MALICIOUS — a54fde2b78b7d67ca67ff4f69e3825793093047be3a9658f77bd5431642a9d20
MALICIOUS — a54fde2b78b7d67ca67ff4f69e3825793093047be3a9658f77bd5431642a9d20 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
a54fde2b78b7d67ca67ff4f69e3825793093047be3a9658f77bd5431642a9d20 - SHA-1:
623d64eb55d372c2aa1fe6f9d292bc0a25b2373f - MD5:
dec921bf56297d9e928eebd1e7e75967 - ssdeep:
1536:HthI7i1XB5qfpdbtTpt+xX0WovGqiSW8pO7VoV:N+7pxxtT/+xXai57A - TLSH:
T1A037BFF750ABDD8C7B8E4B4766E610BC9089F7845132EB6040C8B6ACA47C5BDBF10A41 - Submitted as: a54fde2b78b7d67ca67ff4f69e3825793093047be3a9658f77bd5431642a9d20
- File type: pdf · Size: 71718 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://chcial.ru/uplcv?utm_term=class+8+maths+worksheets+with+answers+pdf, http://www.victorian-manor.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/161538f264487e---xurudadunazozogusupax.pdf, https://cicasoftavukatwebsitesi.demowebsiteleri.com/upload/files/fovesuzusupeku.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://chcial.ru/uplcv?utm_term=class+8+maths+worksheets+with+answers+pdf
- http://www.victorian-manor.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/161538f264487e---xurudadunazozogusupax.pdf
- https://cicasoftavukatwebsitesi.demowebsiteleri.com/upload/files/fovesuzusupeku.pdf
- https://kezmosas.hu/files/file/23397765273.pdf
- https://gornjastubica.hr/files/65610889727.pdf
- https://www.nobleorthodontic.com/wp-content/plugins/super-forms/uploads/php/files/bbc18994a6452f3517c38beb3730fee1/tudowo.pdf
- https://projetovm.com/uploads/files/zofuxibaxebifo.pdf
- https://nbtele.com/en/cache/fck_files/file/beginepam.pdf
- https://parisnordmedical.fr/docs/file/xexifirevufaluw.pdf
- http://marcelponjee.nl/ponjeefiles/file/49702123952.pdf
- https://dogathermalhotel.com/resimler/files/lafezixuzakinan.pdf
- https://atamergranit.com/userfiles/file/66174012290.pdf
- http://melodylavernebettencourt.com/media/file/megoweveso.pdf
- http://consol.hu/images/uploadedimages/file/62195776621.pdf
- https://cfbadalona.net/ckdata/files/vuxenijokebenanon.pdf
- http://bankerz.in/qpic/files/lomoninukukulewiterop.pdf
- https://www.studiorosaliabusco.it/ckfinder/userfiles/files/siduwen.pdf
- http://viaterrestre.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1614ad3e3e49d4---65695793713.pdf
- http://baharemadinah.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613d39386e03b---616591864.pdf
- https://hamayeshniroo.com/shop/file/wagibud.pdf
- https://ce-mi.pl/uploads/userfiles/files/mexojovepadupu.pdf
- https://orcasproje.com/userfiles/file/2904790183.pdf
- http://bbmeti.it/userfiles/files/86666758922.pdf
- https://mackbeks.com/files/file/wizamezuzibuxefa.pdf
- https://vildmarksjagt.dk/userfiles/file/54650047939.pdf
Embedded domains
- chcial.ru
- www.victorian-manor.co.za
- cicasoftavukatwebsitesi.demowebsiteleri.com
- www.nobleorthodontic.com
- projetovm.com
- nbtele.com
- parisnordmedical.fr
- marcelponjee.nl
- dogathermalhotel.com
- atamergranit.com
- melodylavernebettencourt.com
- cfbadalona.net
- bankerz.in
- www.studiorosaliabusco.it
- viaterrestre.com.br
- baharemadinah.com
- hamayeshniroo.com
- ce-mi.pl
- orcasproje.com
- bbmeti.it
- mackbeks.com
- counterreaction.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report