MALICIOUS — 91efc0e0cee52dcbda58530a3952df687b8ef1c62a0e9f5fb0179c4592adc2be
MALICIOUS — 91efc0e0cee52dcbda58530a3952df687b8ef1c62a0e9f5fb0179c4592adc2be is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
91efc0e0cee52dcbda58530a3952df687b8ef1c62a0e9f5fb0179c4592adc2be - SHA-1:
7179e6479a9387c999fe11603b87ad7fbfd4dc05 - MD5:
8dd454fa4c29e69cd5c0c36cda18be6e - ssdeep:
1536:lYBNri+lRMHobEqRMw/Iq76okD0fxW6pO9:C32kMIbEe76oFS9 - TLSH:
T14834CFF310A7CD4CBF5FAB83EE6A519DA44AE358D152F550858C622CD5ECC7D2E20902 - Submitted as: 91efc0e0cee52dcbda58530a3952df687b8ef1c62a0e9f5fb0179c4592adc2be
- File type: pdf · Size: 55953 bytes
- Verdict: malicious (92/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://chcial.ru/uplcv?utm_term=android+camera+app+like+iphone, http://ctmmaximoravenna.com/ckfinder/userfiles/files/rozuxizarajogefitefafo.pdf, https://karaari.leaddeehub.com/userfiles/files/dofemokenosuzijeru.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://chcial.ru/uplcv?utm_term=android+camera+app+like+iphone
- http://ctmmaximoravenna.com/ckfinder/userfiles/files/rozuxizarajogefitefafo.pdf
- https://karaari.leaddeehub.com/userfiles/files/dofemokenosuzijeru.pdf
- http://pelejas.com/IMAGENS/CKFINDER/files/68594343630.pdf
- https://tennis-samara.ru/img/file/nipofimipise.pdf
- http://ip-malkov.ru/uploads/files/totenopad.pdf
- https://100tmt.com/uploadimage/files/20210924154428.pdf
- http://nsdadventist.org/FCKData/file/vureta.pdf
- https://chasehr.in/userfiles/file/28545492774.pdf
- http://telekommarketing.com/firme_data/files/44059798504.pdf
- http://speckrepej.com/upload/file/83176283109.pdf
- http://sedaciesupravy.sk/media/file/laponosoxanakujitapim.pdf
- http://www.musicmaestrodiscos.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1613f32b5bfaf8---47969148957.pdf
- http://aweibel.com/Photo/file/30648235038.pdf
- https://thic.net/plugin/ce1/ckfinder/userfiles/files/80005501942.pdf
- http://aldobini.it/userfiles/files/94561944203.pdf
- http://inbiosa.eu/static/cfiles/files/69922136331.pdf
- https://healthmatters.me/userfiles/file/vibatajotebizipireka.pdf
- http://fedime.org/imagenes/30937657971.pdf
- https://championsforchildren.org/wp-content/plugins/super-forms/uploads/php/files/fdb4fc316ef93027c92c7a4eb3504b68/28913146472.pdf
- http://chaputlawoffice.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/17935997490.pdf
- http://vizit-k.net/uploads/editor/files/13477331085.pdf
- https://www.advids.io/wp-content/plugins/formcraft/file-upload/server/content/files/16141655436b6c---4972738207.pdf
- http://www.thediethub.in/wp-content/plugins/formcraft/file-upload/server/content/files/1613ddef09d66d---divumodetixelaxudul.pdf
Embedded domains
- chcial.ru
- ctmmaximoravenna.com
- karaari.leaddeehub.com
- pelejas.com
- tennis-samara.ru
- ip-malkov.ru
- 100tmt.com
- nsdadventist.org
- chasehr.in
- telekommarketing.com
- speckrepej.com
- www.musicmaestrodiscos.co.uk
- aweibel.com
- thic.net
- aldobini.it
- inbiosa.eu
- healthmatters.me
- fedime.org
- championsforchildren.org
- chaputlawoffice.com
- vizit-k.net
- www.advids.io
- www.thediethub.in
- sedaciesupravy.sk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report