MALICIOUS — 51075311949.pdf
MALICIOUS — 51075311949.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d31d75c2e68d1ae96c34d9cf0c0d563aa909224d84272cffff8099a4dac076d2 - SHA-1:
d506a9d68617b82fb445f33b1669f6d8ddb79cce - MD5:
ad62b1cd1f132afe2c583a6d80b2b849 - ssdeep:
1536:7n0/oVBADBQ5GitzJaeb96trBBkDOJS+9/VbjzJrqBpWapOtQ9NQvoqm6XW+FBM1:YycahtdaMeBBkDOJD9dbj9MGtQHB6fFe - TLSH:
T1C338C0F31197ED5C77CB8B0368EA226DA48EE68C1162EA205484B76CD5BC6BDFF00541 - Submitted as: 51075311949.pdf
- File type: pdf · Size: 83973 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://likebarcode.com/image/files/20210705_104430.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://drafthe.ru/uplcv?utm_term=search+pdf+text+windows+10, https://ventana-sur.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ff933690c4.pdf, http://likebarcode.com/image/files/20210705_104430.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://drafthe.ru/uplcv?utm_term=search+pdf+text+windows+10
- https://ventana-sur.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ff933690c4.pdf
- http://likebarcode.com/image/files/20210705_104430.pdf
- http://www.veronicaneal.com/wp-content/plugins/formcraft/file-upload/server/content/files/1/160705c242a6de---67744282597.pdf
- http://pvsystexperts.com/wp-content/plugins/super-forms/uploads/php/files/qnje8hb6qhcur4ohn0qo3t5e90/vefoxusi.pdf
- https://carthink.org/wp-content/plugins/formcraft/file-upload/server/content/files/1606cc8f23baf6---51314542926.pdf
- http://agataklimowska.pl/userfiles/file/godijel.pdf
- http://yulintimber.cn/d/files/selazapopinizisuligapoli.pdf
- https://soyana.de/js/ckfinder/userfiles/files/66579640822.pdf
- https://apparel.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/a5e9016d1af59951fae9f90bee6acbc8/vosuto.pdf
- http://laros.cz/UserFiles/file/lisumetoli.pdf
- http://ampletrekking.com/userfiles/file/tonigewus.pdf
- https://rjiminfra.com/wp-content/plugins/super-forms/uploads/php/files/a2e6198c8af36108f4f8919b729c2cbc/buwuzunuxobuzatazabutik.pdf
- https://silverlabpupsforsale.com/userfiles/files/gitapasotimujerawalaxu.pdf
- https://prosaison.fr/userfiles/files/fegafusisu.pdf
- http://interstroy96.ru/uploads/files/mejoguvakavulas.pdf
- https://graffitipaintstudio.com/wp-content/plugins/super-forms/uploads/php/files/baad7a40f8753e005ad5cad43b4116c4/fojisitof.pdf
- https://selectwifi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160db199936f32---xinijinozodewiderifex.pdf
- http://in-dapt.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612514cad14ef---fanesujiwebosetizeramaba.pdf
- http://josephpowellfamilyreunion.com/clients/0/04/04c15d356d3082020e114f8c0300f46e/File/78689365028.pdf
- http://zamel2.pl/userfiles/file/lupivoxel.pdf
- http://www.carolglassman.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609da8e5e2439---dibadanoralavenewesekujib.pdf
- http://quocteanviet.com/img-chamthi/files/kufera.pdf
- https://kassa-evotor.ru/wp-content/plugins/super-forms/uploads/php/files/fb3lmc1jbuj7r8ll480p1d0rro/dajubikurasexuvesoxudazam.pdf
- http://breakevenpoint.pl/uploads/editor/file/levig.pdf
Embedded domains
- drafthe.ru
- ventana-sur.com
- likebarcode.com
- www.veronicaneal.com
- pvsystexperts.com
- carthink.org
- agataklimowska.pl
- yulintimber.cn
- soyana.de
- apparel.allianceflooring.net
- ampletrekking.com
- rjiminfra.com
- silverlabpupsforsale.com
- prosaison.fr
- interstroy96.ru
- graffitipaintstudio.com
- selectwifi.com
- in-dapt.com
- josephpowellfamilyreunion.com
- zamel2.pl
- www.carolglassman.com
- quocteanviet.com
- kassa-evotor.ru
- breakevenpoint.pl
- ahi.com.ua
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report