MALICIOUS — 44960709174.pdf
MALICIOUS — 44960709174.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a27d391dff10ed6c199d2b6b4192ae52e1a0e1069710cb29a730bf84cc3a0840 - SHA-1:
2544f5a594fc410abb1c0cc4ad41e17dc4dc5ea6 - MD5:
033c4829c04b0756ebcfcda94f23cc37 - ssdeep:
1536:h+b4iibpyMmwYZOBoQ+P56RBwGWS251r0WRc4tWnSJL4hALvoE2kHWUWcpOmxZd:4zib/YRtIRmGter0We4Kk1voE2kHW/mB - TLSH:
T1C339C0F72057DC0CAA8BCB4369AF15A8B08AD7887272E7500684B57C997C9BD3F10E51 - Submitted as: 44960709174.pdf
- File type: pdf · Size: 88143 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.sanier.pl/wp-content/plugins/super-forms/uploads/php/files/2hj5pqfk560tnbqrn5qdht5ca5/fugedi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://france-ex.com/images/blog//file/jibegofiw.pdf, https://wfbulgaria.com/uploads/wysiwyg/files/15114759898.pdf, http://www.zopfitravel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c7334b3e90a---59500043165.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/BkSY9tpko7c/uplcv?utm_term=hamilton+beach+flexbrew+instruction+manual
- http://france-ex.com/images/blog//file/jibegofiw.pdf
- https://wfbulgaria.com/uploads/wysiwyg/files/15114759898.pdf
- http://www.zopfitravel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c7334b3e90a---59500043165.pdf
- http://amwordpress.org/wp-content/plugins/formcraft/file-upload/server/content/files/16076241bda01e---fokepiwilowuzo.pdf
- http://alnoorcity.com/userfiles/file/1440124349.pdf
- https://www.sanier.pl/wp-content/plugins/super-forms/uploads/php/files/2hj5pqfk560tnbqrn5qdht5ca5/fugedi.pdf
- http://stensoproject.com/userfiles/files/294289421.pdf
- https://nobleanimalsanctuary.org/wp-content/plugins/super-forms/uploads/php/files/tmp/74702671925.pdf
- https://loan-financial.com/wp-content/plugins/super-forms/uploads/php/files/067fc777f23ed0a8dc2b5f1bb8e30b79/ruzoxetu.pdf
- http://legendtec-eg.com/wp-content/plugins/super-forms/uploads/php/files/dts55e7hjgjfpthtu19dtater2/36531719362.pdf
- https://swotin.com/wp-content/plugins/formcraft/file-upload/server/content/files/16081c222dac94---sutalatuzegusejodowimow.pdf
- http://bahattinburyan.com/userfiles/file/38950780727.pdf
- https://medtek.vn/storage/file/60162191580.pdf
- https://thegioidongphuc.net/ckfinder/userfiles/files/81177953454.pdf
- https://realestateconnect.pro/wp-content/plugins/super-forms/uploads/php/files/ru5qib86r1echkq1f45toi28a7/93878025019.pdf
- https://www.demetagras.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071426eb8f02---34743507142.pdf
- http://www.rpv-drachten.nl/files/file/12332420990.pdf
- https://triptoboloyfoundation.org/editorsfiles/files/roxoribajuwogunu.pdf
- https://www.tctnanotech.com/wp-content/plugins/super-forms/uploads/php/files/2f37bf5ce9a0700ae870bd30bbc58ddb/vinumubetejaxomopirowu.pdf
- http://dekogard.net/deko/veri/_files/wusidufefi.pdf
- https://brusroom.com/wp-content/plugins/super-forms/uploads/php/files/b117ffc9e5396b7713e60034a3c573f4/tapebavarezeme.pdf
- http://florylaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/75764140528.pdf
- http://skup-laptopow.com/wp-content/plugins/formcraft/file-upload/server/content/files/16094d4c26960c---27263363341.pdf
- https://spectrumohio.com/wp-content/plugins/super-forms/uploads/php/files/a559f0204c9960cdaedb9de6ca9d14fe/xejetivuzulebe.pdf
Embedded domains
- feedproxy.google.com
- france-ex.com
- wfbulgaria.com
- www.zopfitravel.com
- amwordpress.org
- alnoorcity.com
- www.sanier.pl
- stensoproject.com
- nobleanimalsanctuary.org
- loan-financial.com
- legendtec-eg.com
- swotin.com
- bahattinburyan.com
- thegioidongphuc.net
- realestateconnect.pro
- www.demetagras.com
- www.rpv-drachten.nl
- triptoboloyfoundation.org
- www.tctnanotech.com
- dekogard.net
- brusroom.com
- florylaw.com
- skup-laptopow.com
- spectrumohio.com
- tsafar.ir
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report