MALICIOUS — 64070374715.pdf
MALICIOUS — 64070374715.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d278c9d52eb0d2bb95dee6de89b1f6bae024e0a66b16238527fa808cf31e163d - SHA-1:
244629b2c03ab3e72a32888dd9dbbb6ba1de01f4 - MD5:
632223fbe53891927acfed03c8b0d1ef - ssdeep:
1536:7kqyc3sS8C15w1jqchoTJKXPvbI9WxNwyEuQvKlW8pO+RsW:tv15CjqcKTAXPs6NPFoK0+j - TLSH:
T15F38D0F35197DD4C669A8B0369FA10D8A489D7882032F6A041CCB76CC67C9FDBE54A60 - Submitted as: 64070374715.pdf
- File type: pdf · Size: 82452 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ser-buk.com/userfiles/file/sojadinugiz.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=geography+question+answer+pdf, http://www.barankayalar.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/161467747dc930---jiriwerenebifutesid.pdf, http://paitoonbox.com/userfiles/files/lanonoxa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=geography+question+answer+pdf
- http://www.barankayalar.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/161467747dc930---jiriwerenebifutesid.pdf
- http://paitoonbox.com/userfiles/files/lanonoxa.pdf
- http://ser-buk.com/userfiles/file/sojadinugiz.pdf
- http://votava2.altrodesign.eu/ckfinder/userfiles/files/titoxodatuza.pdf
- https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/33264d857ce81ffb2ce633dde4a3344d/19927401202.pdf
- http://liily.jp/upload/file/20210929072411.pdf
- https://clinicamanila.com/ckfinder/userfiles/files/97063952821.pdf
- http://donghobaoan.com/uploads/files/misabob.pdf
- http://landia-print.com/pdir/file/rowodunebexonumas.pdf
- http://luckyassessoria.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1613a906ec17a9---reluvojijebaporifujam.pdf
- http://hizirferforje.com/admin/fckeditor/editor/images/file/seloxuvejaxaxetusuvix.pdf
- http://terredellamagnagrecia.com/userfiles/files/60597896693.pdf
- http://omonetach.pl/foto/ilustracje/file/jusepifo.pdf
- https://ddriu.hu/wp-content/plugins/super-forms/uploads/php/files/faa6470c0f3df914cd3bc3b901f12c40/renobud.pdf
- http://softtox.pl/new/userfiles/file/vamuxisizifulotegap.pdf
- http://lignumweb.com/site/webroot/uploads/files/64168847416.pdf
- http://cc-loges.com/uploads/file/13040795345.pdf
- https://promoxcenter.ro/ckfinder/userfiles/files/39676557678.pdf
- http://luatsugiadinhviet.com/upload/ck/files/61546954707.pdf
- https://ismet.com.br/ckfinder/userfiles/files/11408105281.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- huntic.ru
- paitoonbox.com
- ser-buk.com
- votava2.altrodesign.eu
- amartzon.store
- liily.jp
- clinicamanila.com
- donghobaoan.com
- landia-print.com
- luckyassessoria.com.br
- hizirferforje.com
- terredellamagnagrecia.com
- omonetach.pl
- softtox.pl
- lignumweb.com
- cc-loges.com
- luatsugiadinhviet.com
- ismet.com.br
- www.w3.org
- purl.org
- ns.adobe.com
- www.barankayalar.com.tr
- ddriu.hu
- promoxcenter.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report