MALICIOUS — 60870451437.pdf
MALICIOUS — 60870451437.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dfc61283a296c5843aab116f67dbb84f9ee59fded8c0182c376bcf7e25e37137 - SHA-1:
e1ddee370bf09aec37876e72158a6a26c272a0d4 - MD5:
3893d9e111a3f23402d48a11d4f7b28d - ssdeep:
3072:yZQlx6uV4K2MSorobwzzythWwr+LCCbao:yZexD2MFMbw67UCCz - TLSH:
T1973AD0F3609BDD1C778F5F536AEA51A8604AD3882172DA50808CBBBC84BCA7E6F14540 - Submitted as: 60870451437.pdf
- File type: pdf · Size: 101190 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://abwlondonblvd.com/uploads/files/raxaraxazufajov.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://schmitz.cz/res/file/wefuresejumawudomo.pdf, https://hobbes-group.com/upload/files/kegebi.pdf, https://www.makathastaliklari.net/wp-content/plugins/formcraft/file-upload/server/content/files/16070ed320c46c---vazabewa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1KS0DP0cxss/uplcv?utm_term=used+to+be+used+to+get+used+to+rules+pdf
- https://schmitz.cz/res/file/wefuresejumawudomo.pdf
- https://hobbes-group.com/upload/files/kegebi.pdf
- https://www.makathastaliklari.net/wp-content/plugins/formcraft/file-upload/server/content/files/16070ed320c46c---vazabewa.pdf
- https://smoothnomad.com/wp-content/plugins/super-forms/uploads/php/files/nc7vjfjhjirod44uahflpfo1tb/61309625237.pdf
- https://carparts-fixture.com/file/file/xidev.pdf
- https://www.toptalentusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c66d81c606d---49640552837.pdf
- http://scoutpate.com/userfiles/file/63804778730.pdf
- http://unipell.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160c5094eb30c0---49023218424.pdf
- http://abwlondonblvd.com/uploads/files/raxaraxazufajov.pdf
- https://latework.cz/soubory/gotar.pdf
- http://salocchi.it/userfiles/files/kadewagaba.pdf
- https://dacoma.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160878cd3a7b66---zerunebifipodofexed.pdf
- http://www.bridalchapel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a0c22d3fc46---kesakivo.pdf
- http://studiofapas.it/userfiles/files/9804516596.pdf
- http://www.primalegal.eu/wp-content/plugins/super-forms/uploads/php/files/d8m4a3h6lkl0qu314vig48au27/soberezo.pdf
- http://minhtoangalaxyhotel.vn/app/webroot/files/ckfinder/files/visoderikup.pdf
- https://soba05.org/wp-content/plugins/super-forms/uploads/php/files/0805bff002f624de86ca28cc177192d3/32629877756.pdf
- https://2acontractor.it/images/file/kesokemetat.pdf
- http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ce5060d8bd---38374889274.pdf
- http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/n5lt9keck3osfg5oao9nrf9383/25624772213.pdf
- http://opalsolar.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1608d87d9254cb---76516466518.pdf
- http://avtokapriz42.ru/userfiles/file/zujakofuwiginapimo.pdf
- http://becskeicsodajo.hu/admin/fck_upload/file/kovobodalomiwiwupepojijaz.pdf
- http://buergerforum-tirol.at/file/nodoxugemadekag.pdf
Embedded domains
- feedproxy.google.com
- hobbes-group.com
- www.makathastaliklari.net
- smoothnomad.com
- carparts-fixture.com
- www.toptalentusa.com
- scoutpate.com
- unipell.com.br
- abwlondonblvd.com
- salocchi.it
- www.bridalchapel.com
- studiofapas.it
- www.primalegal.eu
- soba05.org
- 2acontractor.it
- hellnocancershow.com
- www.sunarnuricomuisvealisverismerkezi.com
- opalsolar.com.au
- avtokapriz42.ru
- www.w3.org
- purl.org
- ns.adobe.com
- schmitz.cz
- latework.cz
- dacoma.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report