MALICIOUS — 98566210301.pdf
MALICIOUS — 98566210301.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a29b2d5e127955c74bfb95085569b8bdf9991b5b5f116797a50c77f9bc0c176c - SHA-1:
f09f530b6b5f18eaa0d2987b8c9c0a588551394c - MD5:
0c1a5b4765dfa25e060b92413c12a3b5 - ssdeep:
1536:8t9ekkUuIbqST8gfacrnLd8TVWCpOViPdQJJWmULWmwLAaG:3xUuIT8OaYnxViPdQJYLWh0 - TLSH:
T1ED38C0F3108BDE8D778BDB4769EA01685486D7DC2127DFA0408C7E6C987C2BDAE01A51 - Submitted as: 98566210301.pdf
- File type: pdf · Size: 80791 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ustunongel.com/image/files/nujibimi.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://xn--9p4b29dncp2cc6y.net/upload/fckeditor/file/pulunaw.pdf, http://dalnoboy.net/data/filestorage/upload/files/61861924441.pdf, https://bearings.vn/images/ckeditor/files/40858374667.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/S30rS-6n6vg/uplcv?utm_term=uk+used+iphone+8+price+in+nigeria+slot
- http://xn--9p4b29dncp2cc6y.net/upload/fckeditor/file/pulunaw.pdf
- http://dalnoboy.net/data/filestorage/upload/files/61861924441.pdf
- https://bearings.vn/images/ckeditor/files/40858374667.pdf
- https://bompentax.com/quangbasanpham/app/webroot/upload/image/files/larutedusejifuf.pdf
- https://clicksnepal.grnca.org/img/files/files/detifupuvenix.pdf
- http://lejonhund.com/upload/17344185892.pdf
- http://kasaitogo.com/uploads/files/12583804551.pdf
- http://kondicionery-krasnogorsk.ru/upload_picture/file/51752585502.pdf
- http://ustunongel.com/image/files/nujibimi.pdf
- http://syuncyoku.jp/upload/file/nunivotifitowafa.pdf
- http://www.hkimm.hk/_bin/ckfinder/userfiles/files/segob.pdf
- http://www.mediacomriccione.it/wp-content/plugins/formcraft/file-upload/server/content/files/161331614594c4---vexibed.pdf
- https://kitchensofdiablo.com/upload/file/28997639153.pdf
- http://casinodanmarkjackpot.dk/userfiles/file/63651223240.pdf
- https://a-guskov.ru/uploads/files/bofosiganisejeno.pdf
- http://zoltysnieg.pl/pliki_wyswig/files/92295332568.pdf
- https://www.ccps.mx/wp-content/plugins/super-forms/uploads/php/files/2a90727692824eeecc281c06589915cc/60285688148.pdf
- https://www.enviedecrire.com/wp-content/plugins/formcraft/file-upload/server/content/files/16137b59872568---rogopasiwam.pdf
- http://bukvoznaika.ru/ckfinder/userfiles/files/75263969106.pdf
- http://sgo-bage.com/public/files/files/55612913739.pdf
- http://lednotice.com/userData/board/file/39341776696.pdf
- http://www.ondebiz.com/userfiles/file/giguwuvodigerule.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- xn--9p4b29dncp2cc6y.net
- dalnoboy.net
- bompentax.com
- clicksnepal.grnca.org
- lejonhund.com
- kasaitogo.com
- kondicionery-krasnogorsk.ru
- ustunongel.com
- syuncyoku.jp
- www.hkimm.hk
- www.mediacomriccione.it
- kitchensofdiablo.com
- a-guskov.ru
- zoltysnieg.pl
- www.ccps.mx
- www.enviedecrire.com
- bukvoznaika.ru
- sgo-bage.com
- lednotice.com
- www.ondebiz.com
- www.w3.org
- purl.org
- ns.adobe.com
- bearings.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report