MALICIOUS — 35369653999.pdf
MALICIOUS — 35369653999.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
bc0ba5183be7c2293f0ffa5fb66f362fde4909afca894a9644abd483493788d1 - SHA-1:
417dc32ce0b1f90294959b04d074a9dabc8c1ec8 - MD5:
30e95a24102bd766e2eaaca7282cd39b - ssdeep:
1536:QqlSYMhzWjAXSCqLHlSYq/pjLH6XOcYMWObI7GzW8pO7ljuAr5zn:1lSYuI0SCYcXxjLHFcvk7Ge7JNR - TLSH:
T1C938C0F72187DD9C778B9F076EAB11A8648AE7CC6131EBE000486B2CD07897EBE04541 - Submitted as: 35369653999.pdf
- File type: pdf · Size: 77945 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://queure.ru/uplcv?utm_term=android+chrome+disable+autoplay, https://vinaarc.com/app/webroot/files/ckfinder/userfiles/files/11288877152.pdf, https://koltoztetes-szallitas-lomtalanitas.excore.hu/ckfinder/userfiles/files/62230623098.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://queure.ru/uplcv?utm_term=android+chrome+disable+autoplay
- https://vinaarc.com/app/webroot/files/ckfinder/userfiles/files/11288877152.pdf
- https://koltoztetes-szallitas-lomtalanitas.excore.hu/ckfinder/userfiles/files/62230623098.pdf
- https://drivingschoolofnorthtexas.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614192b0be01b---wugimo.pdf
- https://sofahatinh.com/upload/files/kosefomuxiwa.pdf
- http://s13cf5ef.alojamientovirtual.com/ropadefutbolbarata/userfiles/file/xamikofiraxog.pdf
- http://kalmi.ru/upfiles/files/44021920899.pdf
- http://kulturazebrak.cz/userfiles/jozowegiwarokogepofu.pdf
- http://essentielles-theater.de/UserFiles/File/numovewunu.pdf
- http://ajk-opakowania.eu/upload/fck/file/18750511053.pdf
- http://illinoislivestock.org/userfiles/file/tikalatilovox.pdf
- http://hosungtour.com/FileData/ckfinder/files/20210904_4C487E8D4F1B8811.pdf
- https://burstallconrad.com/editor_files/file/6944053549.pdf
- http://pajurioverslas.lt/ckfinder/userfiles/files/vefituwolizakosas.pdf
- http://househouse.it/userfiles/files/ribobukederevitapidunater.pdf
- https://www.swx.global/wp-content/plugins/super-forms/uploads/php/files/146abc76329870043269237921dbc1dd/buluxobakodubetegen.pdf
- https://thietkewebseo.com/webroot/img/files/rowugodoj.pdf
- http://videofilm-tv.ru/content/File/vivagabufo.pdf
- http://quocteanviet.com/img-chamthi/files/folimi.pdf
- https://bandloc.com/FCKeditor/file/6318004999.pdf
- http://pspectr.ru/userfiles/file/18330510267.pdf
- http://hanaelectric.com/userData/board/file/22997190147.pdf
- https://www.rogierstoel.nl/wp-content/plugins/super-forms/uploads/php/files/t61p2e33vpl8nkkl002qb6gbq2/75134186170.pdf
- https://www.nobleorthodontic.com/wp-content/plugins/super-forms/uploads/php/files/68937dcc0c2eb0ecfccdbe083b362514/1289695133.pdf
- http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/161366f18c07e5---21281929043.pdf
Embedded domains
- queure.ru
- vinaarc.com
- drivingschoolofnorthtexas.com
- sofahatinh.com
- s13cf5ef.alojamientovirtual.com
- kalmi.ru
- essentielles-theater.de
- ajk-opakowania.eu
- illinoislivestock.org
- hosungtour.com
- burstallconrad.com
- househouse.it
- thietkewebseo.com
- videofilm-tv.ru
- quocteanviet.com
- bandloc.com
- pspectr.ru
- hanaelectric.com
- www.rogierstoel.nl
- www.nobleorthodontic.com
- hellnocancershow.com
- vetregistr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report