MALICIOUS — 160f6600106b3d---17428609355.pdf
MALICIOUS — 160f6600106b3d---17428609355.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d35f9735e32131af862fff36fbc5e427d4e75a57b4d60ce3d778a617136206e8 - SHA-1:
3367a2d3e38ab437052ef78f917120d97440b605 - MD5:
90b52b2b23dfccf33e5dcbe610e7bb3f - ssdeep:
1536:HAvrxUqb/aZPZJ+CVkJUSurkrXizmPMvJMePAXmypVBGu/om+ZWbpONiWNAMa6FK:41UqbUjknrXizmPMvJVzsjLom+bNjra1 - TLSH:
T1BF39CFF310E7ED1C7A4F9F0366BB111CA49AE6485122EB60558C766CC92CA7EBF10E11 - Submitted as: 160f6600106b3d---17428609355.pdf
- File type: pdf · Size: 87657 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://energo-winstal.pl/userfiles/file/xagitomilorozalufatuvoka.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://elegune.net/files/galeria/files/58504653434.pdf, https://www.lowdoc-loans.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16073d8edeec61---23200684763.pdf, https://mithermomix.com.mx/wp-content/plugins/super-forms/uploads/php/files/4741c561e1818d3e37d9efec81c81b27/gowizokomukiz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/3CAf4wW3hvY/uplcv?utm_term=great+danes+and+cats
- https://elegune.net/files/galeria/files/58504653434.pdf
- https://www.lowdoc-loans.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16073d8edeec61---23200684763.pdf
- https://mithermomix.com.mx/wp-content/plugins/super-forms/uploads/php/files/4741c561e1818d3e37d9efec81c81b27/gowizokomukiz.pdf
- https://southtours.com/wp-content/plugins/super-forms/uploads/php/files/171uml673669gudbhsu9f7v09b/sezaxizidasevipoja.pdf
- https://law.com.sg/wp-content/plugins/super-forms/uploads/php/files/a431bb984df0ca90f849f7e3a74182c8/jatukusevutokole.pdf
- https://mfdesign.hu/files/file/71328014738.pdf
- http://energo-winstal.pl/userfiles/file/xagitomilorozalufatuvoka.pdf
- https://rabudiagnostic.com/userfiles/files/sofarukiletiwig.pdf
- http://acecaalcoy.com/userfiles/file/19847397772.pdf
- http://trenermichal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/16077d7cd87879---64758736234.pdf
- https://cristiandellavedova.com/wp-content/plugins/super-forms/uploads/php/files/kmlsk14ersa2l9iepa5khhc9m0/14467993442.pdf
- https://livingcircles.ch/wp-content/plugins/formcraft/file-upload/server/content/files/1609e7a07b50e2---gowonuzekugixafefo.pdf
- http://ylplj.com/ckfinder/userfiles/files/sumetipusupob.pdf
- http://leguido.net/files/67329252568.pdf
- http://specimport.by/files/files/84031150048.pdf
- https://afanasyev-design.ru/wp-content/plugins/super-forms/uploads/php/files/bcd78c4fd852579c51a22e57e6db76db/libenijobalemofid.pdf
- https://www.digitalsofts.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c520c614807---xilodiwafeji.pdf
- https://asigurareingermania.ro/wp-content/plugins/super-forms/uploads/php/files/va74op5velbott3pf8mb2d8ilo/30621579744.pdf
- http://interiorconsignments.com/media/file/dipipu.pdf
- http://math-talk.kr/wp-content/plugins/super-forms/uploads/php/files/jn9om6gudumqbpkldlo62ego78/12391507036.pdf
- http://tv-sat.cz/userfiles/file/58099866158.pdf
- http://www.rebranded.tv/wp-content/plugins/formcraft/file-upload/server/content/files/160801fe1a7a76---ramuvuzepuwitijanafo.pdf
- https://sk-developers.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a4ff01dbdd7---bojeletuzat.pdf
- https://marjoyunlar.com/calisma2/files/uploads/fesiwido.pdf
Embedded domains
- feedproxy.google.com
- elegune.net
- www.lowdoc-loans.com.au
- mithermomix.com.mx
- southtours.com
- law.com.sg
- energo-winstal.pl
- rabudiagnostic.com
- acecaalcoy.com
- trenermichal.pl
- cristiandellavedova.com
- livingcircles.ch
- ylplj.com
- leguido.net
- afanasyev-design.ru
- www.digitalsofts.com
- interiorconsignments.com
- math-talk.kr
- www.rebranded.tv
- sk-developers.com
- marjoyunlar.com
- archerelectricsupply.com
- totalyoumovement.com
- opalbiosciences.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report