MALICIOUS — 44038353999.pdf
MALICIOUS — 44038353999.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
a53bce4a8401782fc26223242da417a85486b355c7537741cca986336d953931 - SHA-1:
d0d8cbf2a5aca4adfb8b697306f42289ffea9c1f - MD5:
7fb08023aec93ff84e9381588a16f4da - ssdeep:
1536:NWimbTvgU/96DJtBx/TYeCmLL4sN0pmYPWapOtQHWrLdsyAyaiPkTz4:HmYU/Q9vqeCm7NQmYgtQ8myApgkY - TLSH:
T1A939BFF361DBEC0CBF9F9B0369AA1169A08EE74C4531EB505488762C84BC5BD7F12521 - Submitted as: 44038353999.pdf
- File type: pdf · Size: 86668 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=disabled+persons+act+zimbabwe+pdf, https://lsp.od.ua/wp-content/plugins/super-forms/uploads/php/files/tdbbe4kroirqlibeaebheskah3/temiwolexolarogovuziveki.pdf, http://dalnoboy.net/data/filestorage/upload/files/88767847736.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=disabled+persons+act+zimbabwe+pdf
- https://lsp.od.ua/wp-content/plugins/super-forms/uploads/php/files/tdbbe4kroirqlibeaebheskah3/temiwolexolarogovuziveki.pdf
- http://dalnoboy.net/data/filestorage/upload/files/88767847736.pdf
- http://centroolosprato.it/userfiles/files/71673098102.pdf
- http://hi-techfiber.com/userfiles/file/wesovemuferof.pdf
- https://consultingexpert.eu/fckeditor/userfiles/file/bevarevamefa.pdf
- http://open.ua/uploads/ckeditor/files/44431839235.pdf
- https://agsposure.org/wp-content/plugins/super-forms/uploads/php/files/d4be95db6dd784369d567a621b2eb3ac/54867560993.pdf
- https://visaonline-vn.com/wp-content/plugins/super-forms/uploads/php/files/9vcl99ec8to4ipb0j0g2rkdb5o/rutezipomekiti.pdf
- https://donnasalon.ru/wp-content/plugins/super-forms/uploads/php/files/2efcb4f1f466a7822029555b92b183f9/32640825673.pdf
- http://www.davidwoodpersonnel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d80926c4c58---77445798485.pdf
- https://skazkavdom.com/wp-content/plugins/super-forms/uploads/php/files/8deda50a207780d0b5225b28a13d7c00/venadifuvemewuzisiv.pdf
- http://eurolocal.info/sites/default/files/images/file/67260855027.pdf
- http://kaplanpm.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607f89fc2bd39---bedabixixazivemejefiv.pdf
- http://614move.com/clients/4890/File/lepubinadamopimefori.pdf
- http://shopgraeagle.com/ckeditor/uploads/files/89224159761.pdf
- http://powerfalcon.net/uppic/files/nejamimakumanokopitifipex.pdf
- http://karmand24.ir/basefile/ehotel724ir/files/vizujagewek.pdf
- https://intelean.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b0c321244e0---65795923543.pdf
- http://japan-railpass.info/images/blog//file/35241729571.pdf
- https://elitestrategyglobal.com/wp-content/plugins/super-forms/uploads/php/files/e170607da3af27c07409efec77428af2/67477624506.pdf
- https://granitabrasive.ro/editor_up/zebedutodubijotubiwitiv.pdf
- http://edanieltour.com/FileData/ckfinder/files/20210608_7544CD7ECD88D2C7.pdf
- http://ceomit.com/fckupload/file/24256091629.pdf
- http://ues-rb.ru/themes/ues-rb.ru/files/wiler.pdf
Embedded domains
- huntic.ru
- lsp.od.ua
- dalnoboy.net
- centroolosprato.it
- hi-techfiber.com
- consultingexpert.eu
- open.ua
- agsposure.org
- visaonline-vn.com
- donnasalon.ru
- www.davidwoodpersonnel.com
- skazkavdom.com
- eurolocal.info
- kaplanpm.com
- 614move.com
- shopgraeagle.com
- powerfalcon.net
- karmand24.ir
- intelean.com
- japan-railpass.info
- elitestrategyglobal.com
- edanieltour.com
- ceomit.com
- ues-rb.ru
- www.urbanwaterways.info
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report