MALICIOUS — 68276216930.pdf
MALICIOUS — 68276216930.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
c777e7f34d659b55cbe4eba2ddff1b26916a2d0a1099284706faa8f44675124f - SHA-1:
a50ed60c5a7354df4815fa60e44c2ecac7e46c16 - MD5:
6f5f899f0c51f2b1b036cf22fccc8e1f - ssdeep:
1536:tcuwisFqLYhgpA7DO6CvJ6Sd6c276VMOfZXQbIzt5jqmSyiQ:mA23Uo6zJLf8ethq3o - TLSH:
T19738BFF36297DE9C7B876B83A9E3516C208E87846537DB441548B72CD4BC2BDAF40A10 - Submitted as: 68276216930.pdf
- File type: pdf · Size: 80440 bytes
- Verdict: malicious (98/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!6F5F899F0C51
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!6F5F899F0C51 (rule
PDF/Phish-FAB!6F5F899F0C51) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://catamma.ru/uplcv?utm_term=actividades+ludicas+de+formacion+civica+y+etica+secundaria, https://retentionstudentexperience.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b9e8ba25a68---ropamowiwu.pdf, http://prestopc.it/upload/file/98164856312.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://catamma.ru/uplcv?utm_term=actividades+ludicas+de+formacion+civica+y+etica+secundaria
- https://retentionstudentexperience.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b9e8ba25a68---ropamowiwu.pdf
- http://prestopc.it/upload/file/98164856312.pdf
- http://maidnheaven.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a5c24288c4---31463545180.pdf
- https://stewsites.com/wp-content/plugins/super-forms/uploads/php/files/df71507ff37ccbf224de5a1083b98072/ladebaguze.pdf
- https://transcendenceit.com/wp-content/plugins/super-forms/uploads/php/files/cfb20d82d95976b182d222bc871abc5b/27620330291.pdf
- http://paymentsbusiness.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16099c3e21c0a8---zozomo.pdf
- https://cls-toronto.com/wp-content/plugins/super-forms/uploads/php/files/130b4b20dbf583125a2cc2409b7134d1/52707128390.pdf
- https://www.endthestigmacounselling.com/wp-content/plugins/super-forms/uploads/php/files/mnit25gd1t0jlj8vbe21ilv51b/658026052.pdf
- https://www.prestigeautobody.com.au/wp-content/plugins/super-forms/uploads/php/files/d20dab5e5d38f79d79636410dafebed0/55896596195.pdf
- http://elmiraclassiccountry.com/wp-content/plugins/super-forms/uploads/php/files/otp30fvpa3l9vi0a3baetlupi2/tojodugul.pdf
- http://79.170.40.182/boothtastic.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a2d26d5268---medegabuvovaforezelir.pdf
- https://www.sudburyhighspeedinternet.ca/wp-content/plugins/super-forms/uploads/php/files/544bf4020ef2028f3ea6ef6bde59eeed/zazudujodetepevetetuxen.pdf
- https://alphaveneers.co.uk/wp-content/plugins/super-forms/uploads/php/files/c48045b90e5681e832a7ece485d4ee1f/negateforijagidivataba.pdf
- http://www.canadavisaservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/160adcd7308906---sidutasevidinafina.pdf
- http://lirealestatelitigator.com/wp-content/plugins/super-forms/uploads/php/files/8b7e7032469c335de670faba3d1e01bd/9856095302.pdf
- http://www.kidnuri.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b742f4be412---298432342.pdf
- https://staffxrecruitment.com/wp-content/plugins/super-forms/uploads/php/files/21b108b7551dd98b37f75f44554c3c8a/sepuridozezerurowuda.pdf
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160a41af76328c---samosenebezagopipupe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- catamma.ru
- retentionstudentexperience.com
- prestopc.it
- maidnheaven.com
- stewsites.com
- transcendenceit.com
- paymentsbusiness.ca
- cls-toronto.com
- www.endthestigmacounselling.com
- www.prestigeautobody.com.au
- elmiraclassiccountry.com
- boothtastic.com
- www.sudburyhighspeedinternet.ca
- alphaveneers.co.uk
- www.canadavisaservices.com
- lirealestatelitigator.com
- www.kidnuri.com
- staffxrecruitment.com
- kaufdeinauto.de
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 79.170.40.182
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report