MALICIOUS — a88374c290222e0aedd31419dec79f124f2e1f7a37d28dbba7f2dac8c46657d8
MALICIOUS — a88374c290222e0aedd31419dec79f124f2e1f7a37d28dbba7f2dac8c46657d8 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
a88374c290222e0aedd31419dec79f124f2e1f7a37d28dbba7f2dac8c46657d8 - SHA-1:
98cf18afefbb1cc0800e20553ada3010ded94e0a - MD5:
c7f4d62feac9a214cb8ea2dcf780826b - ssdeep:
1536:m+0SdlaoqyCyb2RKDFdAhBtDkZwWkNpOPaWGqrqJmrcfHXwa48XSFL:fZHaoq3MFdAtwnPsqWJCcfHgf8w - TLSH:
T1A538D0F321C7ED5C3B9B9F0366E612A4A08AD7C82722EA90005C7B9C957C6BDBF50550 - Submitted as: a88374c290222e0aedd31419dec79f124f2e1f7a37d28dbba7f2dac8c46657d8
- File type: pdf · Size: 77614 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://crewmak.ru/uplcv?utm_term=neve+campbell+filmography, https://www.digitalsofts.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614fa91f2dbdb---34992582619.pdf, http://www.belladermeestetica.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1614f0d9fb03e5---sededusabizavupevemo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crewmak.ru/uplcv?utm_term=neve+campbell+filmography
- https://www.digitalsofts.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614fa91f2dbdb---34992582619.pdf
- http://www.belladermeestetica.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1614f0d9fb03e5---sededusabizavupevemo.pdf
- https://horacebatten.com/ckfinder/userfiles/files/82981185647.pdf
- https://htfcompact.com/wp-content/plugins/super-forms/uploads/php/files/e4bd7911b4dabbb54ef93cfe7f2413ba/xadituvuwawo.pdf
- http://offerseir.com/basefile/offerseircom/files/nalinobekafajobewowekazim.pdf
- https://unibel.pl/pliki/upload/file/35081114669.pdf
- http://skpizzasubs.com/uploads/files/satarenuz.pdf
- https://szalkasszorutacskok.hu/app/webroot/files/content/files/64564771744.pdf
- https://cosplay-expo.it/ckfinder/userfiles/files/2363037774.pdf
- http://seritour.com/rsm/files/pekogizexexelaz.pdf
- http://www.introspekta.si/ckfinder/ckeditor_uploaded_files/files/84041115012.pdf
- http://norilskgu.ru/userfiles/file/gojojajas.pdf
- http://chistogood.ru/admin/ckfinder/userfiles/files/taxipir.pdf
- https://bharatbiodiesel.com/userfiles/file/jowigenuti.pdf
- http://terwaarde.be/ckfinder/userfiles/files/99137149147.pdf
- https://ailani.org/wp-content/plugins/super-forms/uploads/php/files/9d623242378f71f8517b3fcba6c677cf/83233820004.pdf
- https://wct.goldcrownresort.com/magazine_files/files/wilefozojefeg.pdf
- http://sys-svinding.dk/userfiles/file/mupalisujafexasuxumow.pdf
- http://homesunshinepharma.com/upload/files/vozowawelarideredozobi.pdf
- https://mavismanagement.com/wp-content/plugins/formcraft/file-upload/server/content/files/16157424086c82---73153652566.pdf
- http://dlugopis.kbo.pl/ckfinder/userfiles/files/nulerap.pdf
- https://inprovitbolivia.com/ckfinder/userfiles/files/95037786002.pdf
- http://akgwealthplanner.com/crm/files/13418903236.pdf
- https://topclassgardening.nl/images/file/6371653906.pdf
Embedded domains
- crewmak.ru
- www.digitalsofts.com
- www.belladermeestetica.com.br
- horacebatten.com
- htfcompact.com
- offerseir.com
- unibel.pl
- skpizzasubs.com
- cosplay-expo.it
- seritour.com
- norilskgu.ru
- chistogood.ru
- bharatbiodiesel.com
- terwaarde.be
- ailani.org
- wct.goldcrownresort.com
- homesunshinepharma.com
- mavismanagement.com
- dlugopis.kbo.pl
- inprovitbolivia.com
- akgwealthplanner.com
- topclassgardening.nl
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report