MALICIOUS — 66879404528.pdf
MALICIOUS — 66879404528.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d7ea0c52942c8d24a600a021062d60fe0fd1f59bac326fbb0b1f38b8994773b5 - SHA-1:
6366ad8dc75315688dd3000390411a109c9d4c40 - MD5:
b9f42b037f611ec3b83f3f3bcc0e2962 - ssdeep:
1536:l01g47wDWGd//BjbdCu3gWeflQlc2hdis/alWYqIz67C0zqCisgvXG0WApO6Mtq:SwtVGlN2hgs/aB61zqCirvWD6P - TLSH:
T1EC38CFF321DBDE4C370F8B1365E615A9604DD78C2266FF5041987A6CCABCABD6A00B50 - Submitted as: 66879404528.pdf
- File type: pdf · Size: 83593 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://donateagift.eu/userfiles/file/faverovabemizovelotomenu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://laborke.ru/uplcv?utm_term=status+asthmaticus+in+pediatrics+pdf, https://spazmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607769667806c---19955635676.pdf, http://aucoindeshalles.com/menu/file/47218806374.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://laborke.ru/uplcv?utm_term=status+asthmaticus+in+pediatrics+pdf
- https://spazmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607769667806c---19955635676.pdf
- http://aucoindeshalles.com/menu/file/47218806374.pdf
- http://donateagift.eu/userfiles/file/faverovabemizovelotomenu.pdf
- https://nuregio.de/wp-content/plugins/formcraft/file-upload/server/content/files/160aa6417bbd68---56117983564.pdf
- https://vayamcs.com/content_files/files/81889792422.pdf
- http://shrlie.com/upload_fck/file/2021-8-25/20210825152840929786.pdf
- http://northwestpixie-bobs.com/clients/e/e1/e1941a3904c49320334fd90e0ed9e852/File/18040520107.pdf
- http://lmalaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/lezumesirod.pdf
- https://www.rogierstoel.nl/wp-content/plugins/super-forms/uploads/php/files/pl5d3asj00f1c209tphcvi8imp/71783858373.pdf
- http://jingluo.net/uploadfiles/files/tugemode.pdf
- https://www.guestquesttravelmedia.com/wp-content/plugins/super-forms/uploads/php/files/rg2b96nmccc6tggo2ghn0ks392/wapudotepo.pdf
- https://thriveelearning.com/wp-content/plugins/super-forms/uploads/php/files/29c053eca63ae9c945a7b20fae873a94/4546428503.pdf
- http://indecomavo.pl/inc/80086032069.pdf
- http://aucoindeshalles.com/menu/file/16951183131.pdf
- https://canvasations.com/wp-content/plugins/super-forms/uploads/php/files/jo61t72gqgk8i1pbgvvtvkv347/76284326668.pdf
- http://www.logomarcanet.com/userfiles/file/zejixopudekuvefelod.pdf
- http://fine-cottage.ru/userfiles/file/juwabozufipuritadive.pdf
- https://wilocom.ro/ckfinder/userfiles/files/jakuvoliduxenu.pdf
- http://workprohealth.com/wp-content/plugins/formcraft/file-upload/server/content/files/160715bf55eb9b---pezitojodov.pdf
- https://best-turbos.com/wp-content/plugins/super-forms/uploads/php/files/2ce900a8c71d7af239d0c9137e1b4a9d/69375186424.pdf
- http://www.expertnutritionadvisor.com/wp-content/plugins/formcraft/file-upload/server/content/files/16112f2b9325ad---62243636673.pdf
- http://3qbuy.com/CKEdit/upload/files/rajigot.pdf
- http://www.onlinetemsilci.com/wp-content/plugins/formcraft/file-upload/server/content/files/160766828ce823---66571992832.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- laborke.ru
- spazmedia.com
- aucoindeshalles.com
- donateagift.eu
- nuregio.de
- vayamcs.com
- shrlie.com
- northwestpixie-bobs.com
- lmalaw.com
- www.rogierstoel.nl
- jingluo.net
- www.guestquesttravelmedia.com
- thriveelearning.com
- indecomavo.pl
- canvasations.com
- www.logomarcanet.com
- fine-cottage.ru
- workprohealth.com
- best-turbos.com
- www.expertnutritionadvisor.com
- 3qbuy.com
- www.onlinetemsilci.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report