MALICIOUS — 90838376954.pdf
MALICIOUS — 90838376954.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
b473e74211556a1517a1fe7d6461ea78326cbcffae94f54a265edc66429354e0 - SHA-1:
2293e4fd4d03bc43ef8c342df1f23c8024b988af - MD5:
7b78ca999d0732961c1d5c78715e1d4f - ssdeep:
1536:HJD+w7zP1TPliDboev/BtJR1eSaBADP6MR9wbIMJnbWGpOK6pxXlGEWJ+vuodVsz:pXvdPcbVnQXAGMwncK671G9yuo/C - TLSH:
T1F839D0F320DBDD9C779FAF1369BA0169604AD3806076DB618084737CE5BC9BE6B00651 - Submitted as: 90838376954.pdf
- File type: pdf · Size: 91011 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://synerhu.ru/uplcv?utm_term=physical+science+module+1+pdf, https://pabausa.org/wp-content/plugins/formcraft/file-upload/server/content/files/160e5fa3939956---dewetif.pdf, http://9meclinic.com/ckfinder/userfiles/files/zobafo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://synerhu.ru/uplcv?utm_term=physical+science+module+1+pdf
- https://pabausa.org/wp-content/plugins/formcraft/file-upload/server/content/files/160e5fa3939956---dewetif.pdf
- http://9meclinic.com/ckfinder/userfiles/files/zobafo.pdf
- https://www.keystonecare.co.uk/wp-content/plugins/super-forms/uploads/php/files/f78261dc64a86b4b3da78e0067e5d38e/xobegubixa.pdf
- http://english-life.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1606f5364d0659---438419608.pdf
- http://terapeutickemasaze.eu/wp-content/plugins/formcraft/file-upload/server/content/files/1609d28bb4d77b---10666376767.pdf
- http://splogservice.ru/content/file/nusolebefijoxedorasi.pdf
- https://marksiegeldds.com/wp-content/plugins/super-forms/uploads/php/files/eaf6cbc8fb1ce5876ae78dca5d3f8c71/53795920792.pdf
- https://flexrocksrollovers.com/wp-content/plugins/super-forms/uploads/php/files/v97c0bjqk6gno78hv91jo5724g/78936188404.pdf
- https://www.opdrrustukalac.com/wp-content/plugins/formcraft/file-upload/server/content/files/160764bf5e1b8c---9027934459.pdf
- http://www.psstrecno.sk/wp-content/plugins/formcraft/file-upload/server/content/files/1606cb3cfa7fdb---6417334641.pdf
- http://www.tenniscanberra.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1606f605fbb693---20042342309.pdf
- https://vernadoc.com/wp-content/plugins/super-forms/uploads/php/files/cfb001499343e27b371414675266dd31/31062017679.pdf
- http://quickfix-poland.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e7a6600332a---60549533181.pdf
- http://vipnjl.com/userfiles/files/3578251474.pdf
- https://tocgia247.com/wp-content/plugins/super-forms/uploads/php/files/bjqojl2pmrgkr4p80nfqg129em/36198549058.pdf
- http://zuche0551.com/upload/file/bipusopovinoguf.pdf
- https://askopenko.com/wp-content/plugins/super-forms/uploads/php/files/99435aefcc3c912481fb1107a0f58161/82101824422.pdf
- http://mattstergamer.com/wp-content/plugins/super-forms/uploads/php/files/vav6h0lmmiqf64duc4bpko2h1g/sanegafemezimarozegozasag.pdf
- http://lemfhafamilylove.com/clients/a/ae/ae548a02e38cf20d1222216853584fb4/File/rugirijekoxovesufup.pdf
- http://casier-a-bouteilles.fr/file/39408728700.pdf
- http://bjbtrh.com/files/pic/file/bupilima.pdf
- https://anmimar.com/royal/userfiles/file/vafaxinibisivuwubedij.pdf
- https://bataretak.com/img/files/file/vovivisijipo.pdf
- https://plumcourse.com/wp-content/plugins/super-forms/uploads/php/files/d9ba68f5d47db2146211a3b5e24fedf8/vimevutofemo.pdf
Embedded domains
- synerhu.ru
- pabausa.org
- 9meclinic.com
- www.keystonecare.co.uk
- english-life.ru
- terapeutickemasaze.eu
- splogservice.ru
- marksiegeldds.com
- flexrocksrollovers.com
- www.opdrrustukalac.com
- www.tenniscanberra.com.au
- vernadoc.com
- quickfix-poland.com
- vipnjl.com
- tocgia247.com
- zuche0551.com
- askopenko.com
- mattstergamer.com
- lemfhafamilylove.com
- casier-a-bouteilles.fr
- bjbtrh.com
- anmimar.com
- bataretak.com
- plumcourse.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report