MALICIOUS — bed41cdd695d2f0355c8bf57701b866c6bcb51bc95cac5f933a5862d4feb0064
MALICIOUS — bed41cdd695d2f0355c8bf57701b866c6bcb51bc95cac5f933a5862d4feb0064 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
bed41cdd695d2f0355c8bf57701b866c6bcb51bc95cac5f933a5862d4feb0064 - SHA-1:
f5c409cc7d50213136937d4c9a3d6d84c1720801 - MD5:
d82f1e637d6b111640ad2b360e25fa6c - ssdeep:
1536:ngrpwXuW5i3vwg6WWdR01QVJ9MZ2ZACe6LznLTp717gl:gdEuAwwg6fy1QP9I2ZM6fnLN716 - TLSH:
T17736D0F3A1A7DC8D3E82D7136EEA142DB046C7886032AB9C84D8766CC57C67C7E50951 - Submitted as: bed41cdd695d2f0355c8bf57701b866c6bcb51bc95cac5f933a5862d4feb0064
- File type: pdf · Size: 69323 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D82F1E637D6B
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://drafthe.ru/uplcv?utm_term=advanced+trainer+practice+tests+with+answers+pdf, https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/39cbe9edf389b4cb961a2777cd0d56e0/17529668375.pdf, https://www.pal-kont.hu/wp-content/plugins/super-forms/uploads/php/files/1c5e31d12be5f1332965c2e7926d93e1/76837335028.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://drafthe.ru/uplcv?utm_term=advanced+trainer+practice+tests+with+answers+pdf
- https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/39cbe9edf389b4cb961a2777cd0d56e0/17529668375.pdf
- https://www.pal-kont.hu/wp-content/plugins/super-forms/uploads/php/files/1c5e31d12be5f1332965c2e7926d93e1/76837335028.pdf
- https://www.enviedecrire.com/wp-content/plugins/formcraft/file-upload/server/content/files/16079389941eba---66243546450.pdf
- https://c4ir.ae/wp-content/plugins/super-forms/uploads/php/files/d48agggmdj668psfu7r626c0d0/27639652535.pdf
- https://qualitylightsolutions.com/wp-content/plugins/super-forms/uploads/php/files/ddc058e5cd99b53a08245e1a03fa063d/13198804784.pdf
- https://amerismithenterprises.com/wp-content/plugins/super-forms/uploads/php/files/8c2339e0b444eab92fe4f749df1ff165/88510796111.pdf
- https://www.themeshcowork.com/wp-content/plugins/super-forms/uploads/php/files/8270e4ba2d191b844aba515e97827679/sazukezogitoserupojatima.pdf
- https://christembassybarking.org/wp-content/plugins/super-forms/uploads/php/files/22ff8862856b9f280d630f93da714f09/tomawulobogaxagojadolipif.pdf
- https://liantoong.com/archive/upload/files/gigapuj.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb95ed2d4b1---jevokuxad.pdf
- http://for-rent-leuven.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609adee6a6484---zexejok.pdf
- http://www.vivelamusica.es/wp-content/plugins/formcraft/file-upload/server/content/files/16080dab5a892d---tibomifo.pdf
- http://jrpst.pl/userfiles/file/karidapabutukatumixezef.pdf
- http://reiki-roots.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160a93fc95d65a---12866646731.pdf
- http://www.canadiantreasurer.com/wp-content/plugins/formcraft/file-upload/server/content/files/160973f9b0d920---58421173584.pdf
- https://londonvipchauffeur.co.uk/wp-content/plugins/super-forms/uploads/php/files/f3f9452a7c852c887109bde63d5968d9/kipogirumik.pdf
- https://afanasyev-design.ru/wp-content/plugins/super-forms/uploads/php/files/e24ad4d65dee32675ef5ad1dfaa4e6b6/89230261606.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- drafthe.ru
- www.enviedecrire.com
- qualitylightsolutions.com
- amerismithenterprises.com
- www.themeshcowork.com
- christembassybarking.org
- liantoong.com
- www.1000ena.com
- for-rent-leuven.com
- www.vivelamusica.es
- jrpst.pl
- reiki-roots.co.uk
- www.canadiantreasurer.com
- londonvipchauffeur.co.uk
- afanasyev-design.ru
- www.w3.org
- purl.org
- ns.adobe.com
- goactive.hu
- www.pal-kont.hu
- c4ir.ae
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report