MALICIOUS — 91571591.pdf
MALICIOUS — 91571591.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
960130e1bd13fa058006ac01012945783c8f62db672be7eb9dc978d04c5f65e2 - SHA-1:
87d0a2257512fbda2f888eb956b51af68971899d - MD5:
e6ff7f998388f59b730b31123c07c22d - ssdeep:
1536:1UACQI8+sJNU4dXk4yuw5yAmKKHqnW6pOu2EhsIJoW0yT1LLXEKDA+z1:L/Nvt3yKKSNu2EhsIJkytE4Vp - TLSH:
T10638CFF32197DD4C375A8B0369EA51BC648DE3882132DFA04488B6BCD57C57EAF04A12 - Submitted as: 91571591.pdf
- File type: pdf · Size: 81764 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://discoveryenglish.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607f33e351320---xiraxojukarebudagaxuju.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://laborke.ru/uplcv?utm_term=nbr+iso+10004+pdf, https://worldkelo.com/wp-content/plugins/super-forms/uploads/php/files/1c651f15d34ae3f2e8a851dddb9964bb/47235590042.pdf, https://www.litesourcenc.com/wp-content/plugins/super-forms/uploads/php/files/5348b63092c9f63f5fd35696aed91037/63266219173.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://laborke.ru/uplcv?utm_term=nbr+iso+10004+pdf
- https://worldkelo.com/wp-content/plugins/super-forms/uploads/php/files/1c651f15d34ae3f2e8a851dddb9964bb/47235590042.pdf
- https://www.litesourcenc.com/wp-content/plugins/super-forms/uploads/php/files/5348b63092c9f63f5fd35696aed91037/63266219173.pdf
- http://discoveryenglish.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607f33e351320---xiraxojukarebudagaxuju.pdf
- http://gezond-trakteren.nl/kasteel-doornenburg-img/bestandenfile/61113348372.pdf
- https://alixdemassy.fr/userfiles/file/rimuzafogovode.pdf
- https://susta.vn/userfiles/file/35280284306.pdf
- http://clubesquilacoma.com/uploads/files/xinetumuxerariged.pdf
- http://computerdoki.hu/user/file/85045727496.pdf
- http://vilaportugal.com/wp-content/plugins/formcraft/file-upload/server/content/files/160774f2cd6f73---vexitupamenavetoda.pdf
- http://www.fattyweng.com.sg/wp-content/plugins/formcraft/file-upload/server/content/files/160b4ee517b30c---95740617349.pdf
- http://gz-theoutfit.com/UploadFiles/FCKeditor/20210714051946.pdf
- http://hoondb.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607243476f20b---zugatijuxo.pdf
- https://www.cukoyem.com.tr/wp-content/plugins/super-forms/uploads/php/files/qkqmf74vicdpcroc4getavqrs2/sepoloxitakuv.pdf
- https://sunnyvale.com/wysiwygfiles/file/42805371836.pdf
- https://purmoradiatoriai.lt/images/files/zunisebonejekiguxikoso.pdf
- http://brunsfamilyreunion.org/clients/e/e7/e70b0594429ddd28dfd4dd2f61c76e80/File/guridaw.pdf
- https://www.douggoodkin.com/admin/ckfinder/userfiles/files/81088217347.pdf
- https://thegioidongphuc.net/ckfinder/userfiles/files/nometunetejubepuxuzeb.pdf
- http://villa-carlshorst.de/sites/default/files/file/zosejavagunaliputuwopizep.pdf
- http://aquatherm-graz.at/files/64639119381.pdf
- http://europeanprofservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d6e4fcd5d04---mepubuzakuziwefabipeme.pdf
- http://roycraft.ca/userfiles/file/47876173287.pdf
- https://deewo.de/wp-content/plugins/formcraft/file-upload/server/content/files/16080462a72051---jugagezonotafed.pdf
- https://krimgranit.ru/wp-content/plugins/super-forms/uploads/php/files/80bf69fc8b26d33999a2ecb2fad063cd/nulono.pdf
Embedded domains
- laborke.ru
- worldkelo.com
- www.litesourcenc.com
- discoveryenglish.org
- gezond-trakteren.nl
- alixdemassy.fr
- clubesquilacoma.com
- vilaportugal.com
- www.fattyweng.com.sg
- gz-theoutfit.com
- hoondb.com
- sunnyvale.com
- brunsfamilyreunion.org
- www.douggoodkin.com
- thegioidongphuc.net
- villa-carlshorst.de
- europeanprofservices.com
- roycraft.ca
- deewo.de
- krimgranit.ru
- www.w3.org
- purl.org
- ns.adobe.com
- susta.vn
- computerdoki.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report