MALICIOUS — 70799127422.pdf
MALICIOUS — 70799127422.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
94cf3283b89e76e07b12097ffedfb84a58610d77b8cf27463ec95a9b49a64a3a - SHA-1:
1bd2fd25c6a245992811eacbd4f55c0c7b4d7b89 - MD5:
e381587742171e9e0f2aa9dcab0aa482 - ssdeep:
1536:dlahsvlBqtOIRzcZNPb1aimI9CG1GsXdm4PH91cDYjWypOlLfovYzUWENltrMCR0:WsvlBqrij1aNeCG1GsXdm4PHlclLfkMD - TLSH:
T12439D1F310EBDC9C7E8B5F8395F601BCA08AD6887161EA901584B75C893C9BD7F04961 - Submitted as: 70799127422.pdf
- File type: pdf · Size: 89639 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.tecnotrefg.it/wp-content/plugins/formcraft/file-upload/server/content/files/1608008faa01b2---diguzivoroxoxasesum.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://remontnoedelo.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1607e2214f2fe7---kezanomotibigipu.pdf, https://dakotaterritorydevelopment.com/ckfinder/userfiles/files/11091572794.pdf, http://www.tecnotrefg.it/wp-content/plugins/formcraft/file-upload/server/content/files/1608008faa01b2---diguzivoroxoxasesum.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/GLLx1DTH0VQ/uplcv?utm_term=eye+care+switcher+windows+10+download
- http://remontnoedelo.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1607e2214f2fe7---kezanomotibigipu.pdf
- https://dakotaterritorydevelopment.com/ckfinder/userfiles/files/11091572794.pdf
- http://www.tecnotrefg.it/wp-content/plugins/formcraft/file-upload/server/content/files/1608008faa01b2---diguzivoroxoxasesum.pdf
- http://santiagoporter.com/js/ckfinder/core/connector/php/files/58772009337.pdf
- https://grafitpoint.ru/wp-content/plugins/super-forms/uploads/php/files/02bf80958f33ca1c5d2b73f1ca6c4ad1/fedaj.pdf
- https://www.straightmyteeth.eu/wp-content/plugins/super-forms/uploads/php/files/d31d685b87a2d218f08976e4308ef339/piwofu.pdf
- http://bsbcarpet.com/userfiles/file/14446909378.pdf
- http://goldnumber.info/userfiles/file/nunulokeweradaxikivasax.pdf
- http://proreferee.ru/uploads/ckfinder/files/kinomofepivuxesusiv.pdf
- http://mosvag.ru/img/lib/file/59655463443.pdf
- https://joepromenshealth.com/wp-content/plugins/super-forms/uploads/php/files/ba7bedadf6bf12682dd90c2845f52d1a/47659762749.pdf
- https://bataretak.com/img/files/file/kipeloma.pdf
- http://ptk-astana.kz/wp-content/plugins/super-forms/uploads/php/files/a9a581297a26b7f699e68787b8b06e8b/36248905811.pdf
- http://www.tecnotrefg.it/wp-content/plugins/formcraft/file-upload/server/content/files/16081a9f73f47f---sefuxonovexoko.pdf
- http://naturallabs.de/userfiles/file/zopupabegelopekafer.pdf
- http://perfectthesale.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f01fff2a1e---lusetivolazibefomumujowe.pdf
- https://ivfnna.gr/wp-content/plugins/super-forms/uploads/php/files/4439bb958f8205bf2d7a0b04ef3f0929/ripejafazobikadejediwim.pdf
- https://teenvolunteerdallas.org/wp-content/plugins/super-forms/uploads/php/files/f3e3a8e69a1524f2591cb5707e46ad74/zuxak.pdf
- http://jeugdopdewetenschapsagenda.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160876cc542661---19452177088.pdf
- https://criteriacambio.com.br/wp-content/plugins/super-forms/uploads/php/files/57snqjkkev13jciv1n1r0531up/wazedo.pdf
- https://hacunamatata.ru/wp-content/plugins/super-forms/uploads/php/files/bbdcb2544c86d2691d7581f63f370328/88890571677.pdf
- https://wilsonbarrera.com/inicio/wp-content/plugins/formcraft/file-upload/server/content/files/1606d26b87e9a4---giwafuregulakeze.pdf
- http://sns.hu/_user/file/28844938525.pdf
- https://gamletaarnhuset.no/wp-content/plugins/formcraft/file-upload/server/content/files/16098c1a8c3e8a---6011058095.pdf
Embedded domains
- feedproxy.google.com
- remontnoedelo.ru
- dakotaterritorydevelopment.com
- www.tecnotrefg.it
- santiagoporter.com
- grafitpoint.ru
- www.straightmyteeth.eu
- bsbcarpet.com
- goldnumber.info
- proreferee.ru
- mosvag.ru
- joepromenshealth.com
- bataretak.com
- naturallabs.de
- perfectthesale.com
- teenvolunteerdallas.org
- jeugdopdewetenschapsagenda.nl
- criteriacambio.com.br
- hacunamatata.ru
- wilsonbarrera.com
- gamletaarnhuset.no
- amenagementsoleil.com
- arablift.net
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report