MALICIOUS — 57056386464.pdf
MALICIOUS — 57056386464.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
aaf8cc9dce5c4ab8d99209ee3fb671acf2ae55ce072d3fe336579d908f70ebec - SHA-1:
c7101e8d90c8bda4bc4c263be8ae995548fb0c0f - MD5:
3ba7f55c180f1ede16e3b87ce1ed2389 - ssdeep:
1536:1JoccOUX9hulNFmwrJg8AEFM/VAAp3kzW+wwfEpyNWpFcwT3RSmqaWcpOmUsu:f9FQjulNFmwrb05FkzW+nfEpyMKYZqdp - TLSH:
T10B37CFF360EBDD4C764B9B037AFB216C684AD6C85561E6508188BABC817C6BE7F00911 - Submitted as: 57056386464.pdf
- File type: pdf · Size: 75961 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b3d33ac9c45---xewafaputog.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=curcumin+health+benefits+pdf, http://italianopizzeria-pg.com/uploads/files/91933813475.pdf, https://diversifiedhumansolutions.com/wp-content/plugins/super-forms/uploads/php/files/9c01dede1c37b3259911ac932edbcbdf/77776394898.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=curcumin+health+benefits+pdf
- http://italianopizzeria-pg.com/uploads/files/91933813475.pdf
- https://diversifiedhumansolutions.com/wp-content/plugins/super-forms/uploads/php/files/9c01dede1c37b3259911ac932edbcbdf/77776394898.pdf
- https://www.fifatravels.com/wp-content/plugins/formcraft/file-upload/server/content/files/16092d373a0db1---65198124396.pdf
- http://johnmichaelharrisonlaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/83167354224.pdf
- http://cedresarquitectura.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607ae99a963af---49454836769.pdf
- https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b3d33ac9c45---xewafaputog.pdf
- http://coss-wynn-reunion.com/clients/d/db/dbe3622004495b304d8703879a486b7d/File/seronu.pdf
- https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/e03bbe04681aa3dbb32e9de4fb474e16/61294630670.pdf
- http://atlonnuri.org/UpLoadImage/editer/files/48684083577.pdf
- http://bukharaatlanta.com/sites/default/files/file/25164640588.pdf
- http://hanleyresources.com/images/nikawuse.pdf
- https://agronlogistics.com/userfiles/files/zidulepevifakiximikanudir.pdf
- http://accessiblevehicleservices.com/userfiles/file/tuwixudapanijid.pdf
- http://paglialonga.it/userfiles/files/52622582871.pdf
- https://icrs-as.com/userfiles/file/nusasukokifofuw.pdf
- http://hyundai-baoloc.com/luutru/files/15927526767.pdf
- https://www.aceitedeoliva.com/wp-content/plugins/super-forms/uploads/php/files/dc8f4841e5a37df3a0b98d704bb11e72/polidetala.pdf
- https://gservicepz.com/wp-content/plugins/super-forms/uploads/php/files/723f28fc220cef52b084dbd83e35d4da/setozejagigaj.pdf
- http://qlinairnv.be/userfiles/file/67195945012.pdf
- http://detskaoptika.cz/ckfinder/userfiles/files/92669756249.pdf
- http://157.230.241.115/image/upload/File/kikojijigomevofafevile.pdf
- https://doluhosting.com/calisma2/files/uploads/zixetesemamizibuvowi.pdf
- https://ceccargiurgiu.ro/userfiles/file/25847552944.pdf
- https://nullemont.fr/nullemont/ckfinder/userfiles/files/89479154231.pdf
Embedded domains
- crysiq.ru
- italianopizzeria-pg.com
- diversifiedhumansolutions.com
- www.fifatravels.com
- johnmichaelharrisonlaw.com
- cedresarquitectura.com
- www.northamericatalk.com
- coss-wynn-reunion.com
- amezdigital.com
- atlonnuri.org
- bukharaatlanta.com
- hanleyresources.com
- agronlogistics.com
- accessiblevehicleservices.com
- paglialonga.it
- icrs-as.com
- hyundai-baoloc.com
- www.aceitedeoliva.com
- gservicepz.com
- qlinairnv.be
- doluhosting.com
- nullemont.fr
- russkiivopros.com
- www.w3.org
- purl.org
Embedded IP addresses
- 157.230.241.115
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report