MALICIOUS — 53482579944.pdf
MALICIOUS — 53482579944.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 6 of 50 detection engines flagged it.
Identification
- SHA-256:
c3397d5dff3f3428d98175bf782d2a0c2b2e244b58477f71311ef81eaa2f6488 - SHA-1:
f6cfa19f6e50333223c6b40fb4b7c9260e3bb13e - MD5:
9743b0697964ae9111210ff068a629f2 - ssdeep:
1536:muROE4zkGMtdtpcxiF1S7PlqXtitaV8RL6QVwsqj03HKEG/N1FG:5R2kGMtdskF1SLoYtaqRL3F3HT2N6 - TLSH:
T1D737CFF39497ED0CBB871F13FAA3116C5195D7892132A6A44488BB7CC4BCABC7E05940 - Submitted as: 53482579944.pdf
- File type: pdf · Size: 73791 bytes
- Verdict: malicious (92/100)
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!9743B0697964
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://www.ltgpartners.com/wp-content/plugins/super-forms/uploads/php/files/d7624d992949a852dfc6091c3cab4f8c/87643704376.pdf, http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ce1e485f37---bitig.pdf, http://www.circoloaletrium.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607cc1b464a29---3011523294.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/Om9ozkHLxGw/uplcv?utm_term=power+bi+templates+pbit
- https://www.ltgpartners.com/wp-content/plugins/super-forms/uploads/php/files/d7624d992949a852dfc6091c3cab4f8c/87643704376.pdf
- http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ce1e485f37---bitig.pdf
- http://www.circoloaletrium.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607cc1b464a29---3011523294.pdf
- http://ebsenglish.net/_UploadFile/Images/file/rilonaduzore.pdf
- https://vernadoc.com/wp-content/plugins/super-forms/uploads/php/files/3830ce5dc6866bebc5126f2997662cd6/raxugugigamibodazeje.pdf
- http://www.urbanwaterways.info/files/9681080437.pdf
- http://erbilsunhotel.com/wp-content/plugins/super-forms/uploads/php/files/4teq0bskri7jpatbafnc13bqn7/jakazuzonubinewevedi.pdf
- http://sinara.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/1607c9a0ac3ee6---61736481898.pdf
- http://admio.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160893e65c5ae4---lufojotole.pdf
- https://sipsib.ru/wp-content/plugins/super-forms/uploads/php/files/f09756144e2c1a6fd1dc6124922a0fd6/rujediratesopaxorotuk.pdf
- http://www.vivelamusica.es/wp-content/plugins/formcraft/file-upload/server/content/files/16092e1f5e5fb6---gotifuloxilagiweroxe.pdf
- https://3dreamvr.com/wp-content/plugins/super-forms/uploads/php/files/4d0df0ce4b8e12f81ba76371a52b9761/puradato.pdf
- https://thesmithgrouphouston.com/wp-content/plugins/super-forms/uploads/php/files/e40117614896f376d2ebc587c87e44ee/20853142438.pdf
- https://riverasphotovideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/16092d6fa1249f---nared.pdf
- https://www.limratechnologies.net/wp-content/plugins/formcraft/file-upload/server/content/files/16089c5e9044b0---vesilabotewij.pdf
- http://www.ellisrasbetonwerke.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1608dfbbe50aa5---xipotofawezamikusani.pdf
- https://backcountryplayground.com/wp-content/plugins/super-forms/uploads/php/files/0cd7380ec78670c81bdebcae1aa7bde6/41974090226.pdf
- https://qualitylightsolutions.com/wp-content/plugins/super-forms/uploads/php/files/fbae51cb99d9e250ba52ec86d35710a3/2276488244.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- www.ltgpartners.com
- www.marsagri.com
- www.circoloaletrium.it
- ebsenglish.net
- vernadoc.com
- www.urbanwaterways.info
- erbilsunhotel.com
- sinara.org.br
- admio.ru
- sipsib.ru
- www.vivelamusica.es
- 3dreamvr.com
- thesmithgrouphouston.com
- riverasphotovideo.com
- www.limratechnologies.net
- www.ellisrasbetonwerke.co.za
- backcountryplayground.com
- qualitylightsolutions.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report