.pdf
- http://gdbchurch.com/clients/43262/File/zexokuzavixanu.pdf
- http://elenasteele.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607643c7ccfa0---felexujegosaw.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16085c20276990---14347685706.pdf
- https://xn--fct8ml6mwue.tw/uploads/files/bobuxazawixafijakaxamigu.pdf
- https://gamaconsultores.cl/upload/file/1430477313.pdf
- http://systemsbiology.at/uploads/assets/file/zuzamulafaxuxiwelilelovin.pdf
- http://smithmurdock.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608a983c27416---15510998247.pdf
- http://southportrubbish.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608035615f67e---32219980291.pdf
- http://cricalliance.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075d0be389d0---leraw.pdf
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607ca8ebc239d---tigawulejexaxowugebode.pdf
- https://nanyangtextile.com/userfiles/file/vatazovigugalixisifitu.pdf
- https://justbuymeds.net/userfiles/file/54695390884.pdf
- http://trivio.it/userfiles/files/kuvoxubosili.pdf
- https://congchunghadong.com/uploads/files/28310215020.pdf
- https://husvagnsexpo.se/wp-content/plugins/formcraft/file-upload/server/content/files/160c94d74920b3---42274732846.pdf
- https://sirikulsteel.com/wp-content/plugins/formcraft/file-upload/server/content/files/161055f799d2dd---narejoju.pdf
- https://www.swissfillon.com/wp-content/plugins/super-forms/uploads/php/files/d16d05795472a39a9c032570fe99d8bb/xajanapi.pdf
- http://cetinelektrik.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160d52a4beeac5---tavobufetafetax.pdf
- https://condominiobrisasdelnorte.com/userfiles/file/vefumolejo.pdf
- https://myphambambi.com/webroot/img/files/xabavijovoz.pdf
- http://20thhelicoptersquadronreunion.com/clients/71358/File/94341538480.pdf
- https://wfca-czech.cz/temp/userfiles/files/94283278804.pdf
Embedded domains
- laborke.ru
- asiarsolutions.com
- umrllc.com
- gdbchurch.com
- elenasteele.com
- www.1000ena.com
- xn--fct8ml6mwue.tw
- smithmurdock.com
- southportrubbish.com
- cricalliance.com
- kaufdeinauto.de
- nanyangtextile.com
- justbuymeds.net
- trivio.it
- congchunghadong.com
- husvagnsexpo.se
- sirikulsteel.com
- www.swissfillon.com
- condominiobrisasdelnorte.com
- myphambambi.com
- 20thhelicoptersquadronreunion.com
- www.w3.org
- purl.org
- ns.adobe.com
- gamaconsultores.cl
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report