MALICIOUS — 20210913204544.pdf
MALICIOUS — 20210913204544.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a49ca897f7212c742767209164640e0b5e188ce8aa0e8348525dfe5ac10b802e - SHA-1:
f2bdda9b1f697b8518bb34d14308eb060fae6199 - MD5:
4c821ae6c21903a70b11e6ce359e082f - ssdeep:
1536:odiblvoT4YP8NvUH5hMI0tubKBOKzGMjARvvpN5uTbXIWmGTtBw2uWwpOSKRd:Iiblk4W8NO5mtx0mGoAFvmXnT7w2xSW - TLSH:
T12839C0F3219BDC8C7A5A4F431AB61168A487E3D472B7FA9000887A6C957C7BE7F14910 - Submitted as: 20210913204544.pdf
- File type: pdf · Size: 87632 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://nepalipublisher.com/ckfinder/userfiles/files/63471737567.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://garglob.ru/uplcv?utm_term=android+use+phone+as+hotspot, https://soudurelausiere.ca/upload/editor/file/13140851248.pdf, https://nepalipublisher.com/ckfinder/userfiles/files/63471737567.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://garglob.ru/uplcv?utm_term=android+use+phone+as+hotspot
- https://soudurelausiere.ca/upload/editor/file/13140851248.pdf
- https://nepalipublisher.com/ckfinder/userfiles/files/63471737567.pdf
- https://www.agencesramos.com/ckfinder/userfiles/files/viwevesemolal.pdf
- http://japanbizkorea.com/userData/ebizro_board/file/zoratoxavo.pdf
- http://sk-massimo.com/js/upload/files/suwenunevabesep.pdf
- https://ostrichpharmaceuticals.com/userfiles/file/sivadazatix.pdf
- http://hpcad.pl/Upload/file/79568872484.pdf
- https://dancleland.com/img/upload/file/mifazamibakusog.pdf
- http://kythuatviet.vn/uploads/userfiles/file/xisiziwulatebi.pdf
- http://kingbikeonline.com/images/upload/File/57358801504.pdf
- http://businessplan-capalpha.eu/mbp/upload/images/images/upload/ckfinder/faribeg.pdf
- https://ls-machinery.com/uploadpic/files/202109121220471003.pdf
- http://quimicahj.com/admin/userfiles/userfiles/file/ponutoxofukamarazodumam.pdf
- http://ovstav.cz/app/webroot/files/files/lodotilub.pdf
- http://finara-v.com/file_media/file_image/file/98098780450.pdf
- http://smartcookieacademy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613c9cb14fab3---lepadafis.pdf
- https://auto826.com/uploads/files/garajotufusemupadodasok.pdf
- https://heks-tech.com/app/webroot/userfiles/files/79055664076.pdf
- http://karlsbach.de/userfiles/files/fugirove.pdf
- http://elistaprezentow.pl/userfiles/file/lopunuxom.pdf
- http://www.biosafety.biz/ckfinder/userfiles/files/linovigofivi.pdf
- https://doanhnghiepvietnam.org/img_duhoc/files/58730289515.pdf
- http://saconsultancy.com/userfiles/file/wusobojorilexeg.pdf
- https://powermailer.in/userfiles/file/bujaxapuxumexuwozuno.pdf
Embedded domains
- garglob.ru
- soudurelausiere.ca
- nepalipublisher.com
- www.agencesramos.com
- japanbizkorea.com
- sk-massimo.com
- ostrichpharmaceuticals.com
- hpcad.pl
- dancleland.com
- kingbikeonline.com
- businessplan-capalpha.eu
- ls-machinery.com
- quimicahj.com
- finara-v.com
- smartcookieacademy.com
- auto826.com
- heks-tech.com
- karlsbach.de
- elistaprezentow.pl
- www.biosafety.biz
- doanhnghiepvietnam.org
- saconsultancy.com
- powermailer.in
- fsreloading.com
- steakpluspizza.us
File paths
- Y:\X
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report