MALICIOUS — 17278289634.pdf
MALICIOUS — 17278289634.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
88a1d729afe1935508bd80e58cbb81892983e195544068bb5fe6024560096912 - SHA-1:
b6059bf34015a02a79264420a2a626cd7b5a7b0e - MD5:
fb2a7232d66f729cbf0160ac3516a9c6 - ssdeep:
1536:Cjq94B+c38YhRqZbyjKby/s7Y0XIkiIBP4qy4x+uEJyBM0u3n5W6pOu26WrhHFy0:t4TBqZGKb8QTViIBP4kwuEJaM0uKu23f - TLSH:
T1DE39C0F3319BDE6CB71ACB4379A621699447E3C82072979010C876AC9ABC8BD7F10D51 - Submitted as: 17278289634.pdf
- File type: pdf · Size: 86628 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://wtmasonry.com/ckfinder/userfiles/files/suwovug.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=voice+changer+in+ff, https://cissud.com/uploads/ck_editor/files/87257657516.pdf, http://cableesmaltado.com/d/files/kotudekoxawimaxorif.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=voice+changer+in+ff
- https://cissud.com/uploads/ck_editor/files/87257657516.pdf
- http://cableesmaltado.com/d/files/kotudekoxawimaxorif.pdf
- https://wtmasonry.com/ckfinder/userfiles/files/suwovug.pdf
- http://haustechnik-hagenauer.at/befuwojugivo.pdf
- http://debnine.net/UserFiles/File/wekud.pdf
- http://bellezaeimagen.com.mx/wp-content/plugins/formcraft/file-upload/server/content/files/16141facf1abe4---95858251110.pdf
- https://serka.com/serka/upload/files/76543610690.pdf
- http://tlxzkj.com/uploads/file/010517233633.pdf
- http://hide-bo.com/img/tmp/file/2780845385.pdf
- https://quimicasorocolor.com.ve/ckfinder/userfiles/files/73028013073.pdf
- http://sake2metustin.com/uploads/files/83973191083.pdf
- https://maharajganjtimes.com/assets/ckfinder/core/connector/php/uploads/files/48146819449.pdf
- http://stuarteisbrucklaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/25549863267.pdf
- https://inverpalmas.com/aym_image/files/57451415264.pdf
- https://wilsonbarrera.com/inicio/wp-content/plugins/formcraft/file-upload/server/content/files/1613860a920e00---17152819996.pdf
- https://kapefashion.com/files/files/68447362854.pdf
- https://bulgariapools.com/contents/files/6255982299.pdf
- http://jyjwqj.com/uploadfile/file///2021091805205882.pdf
- http://trainternational.in/wp-content/plugins/formcraft/file-upload/server/content/files/16139da8b64d01---fowipa.pdf
- http://vinhthuanvietnam.com/upload/files/79535872615.pdf
- http://101-games.ru/images/uploads/files/25044534652.pdf
- http://vagtteam.com/userfiles/Files/wuwexarizonugoj.pdf
- https://247christianity.org/fckeditor/userfiles/file/nuwex1631883759.pdf
- https://ltes.tw-goods.com/UserFiles/files/xupekumisak.pdf
Embedded domains
- crysiq.ru
- cissud.com
- cableesmaltado.com
- wtmasonry.com
- debnine.net
- bellezaeimagen.com.mx
- serka.com
- tlxzkj.com
- hide-bo.com
- sake2metustin.com
- maharajganjtimes.com
- stuarteisbrucklaw.com
- inverpalmas.com
- wilsonbarrera.com
- kapefashion.com
- bulgariapools.com
- jyjwqj.com
- trainternational.in
- vinhthuanvietnam.com
- 101-games.ru
- vagtteam.com
- 247christianity.org
- ltes.tw-goods.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report