MALICIOUS — b087dbef4f1abd9093200f16b44a649078009698ba2459d9e4f3e73ac20d4175
MALICIOUS — b087dbef4f1abd9093200f16b44a649078009698ba2459d9e4f3e73ac20d4175 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b087dbef4f1abd9093200f16b44a649078009698ba2459d9e4f3e73ac20d4175 - SHA-1:
12451213a7bd3e5e87e5938c7e249832eece61b4 - MD5:
89cf5495701410afb0f4bfa233c32cfc - ssdeep:
1536:P+FDq0/5JF6oFtqNgPuDhkbxK2XczSY6mbmajOGjUmWspORLRTuDWQ:mw45r6EtqfDhkbxK2XgVbmajbuRLQl - TLSH:
T17F37E1F2609BED0C778B8F03A99B11EC908CE3986663D5A5C98C576CD0ACD7E7D04A50 - Submitted as: b087dbef4f1abd9093200f16b44a649078009698ba2459d9e4f3e73ac20d4175
- File type: pdf · Size: 75480 bytes
- Verdict: malicious (92/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://inwebjor.ru/uplcv?utm_term=cat+optical+illusion, http://cityhigh78.com/clients/2/2d/2ddbae4fb74c169819b3574d76e4e264/File/24396720131.pdf, https://nusbetaja2.com/contents//files/43695660085.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://inwebjor.ru/uplcv?utm_term=cat+optical+illusion
- http://cityhigh78.com/clients/2/2d/2ddbae4fb74c169819b3574d76e4e264/File/24396720131.pdf
- https://nusbetaja2.com/contents//files/43695660085.pdf
- https://ofertaromania.ro/ckfinder/userfiles/files/vupexifakoka.pdf
- https://alignerco.com/wp-content/plugins/super-forms/uploads/php/files/7e5b96b441a5ec81a32d4f5afc352265/fufef.pdf
- http://caribsplash.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608a4558946e0---73320833167.pdf
- http://midiabyz.com/wp-content/plugins/super-forms/uploads/php/files/137b8f0154665a2dcdedc9d88746606f/88388702731.pdf
- https://hmjrgoldhockey.org/wp-content/plugins/super-forms/uploads/php/files/5372fb649a292fbfbc8da0a6b64d6e3a/rebasufifojup.pdf
- http://www.supercarrentalsofmiami.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609b9d6e3b3a0---lexasafovitimoxomadivo.pdf
- https://carpanea.it/wp-content/plugins/super-forms/uploads/php/files/850a06f913ccf553e184faf395815a2a/96161887829.pdf
- http://yuhenganquan.com/userfiles/file/20210703071611_1771183784.pdf
- http://akicgiyim.com/userfiles/file/68663688642.pdf
- http://robertsrucker.com/clients/7/7f/7f5ecd1287ec2152c36a7dc1808edcbf/File/kafinumujuriderufawi.pdf
- http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a12e6154f93---vebulogep.pdf
- http://stinpo.com/ckfinder/userfiles/files/ridosogupu.pdf
- http://livingkaneohe.com/userimages/zaxokuwunugi.pdf
- http://di-tech.kr/fckeditor/userfiles/file/gavoxixijejisulumudil.pdf
- http://www.pirac.org/wp-content/plugins/super-forms/uploads/php/files/1feb959d659ff23f00902b6b376e25be/kavexiwojenonigemabela.pdf
- http://hoteldazegliotorino.com/userfiles/files/37906464881.pdf
- https://saftanton.dk/wp-content/plugins/formcraft/file-upload/server/content/files/160d41bdbba476---42524951158.pdf
- http://anhuicrew.com/upload_fck/file/2021-4-29/20210429020246594942.pdf
- http://muszempilla.com/files/file/xenuvuxipugofejo.pdf
- http://rusiuojigalvoji.lt/wp-content/plugins/formcraft/file-upload/server/content/files/160ad2d92c1377---tijulugasimuwamo.pdf
- http://inspiredindianfoundation.org/uploads/rupomododagufogawepikifis.pdf
- https://finances-canada.com/wp-content/plugins/super-forms/uploads/php/files/6c13fc52a2467ebbf5a1a04b98e77836/86838475771.pdf
Embedded domains
- inwebjor.ru
- cityhigh78.com
- nusbetaja2.com
- alignerco.com
- caribsplash.org
- midiabyz.com
- hmjrgoldhockey.org
- www.supercarrentalsofmiami.com
- carpanea.it
- yuhenganquan.com
- akicgiyim.com
- robertsrucker.com
- vtracauto.com
- stinpo.com
- livingkaneohe.com
- di-tech.kr
- www.pirac.org
- hoteldazegliotorino.com
- anhuicrew.com
- muszempilla.com
- inspiredindianfoundation.org
- finances-canada.com
- ofertaromania.ro
- saftanton.dk
- rusiuojigalvoji.lt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report