MALICIOUS — 28673117541.pdf
MALICIOUS — 28673117541.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cfe4e1600ba754ed8d316609e59d8ea94a2e6d9fe2ece277ef340f2552efbb4f - SHA-1:
610f9319d28318de79c354efbe8f5f912630030b - MD5:
2aa49eca7268b9085895b8fd2c74cde4 - ssdeep:
1536:PpIQc0KX4qvCMZG0JMWwcYSaoC8oiTjy9scw+EmnOr9ei3TY7/9:m/4CCgPJMXZe/jQdOr9eBJ - TLSH:
T13937D1F3B167EE9CBF45AB03696620A56182D3CC1132D3B919C476ACC4787BE7C61A10 - Submitted as: 28673117541.pdf
- File type: pdf · Size: 75420 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!2AA49ECA7268
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.agrosystem.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16090c8e7a7a83---rumejitijunugajolatukav.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://allytemp.ru/uplcv?utm_term=dragon+ball+legends+latest+apk, https://mfdesign.hu/files/file/54978504921.pdf, http://www.agrosystem.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16090c8e7a7a83---rumejitijunugajolatukav.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://allytemp.ru/uplcv?utm_term=dragon+ball+legends+latest+apk
- https://mfdesign.hu/files/file/54978504921.pdf
- http://www.agrosystem.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16090c8e7a7a83---rumejitijunugajolatukav.pdf
- http://cn-noah.com/uploadfile/file/xetaxovazikanorujude.pdf
- https://www.helmmsp.ca/wp-content/plugins/super-forms/uploads/php/files/319394456f84a5ed5605e3b72147ab72/45731556683.pdf
- http://thegreenlegacykeepers.com/clients/e/e8/e8dc17949b7ef813e9937e453902477f/File/texuxanodavunisezuw.pdf
- https://earplighting.com/wp-content/plugins/super-forms/uploads/php/files/e51681eb79a9c82fcedc83c0f7ecb656/kenedipusapitisiloveviv.pdf
- https://vizzzio.ru/wp-content/plugins/super-forms/uploads/php/files/2251a8eec97b228687cce5bf0e714ecc/fofosulebilofalijit.pdf
- https://utilitydiscount.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d4bdb8faf6---wibikojedipanolipamojesa.pdf
- http://ctyrkolky-gamax.cz/data/dokumenty/16248399740.pdf
- https://bakwanudang.com/contents//files/65811076768.pdf
- https://maximatrimony.com/ckfinder/userfiles/files/mufinuliwukitomiso.pdf
- https://puertoestereo.com/wp-content/plugins/super-forms/uploads/php/files/s3cjmfr6r94estmcv3oj0tcasf/jajazazilofopebomajimopi.pdf
- http://palami.by/images/file/76820341959.pdf
- http://aliancegroup.su/wp-content/plugins/formcraft/file-upload/server/content/files/1608597056187d---sebunuratanimab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- allytemp.ru
- cn-noah.com
- www.helmmsp.ca
- thegreenlegacykeepers.com
- earplighting.com
- vizzzio.ru
- utilitydiscount.com
- bakwanudang.com
- maximatrimony.com
- puertoestereo.com
- aliancegroup.su
- www.w3.org
- purl.org
- ns.adobe.com
- mfdesign.hu
- www.agrosystem.com.tr
- ctyrkolky-gamax.cz
- palami.by
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report