MALICIOUS — 99291067477.pdf
MALICIOUS — 99291067477.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
b43a7c2f28f6ca4aaa3ba10347183f3f25cf96f47aebe4166886ac4ff2b53e62 - SHA-1:
e9f14fe243032bbcb2fa298364502659a16dd511 - MD5:
3e7f8a007cc19e1c4ad2535d879fc71f - ssdeep:
1536:KoTqTGL6W2RnuPgkqTQS5wrDt0tcaWcWGpOK96sO1M6imgWqQeZ7na4:5TUcTqFqDmFyKosAM6im3eZ7d - TLSH:
T1FF37B0E3709BDD8C76DBAB036AEA216C644DD74C1122E6A0408CB62DC1BC9FD7F04951 - Submitted as: 99291067477.pdf
- File type: pdf · Size: 73277 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://dienlanhhonganh.com/images/pic/file/wiredoforadijur.pdf, https://asigurareingermania.ro/wp-content/plugins/super-forms/uploads/php/files/9ucld84mfv3pde8ejjtn5iaikv/73532440549.pdf, http://moveisgarciadigital.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16086714a3b5e5---23954808940.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/cv9VXjIrmdE/uplcv?utm_term=numeros+cuanticos+quimica+pdf
- https://dienlanhhonganh.com/images/pic/file/wiredoforadijur.pdf
- https://asigurareingermania.ro/wp-content/plugins/super-forms/uploads/php/files/9ucld84mfv3pde8ejjtn5iaikv/73532440549.pdf
- http://moveisgarciadigital.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16086714a3b5e5---23954808940.pdf
- https://www.lsv-wittlage.de/ckfinder/userfiles/files/64986025730.pdf
- https://familienbilstrup.dk/userfiles/file/gajuzelakepuvezeji.pdf
- https://www.c2commercial.com/wp-content/plugins/super-forms/uploads/php/files/0153146826b043de136a54f55d68993e/65092708892.pdf
- https://www.ezhealthcheck.com/wp-content/plugins/super-forms/uploads/php/files/2ujer46312geaokbogohit0htg/1024288916.pdf
- https://noukos.gr/wp-content/plugins/formcraft/file-upload/server/content/files/160fa47aed5b2a---gurubegulubadazipeveseg.pdf
- https://bikinibody.be/wp-content/plugins/super-forms/uploads/php/files/7eumud1ob7o1bnmq52bid2it21/redeterigamokisax.pdf
- https://www.adelaarenergy.com/wp-content/plugins/super-forms/uploads/php/files/4rk5smqttmtulkesg10cpvkgfn/26034357422.pdf
- http://asbufestival.com/uploads/FCK_files/file/57134563568.pdf
- http://tzoetemondje.be/uploads/files/60886827618.pdf
- http://nissanotogovap.net/uploads/images/files/poxexomemitenupop.pdf
- https://bahamianbrewery.com/ckfinder/userfiles/files/66104307118.pdf
- https://smoothnomad.com/wp-content/plugins/super-forms/uploads/php/files/au14i5u76p7ni5g82iqt50vrjo/72271015401.pdf
- http://www.catalogodecineargentino.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e8bfd4e9d27---wilokafajomabo.pdf
- https://feriaesotericadeatocha.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b869f8416fa---gabonizit.pdf
- http://www.ponderosafestival.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b5fa75ce409---valojanefevulez.pdf
- http://urjabatteries.in/userfiles/file/38912941689.pdf
- http://mtjjt.com/2013/upload/article/files/210813230247450035n98lv.pdf
- http://www.associatedomains.com/wp-content/plugins/formcraft/file-upload/server/content/files/160815dd9cb2b1---78429957824.pdf
- https://tipresentoio.it/images/file/60338145675.pdf
- https://biocoop.legreniervert.fr/ckfinder/userfiles/files/tuwonekixutotat.pdf
- https://108pizza.pl/uploads/userfiles/files/kijedexakedugokune.pdf
Embedded domains
- feedproxy.google.com
- dienlanhhonganh.com
- moveisgarciadigital.com.br
- www.lsv-wittlage.de
- www.c2commercial.com
- www.ezhealthcheck.com
- bikinibody.be
- www.adelaarenergy.com
- asbufestival.com
- tzoetemondje.be
- nissanotogovap.net
- bahamianbrewery.com
- smoothnomad.com
- www.catalogodecineargentino.com
- feriaesotericadeatocha.com
- www.ponderosafestival.com
- urjabatteries.in
- mtjjt.com
- www.associatedomains.com
- tipresentoio.it
- biocoop.legreniervert.fr
- 108pizza.pl
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report