MALICIOUS — 54730741792.pdf
MALICIOUS — 54730741792.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a29b7dfc0a50c68d81cafb4e870dae79bfa14b905847ee5f67ad179527cf22ea - SHA-1:
160c6254e0235d23d9d74d5979cfb0fc0cf69d97 - MD5:
0d5211f37c81af186a3a5d38d04617a0 - ssdeep:
1536:WI8MC2MTm44yZ4M94eeE9ot8prCjm5s6miVWw1u4+hnW8pO7OI2:mMC9C4HAE9oturv5sXiG4+h67c - TLSH:
T1D038BFF361A7EE8C7B578B532DFA11A8A189E7982162EB5440C8337DD5FC27DAE10500 - Submitted as: 54730741792.pdf
- File type: pdf · Size: 82431 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://studioguatta.it/userfiles/files/82710534773.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=neither+nor+used+in+a+sentence, http://studioguatta.it/userfiles/files/82710534773.pdf, https://highlander-inn.com/assets/userfiles/files/sifilubowafijojexiwap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pistant.ru/uplcv?utm_term=neither+nor+used+in+a+sentence
- http://studioguatta.it/userfiles/files/82710534773.pdf
- https://highlander-inn.com/assets/userfiles/files/sifilubowafijojexiwap.pdf
- http://daltan.hu/userfiles/file/58018618450.pdf
- https://linhngapt.vn/upload/files/1755437912.pdf
- https://photojet.net/userfiles/file/julikawazusiboz.pdf
- https://losungversorger.com/product/file/80271868090.pdf
- https://hainutedecopii.eu/ckfinder/userfiles/files/jokinemaxirexezo.pdf
- http://tnslib.tools/userfiles/files/17371786671.pdf
- https://rentcar888.com/uploads/files/202109050505054883.pdf
- http://phuwangnam.com/user_file/file/72528772265.pdf
- http://cnfglgreat.netsociality.com/upload/files/94699664139.pdf
- http://3gr-group.com/ci/userfiles/files/10769879924.pdf
- http://ibshop.gr/uploads/_uploads/files/lexadefajozurevox.pdf
- https://raguvosbaldai.manovonia.lt/images/files/buxijuze.pdf
- http://apothepharma.com/upload/files/68977675426.pdf
- https://tepihtrava.rs/files/89743091043.pdf
- http://midesignvn.com/uploads/files/39504178912.pdf
- https://giltmorestukko.hu/ckfinder/userfiles/files/63145937248.pdf
- http://rideabikenews.com/user_img/files/vafuxukuravikifugezalom.pdf
- http://koreadramatour.com/FileData/ckfinder/files/20210911_5EF356F70029C551.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- pistant.ru
- studioguatta.it
- highlander-inn.com
- photojet.net
- losungversorger.com
- hainutedecopii.eu
- rentcar888.com
- phuwangnam.com
- cnfglgreat.netsociality.com
- 3gr-group.com
- apothepharma.com
- midesignvn.com
- rideabikenews.com
- koreadramatour.com
- www.w3.org
- purl.org
- ns.adobe.com
- daltan.hu
- linhngapt.vn
- tnslib.tools
- ibshop.gr
- raguvosbaldai.manovonia.lt
- tepihtrava.rs
- giltmorestukko.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report