MALICIOUS — 68338056214.pdf
MALICIOUS — 68338056214.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
b54d190714bb805bf17ce5af6a5e81ea2ef4d8a9c87924cdb402a28fa92e3537 - SHA-1:
f590fc72a53ca87b6a942ae0f55d786dd7fcdadc - MD5:
68e9241a55119328f65f12c6f5392d9e - ssdeep:
1536:7B6u4h9wBif0rQmUMEhWNmkqMhi7gYl/LQtRKwbh+IfweIvxZhW:F659wBif0RChI0MAVBah9+mVYxy - TLSH:
T17037CFB751C7EE4C769AAB43A6FA102C204BEB493132D6504485F3BDD4BCABD3E49910 - Submitted as: 68338056214.pdf
- File type: pdf · Size: 71194 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!68E9241A5511
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://abapaposentados.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160763cbbee8ef---rukujafekuzavix.pdf, https://yssnewlessons.org/UserFilesTwo/file/xinoneju.pdf, https://divorcioconsensual.com.br/wp-content/plugins/super-forms/uploads/php/files/e872adc1df94019f6d378eb8d26c1e03/nosabobarineko.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/PmAiG5ZyT-k/uplcv?utm_term=nasus+guide+season+9
- http://abapaposentados.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160763cbbee8ef---rukujafekuzavix.pdf
- https://yssnewlessons.org/UserFilesTwo/file/xinoneju.pdf
- https://divorcioconsensual.com.br/wp-content/plugins/super-forms/uploads/php/files/e872adc1df94019f6d378eb8d26c1e03/nosabobarineko.pdf
- https://amesmedicalservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608a59b77d8b5---wemozirawujunakodiza.pdf
- http://www.britocunhaadvocacia.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/16082b82920dcd---rovikina.pdf
- https://www.breastcancerfoundation.in/wp-content/plugins/super-forms/uploads/php/files/33fa46725624d4c2a3aca55e10bc57e2/24113298609.pdf
- https://www.truesdalepainting.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609cdc678f00f---52914629678.pdf
- https://ascinfratech.com/clientprojects/trading/file/tufisedijamepike.pdf
- http://akinmedical.com/uploads/file/54908648346.pdf
- https://www.sharpeningfactory.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607fefcd28614---90120976536.pdf
- http://math-talk.kr/wp-content/plugins/super-forms/uploads/php/files/nhmhkdhogfk8dc1p6e5evdu4ct/wuduninetaxomigowokutuv.pdf
- http://splogservice.ru/content/file/xiletifegod.pdf
- https://palcev.ru/userfiles/file/38658044241.pdf
- http://www.jcca.co.in/wp-content/plugins/formcraft/file-upload/server/content/files/160817149a6f23---muxaj.pdf
- https://sckstone.com/wp-content/plugins/super-forms/uploads/php/files/481511300107093a9857d440b2f3d7d7/gojazujiwosaxeb.pdf
- https://www.electriclighting.com/wp-content/plugins/super-forms/uploads/php/files/6f282e2346c24ca1abb58a66e7a62f9b/1452573276.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- abapaposentados.com.br
- yssnewlessons.org
- divorcioconsensual.com.br
- amesmedicalservices.com
- www.britocunhaadvocacia.com.br
- www.breastcancerfoundation.in
- www.truesdalepainting.com
- ascinfratech.com
- akinmedical.com
- www.sharpeningfactory.com
- math-talk.kr
- splogservice.ru
- palcev.ru
- www.jcca.co.in
- sckstone.com
- www.electriclighting.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- F:\jU
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report