MALICIOUS — 202109262213416134.pdf
MALICIOUS — 202109262213416134.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d4bb0324a5a9f3ffd26ebfd8200b34a5dcc1ccbb3fe70af27b5837b14be0b19c - SHA-1:
629b3286dbe7e09b284da874b07f36b42e165b57 - MD5:
cc0bdce8100a638737a0bde332d2344c - ssdeep:
1536:IFrKLC9mQJJhBjQJwpVKX6g0VU2OlENT9W8pO73WjR6Vl7we3:cKe9mQBSJiVKqg0JO6NT87SR6Vl7N - TLSH:
T12A37CEF720ABDD8C774F9B437AA701AD549EE7885272EA600084727C967C97D7F01940 - Submitted as: 202109262213416134.pdf
- File type: pdf · Size: 72901 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.higher-energy-trampolineclub.com/wp-content/plugins/formcraft/file-upload/server/content/files/161324404d3dcc---93196570026.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://inwebjor.ru/uplcv?utm_term=coc+mod+server+1, http://bjoybrands.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132b64aa1179---15224603780.pdf, http://zentrumok.com/userfile/files/45061492890.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://inwebjor.ru/uplcv?utm_term=coc+mod+server+1
- http://bjoybrands.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132b64aa1179---15224603780.pdf
- http://zentrumok.com/userfile/files/45061492890.pdf
- https://mavachhaiphong.com/upload/files/64046245700.pdf
- http://secureyun.cn/uploadfile/file///2021091000360848.pdf
- https://www.higher-energy-trampolineclub.com/wp-content/plugins/formcraft/file-upload/server/content/files/161324404d3dcc---93196570026.pdf
- https://regalcabs.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1613bd96e67a56---97044611606.pdf
- http://metallpress.ru/files/favarokuburugu.pdf
- http://maximaviajes.com/FCKfiles/file/japefosulivujeped.pdf
- http://ez-surveying.com/htdocs/cljr/data/files/46292245157.pdf
- https://tractorpulling-emmeloord.nl/upload/file/domadogidapipadaxomawixu.pdf
- https://www.afoa.org.ar/backend/ckfinder/userfiles/files/63192767369.pdf
- https://galaxy-training.com/userfiles/file/dimokunemafaraleg.pdf
- https://swotin.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614beb6a56946---reborarulu.pdf
- https://brune-schmuckwerk.de/ckfinder/userfiles/files/baput.pdf
- http://bright-mineral.com/uploadfile/file/2021092500523125.pdf
- http://nakamurasangyou.jp/app/webroot/uploads/files/96699169330.pdf
- http://twgo8.com/uploads/base/files/202109122309066267.pdf
- http://www.specemc.ru/upload/files/70528429120.pdf
- http://www.immo-uno.com/ckfinder/userfiles/files/82458220816.pdf
- https://visualmotion.nl/uploads/file/95569097568.pdf
- http://a2itsolutions.com/chop/multimedia/userfiles/file/modasodiwusujiwafazu.pdf
- https://lmetinternationalschool.in/ckeditor/ckfinder/userfiles/files/11538512805.pdf
- http://www.iuoelocal870.com/kaizen/ckfinder/userfiles/files/22859838093.pdf
- https://www.democratum.com/wp-content/plugins/super-forms/uploads/php/files/442a256cb5e52d7ca379ce60ee3190dd/42587170375.pdf
Embedded domains
- inwebjor.ru
- bjoybrands.com
- zentrumok.com
- mavachhaiphong.com
- secureyun.cn
- www.higher-energy-trampolineclub.com
- regalcabs.co.uk
- metallpress.ru
- maximaviajes.com
- ez-surveying.com
- tractorpulling-emmeloord.nl
- galaxy-training.com
- swotin.com
- brune-schmuckwerk.de
- bright-mineral.com
- nakamurasangyou.jp
- twgo8.com
- www.specemc.ru
- www.immo-uno.com
- visualmotion.nl
- a2itsolutions.com
- lmetinternationalschool.in
- www.iuoelocal870.com
- www.democratum.com
- gelinyuanyi.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report