MALICIOUS — 20210903_145240_167.pdf
MALICIOUS — 20210903_145240_167.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
cc515bf353c1bedb993e3224ddb165d947a97a1b7c45af5471e6edd3d28963a7 - SHA-1:
2cdc29b04dd2e5e2aa3c9d7b987e108e0f006266 - MD5:
bb6785bd4d68920f4f44bb01b26f05a9 - ssdeep:
1536:a+L2u9MEU5gpmKnCiQHJ/pNEteyzTdW6pOu2liM2aMwWhEHyvgx:r5O5JmnEhccy/uu2lG5fK - TLSH:
T13B37CFF32097DE8CBB4B5F13B9DB01A86589D7895162DB90408877ACD4BCA7E6F10B00 - Submitted as: 20210903_145240_167.pdf
- File type: pdf · Size: 71958 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=oral+proficiency+test+pdf, http://ljhalls.com/wp-content/plugins/super-forms/uploads/php/files/167bbfe0491751bdb732a69c321c3940/63023441660.pdf, https://www.bakirkoytemsilcisi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607344ad17f5e---pajowobosamedexore.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pistant.ru/uplcv?utm_term=oral+proficiency+test+pdf
- http://ljhalls.com/wp-content/plugins/super-forms/uploads/php/files/167bbfe0491751bdb732a69c321c3940/63023441660.pdf
- https://www.bakirkoytemsilcisi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607344ad17f5e---pajowobosamedexore.pdf
- https://myhoorayhealth.com/wp-content/plugins/super-forms/uploads/php/files/q70emu3micfi6pcdi6isvq6t53/12088481700.pdf
- https://kantankacreative.com/wp-content/plugins/super-forms/uploads/php/files/e4dbd179de652d7030a57ec9ddb8bba4/48232411759.pdf
- https://adepotcustom.com/UploadFiles/file/20210507030449111.pdf
- http://bahtiyardishekimi.com/fckfiles/file/pavuzaporikegojoki.pdf
- https://www.mii.net/wp-content/plugins/super-forms/uploads/php/files/6456f897d9e975aeaab3c59a29e05440/48058159433.pdf
- http://polskienarty.pl/data/aktualnosci_imgs/file/badarurelevoradunema.pdf
- https://ncfouting.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ebd8ba7235---90903650906.pdf
- http://stringquartet.biz/web/images/fck/file/zegikuvizesatesun.pdf
- https://china-glass-mosaic.com/userfiles/files/20210821_083232.pdf
- http://morebricks.com/ckfinder/userfiles/files/merowixiz.pdf
- https://zohopin.com/calisma2/files/uploads/tikidakewetafevexat.pdf
- http://www.opencalgary.org/wp-content/plugins/formcraft/file-upload/server/content/files/160710e4d4c14a---tepewoxikemipojete.pdf
- http://carmakers.cz/userfiles/files/buxipepoz.pdf
- https://daynexweb.com/upload/ckfinder/files/3911316254.pdf
- https://ontime-taxi.kg/wp-content/plugins/super-forms/uploads/php/files/abcc0b3500557c7d4dbb737e04314279/67104039404.pdf
- http://woori-tour.kr/FileData/ckfinder/files/20210710_0A2FADAFEC7142ED.pdf
- https://hmv.ir/wp-content/plugins/formcraft/file-upload/server/content/files/160f108c2b92b2---zonumexep.pdf
- http://ednak.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608fc98f078df---18676485911.pdf
- http://heilpraxis-pankow.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609c2cd3aab1e---xanorimexeduxugabeje.pdf
- http://monkey-do.net/userfiles/file/rupezulegunujomerumiw.pdf
- https://stewsites.com/wp-content/plugins/super-forms/uploads/php/files/a7fa008f5b5f54a2104683541f3f1ad4/geresexifupunavo.pdf
- https://sk-developers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b8cad0cd95---rinajanejepupefafogurele.pdf
Embedded domains
- pistant.ru
- ljhalls.com
- www.bakirkoytemsilcisi.com
- myhoorayhealth.com
- kantankacreative.com
- adepotcustom.com
- bahtiyardishekimi.com
- www.mii.net
- polskienarty.pl
- ncfouting.com
- stringquartet.biz
- china-glass-mosaic.com
- morebricks.com
- zohopin.com
- www.opencalgary.org
- daynexweb.com
- woori-tour.kr
- hmv.ir
- ednak.com
- heilpraxis-pankow.de
- monkey-do.net
- stewsites.com
- sk-developers.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report