MALICIOUS — 60178519825.pdf
MALICIOUS — 60178519825.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c07673ec5eec237827a1978655b375334aa39818925661641cf58a6706cfccad - SHA-1:
a8815b054f30e04e0802b94e3fb2872837da3372 - MD5:
953a60714bed0150ece7afc6bb2ebebc - ssdeep:
1536:mOTY5zr91YLdNNFdv9aNh26d5tei7cZGZR0914xZvCIsuB/GB:Azr8LdNjdv9ANLteiIZGZoexVJsuBY - TLSH:
T1A836D0F3625BCE4C7E466B136AB7147CA04DC6882422E7E808C471FDD6AC67FAD10951 - Submitted as: 60178519825.pdf
- File type: pdf · Size: 69243 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!953A60714BED
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.ideaklinikbakirkoy.com/wp-content/plugins/formcraft/file-upload/server/content/files/160792bb79d568---92689023328.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://alpha-th.com/userfiles/file/78096683497.pdf, https://www.dyna-tech.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16080e6f1cfbdf---zategafivibasedegul.pdf, http://czdashan.cn/uploadfile/file/2021042923254673499.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=byju%2527+s+apk+apkpure
- http://alpha-th.com/userfiles/file/78096683497.pdf
- https://www.dyna-tech.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16080e6f1cfbdf---zategafivibasedegul.pdf
- http://czdashan.cn/uploadfile/file/2021042923254673499.pdf
- https://www.enterpriselighting.com/wp-content/plugins/super-forms/uploads/php/files/76b871e44f05929179bb77b56bcbf9cd/soluwimal.pdf
- http://dirabrealtors.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b33061341a---32182324010.pdf
- http://omniatel.it/wp-content/plugins/formcraft/file-upload/server/content/files/160732bb17353d---16693862432.pdf
- https://chicagoportablexray.com/wp-content/plugins/formcraft/file-upload/server/content/files/16079ccaa368ec---xikadavewevabirevodazupag.pdf
- http://www.farparts.cl/wp-content/plugins/formcraft/file-upload/server/content/files/1607ce4378b0da---62448615382.pdf
- http://www.bewegeninarnhem.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607a0b9d475d9---71642288610.pdf
- https://www.ideaklinikbakirkoy.com/wp-content/plugins/formcraft/file-upload/server/content/files/160792bb79d568---92689023328.pdf
- http://for-rent-antwerp.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607df64463761---21074952992.pdf
- http://blog.crowdly.com/wp-content/plugins/formcraft/file-upload/server/content/files/16084f549c0a52---xegoliguk.pdf
- https://thejinglelab.com/wp-content/plugins/super-forms/uploads/php/files/gi6upfh8d8usuer2bms83nivkm/menarav.pdf
- http://dodici12.ru/wp-content/plugins/super-forms/uploads/php/files/47ck4sui5krfgc083a1r1qddn1/75482721476.pdf
- https://www.audioclinica.pt/wp-content/plugins/super-forms/uploads/php/files/9k7hdu8jts3j7bjttv7ib7336b/90095310774.pdf
- https://hightechrustremovers.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160866da1cee80---wawataxiv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- alpha-th.com
- www.dyna-tech.nl
- czdashan.cn
- www.enterpriselighting.com
- dirabrealtors.com
- omniatel.it
- chicagoportablexray.com
- www.bewegeninarnhem.nl
- www.ideaklinikbakirkoy.com
- for-rent-antwerp.com
- blog.crowdly.com
- thejinglelab.com
- dodici12.ru
- hightechrustremovers.nl
- www.w3.org
- purl.org
- ns.adobe.com
- www.farparts.cl
- www.audioclinica.pt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report