MALICIOUS — 38174549850.pdf
MALICIOUS — 38174549850.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
95f23864b7c4c9f78de41e920630af36966da52e0126e63405435dd4c6290a04 - SHA-1:
13601169ae3e456cbb8196275610790406fd0d9f - MD5:
4c4a0ae99061bade6492d2aa2cc77d57 - ssdeep:
1536:tcpNoPTGfReRhzfj6ieeYeXkAh+WCpOViIWQpfILU085LMG:mpNKTAReRBjQe0AhTVigBB0cZ - TLSH:
T19637BFF351AFCD5C668ACF076DEA11AC5046E68C2151EEA1A088B63CD47C6FCBF40661 - Submitted as: 38174549850.pdf
- File type: pdf · Size: 73819 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://lobi.md/userfiles/file/83843439084.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://crewmak.ru/uplcv?utm_term=strength+training+program+for+weight+loss+pdf, https://cryptoshift.be/anaeter_capital/siteadmin/userfiles/files/vuniziwerubev.pdf, https://valleyrentals.com/userfiles/file/78415371864.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crewmak.ru/uplcv?utm_term=strength+training+program+for+weight+loss+pdf
- https://cryptoshift.be/anaeter_capital/siteadmin/userfiles/files/vuniziwerubev.pdf
- https://valleyrentals.com/userfiles/file/78415371864.pdf
- http://rqconsultores.com/userfiles/file/kuwimojedinupuzepotufen.pdf
- https://mcdelandes.ca/uploads/file/20142333411.pdf
- http://tabouligrill.com/ckfinder/userfiles/files/63859014700.pdf
- http://swapnakoodu.com/fck_uploads/file/34994563469.pdf
- https://e-midas.ro/files/file/mudapituluvumewefelureju.pdf
- http://lobi.md/userfiles/file/83843439084.pdf
- http://mwcapital.net/ckfinder/userfiles/files/sibudujadu.pdf
- http://www.serge-valentin.net/ckfinder/userfiles/files/nupegopabezulogarozokogi.pdf
- http://supair-lux.hu/ckfinder/userfiles/files/numigufumugilotefepi.pdf
- https://cqhuaan.myhost360.cn/upload/files/09-06-20-27-14-55.pdf
- http://retailpark.bg/uploads/wysiwyg/files/50226514522.pdf
- https://sofupingame.com/calisma2/files/uploads/90444361232.pdf
- http://thegoshow.net/userfiles/file/69554058077.pdf
- http://lt101shop.com/userfiles/files/68368107168.pdf
- http://lepal.sk/ckfinder/userfiles/files/67315449856.pdf
- https://olivier-daulte.com/ckfinder/userfiles/files/46150890274.pdf
- http://sapaelitehotel.com/webroot/img/files/xanotodokakikemomev.pdf
- http://investgeorgia.ge/userfiles/file/foderunem.pdf
- http://www.hausbaumesse.at/ckfinder/userfiles/files/zemapububetujifetapejid.pdf
- http://giovanniseneca.eu/userfiles/files/57728626592.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- crewmak.ru
- cryptoshift.be
- valleyrentals.com
- rqconsultores.com
- mcdelandes.ca
- tabouligrill.com
- swapnakoodu.com
- mwcapital.net
- www.serge-valentin.net
- cqhuaan.myhost360.cn
- sofupingame.com
- thegoshow.net
- lt101shop.com
- olivier-daulte.com
- sapaelitehotel.com
- giovanniseneca.eu
- www.w3.org
- purl.org
- ns.adobe.com
- e-midas.ro
- lobi.md
- supair-lux.hu
- retailpark.bg
- lepal.sk
- investgeorgia.ge
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report