MALICIOUS — 96025766817.pdf
MALICIOUS — 96025766817.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ba9f90df632382ed0cf2c3ed85ff69c66fa096a2bbd7e9b1330e31375aeb6c2c - SHA-1:
e116e73c857625af1969ef9b17bd9d91472fc885 - MD5:
ce258719ace664bf057eb45a65c5b4d2 - ssdeep:
1536:+ZLFIDT4u+lkJ5rJTj88dB/KEoZqvMNsE43tLUW6pOu26WU2OfZXG7vet8PEwgEG:ELFIo5Cl88dwESqvMOx3thu2JOxW7veF - TLSH:
T1F039D0F36187DD0CB3579F077AEA2218608BDB8811A2DA50508D767CDA7C5FEAE04711 - Submitted as: 96025766817.pdf
- File type: pdf · Size: 88491 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://kaupa.cz/userfiles/file/61964311030.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://hit-air.pro/ckfinder/userfiles/files/5864471350.pdf, http://tubietelbar.hu/uploadfile/65622438628.pdf, http://bagpack.com.np/wp-content/plugins/formcraft/file-upload/server/content/files/160a38a120f441---favubetutideninesuwalot.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/zMnd8XtcwSM/uplcv?utm_term=start+windows+in+safe+mode+from+command+prompt
- http://hit-air.pro/ckfinder/userfiles/files/5864471350.pdf
- http://tubietelbar.hu/uploadfile/65622438628.pdf
- http://bagpack.com.np/wp-content/plugins/formcraft/file-upload/server/content/files/160a38a120f441---favubetutideninesuwalot.pdf
- http://bamt.be/wp-content/plugins/formcraft/file-upload/server/content/files/160abf66759c88---nizoxabojirunakotitaw.pdf
- https://transilvaniafishing.ro/app/webroot/files/userfiles/files/54832072281.pdf
- https://thegioibaobicarton.com/Images_upload/files/rebulazamerepolesofufale.pdf
- http://kaupa.cz/userfiles/file/61964311030.pdf
- https://666666.vn/upload/fck/file/zitujisul.pdf
- http://study4student.com/cache/fck_files/file/26524241792.pdf
- http://tksvolga.ru/userfiles/file/mebalogafibarudaxa.pdf
- http://churchliferesources.org/wp-content/plugins/formcraft/file-upload/server/content/files/16090a07128857---19963030441.pdf
- https://apatity.verlauf-ekb.ru/admin/ckfinder/userfiles/files/98813655327.pdf
- https://carstenrath.com/wp-content/plugins/super-forms/uploads/php/files/i868mtec1umvr68l5jhgh79spr/sirawududuxodozuj.pdf
- http://remontnoedelo.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160fff5bb8d9c2---rawaxatexixibimoxaxolaf.pdf
- http://www.skupp.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160809ca9a19ed---95090605654.pdf
- https://hpsoft.shop/upload/files/gikefusesalavugurugapes.pdf
- https://www.ezhealthcheck.com/wp-content/plugins/super-forms/uploads/php/files/h5u519m76enlm2pl948his8d8v/dapejadewigurenuv.pdf
- http://resortcrimea.com/ckfinder/userfiles/files/91961311265.pdf
- https://krimgranit.ru/wp-content/plugins/super-forms/uploads/php/files/9cc5012a8d0300999573bf5eff7404ff/pajex.pdf
- http://www.photobreak.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1607a56dee2822---22907419998.pdf
- http://immobilieninvestors.eu/userfiles/file/64547556332.pdf
- https://cremeconferences.com/wp-content/plugins/super-forms/uploads/php/files/7631826e17285d0f99e796e8a26939ec/nemezada.pdf
- http://www.icodar.com/wp-content/plugins/formcraft/file-upload/server/content/files/160908cad18bdb---pomokapogopomabot.pdf
- http://thevisionkharj.com/userfiles/files/gipoladubep.pdf
Embedded domains
- feedproxy.google.com
- hit-air.pro
- bamt.be
- thegioibaobicarton.com
- study4student.com
- tksvolga.ru
- churchliferesources.org
- apatity.verlauf-ekb.ru
- carstenrath.com
- remontnoedelo.ru
- www.skupp.pl
- hpsoft.shop
- www.ezhealthcheck.com
- resortcrimea.com
- krimgranit.ru
- www.photobreak.com.br
- immobilieninvestors.eu
- cremeconferences.com
- www.icodar.com
- thevisionkharj.com
- www.w3.org
- purl.org
- ns.adobe.com
- tubietelbar.hu
- bagpack.com.np
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report