MALICIOUS — 59793873185.pdf
MALICIOUS — 59793873185.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a62e6a4f3f5e29e8df718f312ac442d044fc7f800fd4cda07c4bfb15d9725c37 - SHA-1:
2cd1d7029bdf0cce47df7a766ceafc32aec7a18c - MD5:
20b90fc9d52914e737aec38010ee368d - ssdeep:
1536:ifXwXO1yjkdh54fWKnYD4FMJ3YezF5SIg7OMJH3f8YOpKLsQAW1DeXea3QWspO2o:GgXO3HGfWPD4FMJ3YEgIf2XEYWMsQVot - TLSH:
T1BA38C0F72157DD8CF247EF0376E71158604BE7885162EBA09188B66CD4BC9BE6E00B42 - Submitted as: 59793873185.pdf
- File type: pdf · Size: 79967 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://emiem.pl/public/upload/ckfinder/userfiles/files/8124772692.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://nomylo.ru/uplcv?utm_term=cannot+open+zip+file+on+android, https://stcatherine.ac.ug/wp-content/plugins/formcraft/file-upload/server/content/files/16141da2c59d4d---54260818123.pdf, https://www.dooleysnaturalgas.com/ckfinder/userfiles/files/mukudasorakuferegovexefi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nomylo.ru/uplcv?utm_term=cannot+open+zip+file+on+android
- https://stcatherine.ac.ug/wp-content/plugins/formcraft/file-upload/server/content/files/16141da2c59d4d---54260818123.pdf
- https://www.dooleysnaturalgas.com/ckfinder/userfiles/files/mukudasorakuferegovexefi.pdf
- http://daisin1977.com/js/upload/files/35397482483.pdf
- http://hatowo.com/app/webroot/uploads/files/datixinawakekatemasati.pdf
- http://emiem.pl/public/upload/ckfinder/userfiles/files/8124772692.pdf
- https://www.frontierexim.com/wp-content/plugins/super-forms/uploads/php/files/a63pss08kqld9oja6539do5695/71055245417.pdf
- http://3e-recycling.ru/app/webroot/filesfiles/mewuxowu.pdf
- http://hiredriver.com/uploads/assets/files/46500609049.pdf
- http://sakuragiramenandsushi.com/uploads/files/gufawegutipoligozakef.pdf
- http://www.stratcareerservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/16131688ee4391---8359244125.pdf
- http://grupomarsamo.com/wp-content/plugins/formcraft/file-upload/server/content/files/161433f5647a14---54268134567.pdf
- http://www.predoisiasociatii.ro/wp-content/plugins/formcraft/file-upload/server/content/files/161467ff6a8919---45397181412.pdf
- http://palirna-frydek.cz/uploaded/file/nanumaligarigukolazutedi.pdf
- http://onnetsolution.in/userfiles/file/95066956470.pdf
- http://www.drivingschool-brno.cz/files/files/galezugifetiduwebug.pdf
- http://lor-rostov.su/userfiles/files/kilifadariral.pdf
- http://www.pro9apps.com/app/webroot/files/uploadimagesfile/luxekediwatix.pdf
- http://devitohomesorlando.com/userfiles/files/35127677385.pdf
- http://hantechwelding.com/userfiles/file/2021090501080573499.pdf
- http://na3.it/misc/file/koguwalowivedalenone.pdf
- http://davidhammerstein.org/ckfinder/userfiles/files/11922685935.pdf
- http://viaterrestre.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1613142ed11de2---bofazaxuvabenuxulodiweju.pdf
- http://chandigarhdatarecovery.com/files/file/zodewedavavajisibu.pdf
- https://signika.pl/Upload/file/15856925444.pdf
Embedded domains
- nomylo.ru
- www.dooleysnaturalgas.com
- daisin1977.com
- hatowo.com
- emiem.pl
- www.frontierexim.com
- 3e-recycling.ru
- hiredriver.com
- sakuragiramenandsushi.com
- www.stratcareerservices.com
- grupomarsamo.com
- onnetsolution.in
- lor-rostov.su
- www.pro9apps.com
- devitohomesorlando.com
- hantechwelding.com
- na3.it
- davidhammerstein.org
- viaterrestre.com.br
- chandigarhdatarecovery.com
- signika.pl
- www.w3.org
- purl.org
- ns.adobe.com
- stcatherine.ac.ug
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report