MALICIOUS — 68239700433.pdf
MALICIOUS — 68239700433.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c9242b2860c0d712064f6252579c296568bd3a5c4398d80d9ce2eba7d2dde1c9 - SHA-1:
76399cd65ae4e36e0e46dea5c44fe886dffbc7ce - MD5:
69df1a6421062bb811765536f8a7e915 - ssdeep:
1536:a3/c3UdBFa60FVMWdq8dXBxJsj7FKXeU8h+HBTPj0WNnW6NXGTmWepOyzbe:cldK6E7d9BxJsjxKR9HBLjsNTXye - TLSH:
T12438C0F360ABDC8D738A9F072DAB166C944ADBC47052EA400088BABCD47C4BEBF14551 - Submitted as: 68239700433.pdf
- File type: pdf · Size: 83385 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://zh-huaxun.com/uploadfiles/files/sugimonowowerisiromedewer.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://dobrasekacka.cz/userfiles/file/9802586727.pdf, http://yingtailong.com/upload/file/210917122227216907gjtmh03u033p.pdf, https://tlproduct.com/userfiles/file/84326616587.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/3CAf4wW3hvY/uplcv?utm_term=android+gingerbread+to+kitkat
- http://dobrasekacka.cz/userfiles/file/9802586727.pdf
- http://yingtailong.com/upload/file/210917122227216907gjtmh03u033p.pdf
- https://tlproduct.com/userfiles/file/84326616587.pdf
- http://fcraregistration.com/UploadedData/file/zowidak.pdf
- http://www.iso-clean.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16137f4573afc6---damegaburusep.pdf
- https://quizai.com/uploads/files/jafixiz.pdf
- http://www.appsolutely.sg/wp-content/plugins/formcraft/file-upload/server/content/files/1613cff25b19ba---tivabiranoneduvewakuxo.pdf
- http://vetusmeter.com/images/upload/File/gewizalobunebuwozux.pdf
- http://zh-huaxun.com/uploadfiles/files/sugimonowowerisiromedewer.pdf
- http://riccaassociati.eu/userfiles/files/pifotovofagirixijetojiriz.pdf
- http://namhungholdings.com/uploads/ckfinder/files/92718243723.pdf
- https://self-storage.sg/images/uploadedimages/file/88495258212.pdf
- http://aodaibooking.com/FileData/ckfinder/files/20210910_48946DE87F85C5F4.pdf
- http://potlista.com/file/files/simorabonopajepit.pdf
- http://sevenseahotel.com/uploads/images/files/80726436250.pdf
- http://s8radziejowice-paszkow.pl/userfiles/file/vusuvetusubo.pdf
- http://dreamcatcherltd.com/userfiles/file/3927753811.pdf
- https://independentmusicleague.com/wp-content/plugins/super-forms/uploads/php/files/602d8346402386a4eb77c66edd090afc/fepamejetutawimob.pdf
- http://princeverma.in/uploads/files/48305306342.pdf
- http://protetyka-lublin.com/images/wyswig_images/file/xevemonakuvuwowufu.pdf
- https://skatrip.com/basefile/skatripcom/files/31129452484.pdf
- http://chiangmai-clean.com/user_img/files/wesevikijuk.pdf
- http://merwepizza.com/upload/file/tanox.pdf
- http://remproekt-m.ru/admin/ckfinder/userfiles/files/wejibuxevegedasofas.pdf
Embedded domains
- feedproxy.google.com
- yingtailong.com
- tlproduct.com
- fcraregistration.com
- www.iso-clean.fr
- quizai.com
- www.appsolutely.sg
- vetusmeter.com
- zh-huaxun.com
- riccaassociati.eu
- namhungholdings.com
- self-storage.sg
- aodaibooking.com
- potlista.com
- sevenseahotel.com
- s8radziejowice-paszkow.pl
- dreamcatcherltd.com
- independentmusicleague.com
- princeverma.in
- protetyka-lublin.com
- skatrip.com
- chiangmai-clean.com
- merwepizza.com
- remproekt-m.ru
- senkyu.jp
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report