MALICIOUS — 42540583568.pdf
MALICIOUS — 42540583568.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
96927f1e96e23426f087e0e88e4ce3106d686e69bf5778c97f23256e3301caf3 - SHA-1:
3dd12a1d5671e5126ca750b9d99013abdb0a508e - MD5:
55af41e31dbae6b52efa3ae92f789f63 - ssdeep:
1536:yr9z+GGs7PrJbwvBVMVxUwJ7xTm/tCCOPjpW6pOu26Wfq5ZZYKq6Ztk2LSxek:m7ZbwvBVMVxvJ79mUrbKu2RKw6Ztfi - TLSH:
T12A38C0F311ABDD4D764B5B1378B61068A44AEBCCA136EB6045C8B71CD47C5BEBE00A12 - Submitted as: 42540583568.pdf
- File type: pdf · Size: 81270 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://jjc-dev.com/userfiles/file/81039566916.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://jjc-dev.com/userfiles/file/81039566916.pdf, http://tomgiongvip.com/uploads/files/file/64899594164.pdf, https://www.prieur-equipement.com/ckfinder/userfiles/files/79992740302.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/3vuEKuznOb8/uplcv?utm_term=convert+ppt+to+video+android
- http://jjc-dev.com/userfiles/file/81039566916.pdf
- http://tomgiongvip.com/uploads/files/file/64899594164.pdf
- https://www.prieur-equipement.com/ckfinder/userfiles/files/79992740302.pdf
- http://remproekt-m.ru/admin/ckfinder/userfiles/files/68624058905.pdf
- https://macleanpinesdrivingschool.com.au/wp-content/plugins/super-forms/uploads/php/files/dc35b5426298c47a78222b577f5ea822/suzuxuvonoborafukexibed.pdf
- http://aqbnb.com/uploadfile/file/nodenipasezosipalokelewe.pdf
- http://greathorserider.com/ckfinder/userfiles/files/tisinisewixomaramitusig.pdf
- https://cradlegold.com/wp-content/plugins/super-forms/uploads/php/files/m1onivisf5oqhko4ilb1rgp4kv/75494120082.pdf
- http://sunway.me/ROOT_PATHuploads/file/060550165431.pdf
- http://mimarathi.live/assets/ckfinder/core/connector/php/uploads/files/pasutufapuguxe.pdf
- http://beauty214.com/uploads/files/202109050806111047.pdf
- https://santa.sg/images/users/00000000/files/18385017637.pdf
- https://ms1oke.com/contents/files/80072835223.pdf
- https://lawina-radom.pl/files/file/73567075335.pdf
- http://av72-reklama.ru/userfiles/file/16304551977feac573fdaafa6dcede.pdf
- https://www.advids.io/wp-content/plugins/formcraft/file-upload/server/content/files/1613102bbcbffd---13893751555.pdf
- http://profisystem.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1612f130ff092a---jitopudonoxawi.pdf
- https://ketgate.eu/wp-content/plugins/super-forms/uploads/php/files/f9e9c6ab4477f551efef2ec2b2d38097/51009452149.pdf
- http://ff-engineering.com/userfiles/files/59780504332.pdf
- http://meble-tk.pl/userfiles/file/petasutodufewapuzi.pdf
- https://badanie-wody.pl/galeria/file/65025113335.pdf
- https://satesayap.com/contents/files/rawer.pdf
- http://1544-7419.net/upload/fckeditor/file/porigon.pdf
- https://shevian.com/images/file/mererobukenotux.pdf
Embedded domains
- feedproxy.google.com
- jjc-dev.com
- tomgiongvip.com
- www.prieur-equipement.com
- remproekt-m.ru
- macleanpinesdrivingschool.com.au
- aqbnb.com
- greathorserider.com
- cradlegold.com
- sunway.me
- mimarathi.live
- beauty214.com
- santa.sg
- ms1oke.com
- lawina-radom.pl
- av72-reklama.ru
- www.advids.io
- ketgate.eu
- ff-engineering.com
- meble-tk.pl
- badanie-wody.pl
- satesayap.com
- 1544-7419.net
- shevian.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report