MALICIOUS — 160dd60f8a7048---26842175356.pdf
MALICIOUS — 160dd60f8a7048---26842175356.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a7fdbe168cf1825892036a6fb47ed9c3904b14cd9ae4d89ebd074b05b6d1d3a2 - SHA-1:
3abb5a142695bb0dce7b8c03aba36cafa4d0e9c4 - MD5:
122b0b0d3969b25502430a7689efc76f - ssdeep:
1536:jg4whS8bJiTauZ+ONiw87wmhTJmB3cuSMZ3DWY2QSxJaMxRJ6OpoOWjgZytbYJS5:Rf8bJGaWLYP7HJmBsXMZSQSxJvRIzx64 - TLSH:
T1C039C0F350CBEC4C37CB9F8395A61199649AE3886572DA6180C8B77CC5BCA7DBE00941 - Submitted as: 160dd60f8a7048---26842175356.pdf
- File type: pdf · Size: 90739 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://discoveryenglish.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608eca465293c---2998516396.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://discoveryenglish.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608eca465293c---2998516396.pdf, http://makaifruits.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609aa472cff86---24579612262.pdf, http://vstarmp.cn/upload/files/20210614_115454.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/LPIa9PGmDLg/uplcv?utm_term=cite+sources+powerpoint
- http://discoveryenglish.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608eca465293c---2998516396.pdf
- http://makaifruits.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609aa472cff86---24579612262.pdf
- http://vstarmp.cn/upload/files/20210614_115454.pdf
- https://schreinerheusi.de/wp-content/plugins/formcraft/file-upload/server/content/files/160aff64633562---15002426227.pdf
- https://www.projectorrentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ad9a99ea1a2---56006565338.pdf
- http://sva-jeanroze.com/xmedia/file/nonekexituloxi.pdf
- http://hanarotalk.com/userfiles/file///50174232482.pdf
- https://metroguards.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16083b0da3a416---99040707628.pdf
- http://sskj.pl/userfiles/file/simobosik.pdf
- https://agentcctv.com/userfiles/file/60305598262.pdf
- https://abeess.com/userfiles/file/5067133470.pdf
- https://shinyjewellers.com/wp-content/plugins/super-forms/uploads/php/files/m2sbjida2v4ht3oh7vsip93u1c/59333080116.pdf
- https://trsbarriersdirect.com/wp-content/plugins/super-forms/uploads/php/files/77e3fka2mv0uii5s1jttu66p9q/84970464338.pdf
- http://c2mag.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608c1adaa9edc---zovapolatenajotobo.pdf
- https://storage-in-motion.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078d29e902f9---fotufasi.pdf
- https://agrotehholding.ru/wp-content/plugins/super-forms/uploads/php/files/e8ae5f4dd21b37114b40d233d6b7a1f0/detaga.pdf
- https://makemycake.gr/wp-content/plugins/super-forms/uploads/php/files/sr1mfrgf9gqujh0kgl4g85j71g/99664875479.pdf
- https://nuregio.de/wp-content/plugins/formcraft/file-upload/server/content/files/160c66a99d5761---juzugeragar.pdf
- https://trsbarriersdirect.com/wp-content/plugins/super-forms/uploads/php/files/4msjf76c696vrpm5jvk6ulki91/22615041411.pdf
- https://widepolymers.com/userfiles/file/gugik.pdf
- http://westtech1963.com/clients/d/d4/d4250bc21dcbbf02d7f9bc68df143add/File/38856984959.pdf
- http://www.danvillern.com/wp-content/plugins/super-forms/uploads/php/files/l8e0ie0nfvb4g3n4f58iojdsn3/ragesip.pdf
- https://www.qlsny.com/wp-content/plugins/super-forms/uploads/php/files/ff4d6eb0edf78278fc54cf02bbf8a8be/doguguwebafemiwaku.pdf
- https://rocksoliddesigns.biz/userfiles/file/xibewilexawo.pdf
Embedded domains
- feedproxy.google.com
- discoveryenglish.org
- makaifruits.com
- vstarmp.cn
- schreinerheusi.de
- www.projectorrentals.com
- sva-jeanroze.com
- hanarotalk.com
- metroguards.com.au
- sskj.pl
- agentcctv.com
- abeess.com
- shinyjewellers.com
- trsbarriersdirect.com
- c2mag.com
- storage-in-motion.com
- agrotehholding.ru
- nuregio.de
- widepolymers.com
- westtech1963.com
- www.danvillern.com
- www.qlsny.com
- rocksoliddesigns.biz
- www.phsdcenter.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report