MALICIOUS — 70559654511.pdf
MALICIOUS — 70559654511.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d63baaff459436a84232762bfbaf63a8d45780fd93405b4520bcb4a9508ff467 - SHA-1:
69915a0343b9d0fc243b8e8917a1b45ae3b4a1b1 - MD5:
08bc58d05c3cd2fdcfd7f799831d1384 - ssdeep:
1536:e4HsJakGaxFipdmAGGcYZyZhA0/RmW9S7TV7pqDATF3DaClW5B6KgW8pO7I0M:bHsJnyOAbZEhBI0Ah3DJKL78 - TLSH:
T1D238D1F3608BCD1C7A87DF439DE612EC615FD7882222E9504588B52CD47CABD6F10661 - Submitted as: 70559654511.pdf
- File type: pdf · Size: 83070 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://frigosztufi.ro/ckfinder/userfiles/files/49505086838.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://nuevocoach.co.uk/wp-content/plugins/super-forms/uploads/php/files/453574e3e6ff3fdbe856855066d5c5a3/4674758808.pdf, https://frigosztufi.ro/ckfinder/userfiles/files/49505086838.pdf, https://go2germany.ru/files/file/53629766379.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=hamd+o+naat+urdu+pdf
- https://nuevocoach.co.uk/wp-content/plugins/super-forms/uploads/php/files/453574e3e6ff3fdbe856855066d5c5a3/4674758808.pdf
- https://frigosztufi.ro/ckfinder/userfiles/files/49505086838.pdf
- https://go2germany.ru/files/file/53629766379.pdf
- http://ashioke.com/images/library/File/sisenobixep.pdf
- http://makassitools.com/userfiles/file///84426635267.pdf
- https://www.ergunaygoren.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d5fe748653---sawuwaz.pdf
- https://genesisbehaviorcenter.com/wp-content/plugins/super-forms/uploads/php/files/0e6dbb5aada0b5d024ec19d03dcd42cf/57056615015.pdf
- http://www.auditsi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160be5c377be7a---6833217237.pdf
- http://mirembeestate.co.ug/wp-content/plugins/formcraft/file-upload/server/content/files/16075f26dd5d16---tuzuliwemagewube.pdf
- https://www.tratedu.net/ssss2018/assets/143ad273/ckfinder/core/connector/php/upload/userfiles/files/d516a1faa6c81893c337f83106ce3de1.pdf
- http://wsystem.sk/userfiles/files/taremefutumarosajupepib.pdf
- https://beachesbrewing.com/wp-content/plugins/super-forms/uploads/php/files/d3100befd0770a6049360eecf7ebedd6/tijevi.pdf
- https://howardsteeves.com/wp-content/plugins/super-forms/uploads/php/files/e87bc57fc90be504165ffffd0ed69d3d/nobaguxemuxaxakevubematat.pdf
- https://patriot.ch/wp-content/plugins/super-forms/uploads/php/files/6hbu9c0rgfb970cm6h7vhb1jrm/tovan.pdf
- http://villaturri.it/wp-content/plugins/formcraft/file-upload/server/content/files/16086d2cf9003c---64671856369.pdf
- https://www.kiteschule-kiel.de/wp-content/plugins/formcraft/file-upload/server/content/files/1608604429602e---86703700847.pdf
- https://www.sevgiliyevideo.net/wp-content/plugins/formcraft/file-upload/server/content/files/1610df97c100af---dipif.pdf
- http://www.kidnuri.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608401144e4fb---85382542997.pdf
- https://www.allterra.group/wp-content/plugins/super-forms/uploads/php/files/dcd079cced664ec0be690e8c74aa92ea/96634507899.pdf
- http://adacu.org/userfiles/file/20210809073314.pdf
- http://www.guaitoli.eng.br/wp-content/plugins/formcraft/file-upload/server/content/files/160bb79d975712---19079022890.pdf
- https://arhometutor.com/userfiles/file/80659547931.pdf
- https://sidexsideaudio.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b42ad208f07---73439805886.pdf
- http://awkontrakt.pl/ckfinder/userfiles/files/76393635712.pdf
Embedded domains
- feedproxy.google.com
- nuevocoach.co.uk
- go2germany.ru
- ashioke.com
- makassitools.com
- www.ergunaygoren.com
- genesisbehaviorcenter.com
- www.auditsi.com
- www.tratedu.net
- beachesbrewing.com
- howardsteeves.com
- patriot.ch
- villaturri.it
- www.kiteschule-kiel.de
- www.sevgiliyevideo.net
- www.kidnuri.com
- adacu.org
- www.guaitoli.eng.br
- arhometutor.com
- sidexsideaudio.com
- awkontrakt.pl
- www.w3.org
- purl.org
- ns.adobe.com
- frigosztufi.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report