MALICIOUS — 76697302163.pdf
MALICIOUS — 76697302163.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
e0306f92f48490251d493e17148e3489f6f3eba96efce30cf598c3d6892eb32a - SHA-1:
8a983c35e497a7855fb32ee746ea0fccd0ed73f5 - MD5:
604f2ce115d9967e5bb1a5c0dd8729cb - ssdeep:
1536:/eJaGLvTEtIxpGavuIHzMpEx+qoTnYUfSRWxuUNAyKeW8pO+mu62TUdV:2UMqQMkQpECTY52u5x5+PlyV - TLSH:
T1FF39D1F36197DD1C769BAB0369EB02BC544AD3CC2162EBA44848BB6CD07C67CAF14251 - Submitted as: 76697302163.pdf
- File type: pdf · Size: 89663 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://www.skyline-recruiting.com/wp-content/plugins/super-forms/uploads/php/files/d83a4c8117ee462d99eee9a2b3661c0e/logon.pdf, https://www.fifatravels.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071ce95b842d---kiwuganubasalibirip.pdf, http://piau-po21inn.com/CKEdit/upload/files/52856963943.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/S30rS-6n6vg/uplcv?utm_term=aviation+vocabulary+for+pilots+pdf
- https://www.skyline-recruiting.com/wp-content/plugins/super-forms/uploads/php/files/d83a4c8117ee462d99eee9a2b3661c0e/logon.pdf
- https://www.fifatravels.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071ce95b842d---kiwuganubasalibirip.pdf
- http://piau-po21inn.com/CKEdit/upload/files/52856963943.pdf
- http://www.ellisrasbetonwerke.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/16070df0d66dd6---gavaperunexuto.pdf
- http://szao-spb.ru/images/news/file/62286109041.pdf
- http://www.pointcookelectrician.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160fdd19d46713---30735158968.pdf
- http://namuvaldymas.lt/userfiles/file/23355247707.pdf
- https://gulceoyunlar.com/calisma2/files/uploads/83847048200.pdf
- https://markaoyun.com/calisma2/files/uploads/susezida.pdf
- https://reifenscho.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607b607377629---47881697151.pdf
- http://www.jfac.kr/ckfinder/userfiles/files/35959080309.pdf
- http://ontheedgeofnow.com/wp-content/plugins/formcraft/file-upload/server/content/files/16099ced36ca05---mapavibas.pdf
- https://flyingfish-stay.com/userfiles/file/48936483447.pdf
- http://kayamedbursa.com/userfiles/file/58821721547.pdf
- https://nowackleverkusen.de/wp-content/plugins/formcraft/file-upload/server/content/files/16091f4d2f0d6f---fulagawekasibeg.pdf
- http://www.next-conseil.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160abf6eca094f---19532686549.pdf
- https://cuatudongsaigon.vn/uploads/files/41904037237.pdf
- http://abworder.com/uploads/files/xapazuxokakof.pdf
- https://vallejardin.com/wp-content/plugins/super-forms/uploads/php/files/d1ef4446304c0ed47bf1aa007a3b9111/41980624461.pdf
- http://associatedreclaimed.reclaimedoils.com/userfiles/files/32499313662.pdf
- https://cremeconferences.com/wp-content/plugins/super-forms/uploads/php/files/84674bbd878ca0489cd342f1755c12b6/67151765904.pdf
- https://cncunse.com/d/files/40153247834.pdf
- https://binarbaidequipment.com/public_html/userfiles/file/kibajomudo.pdf
- https://tlpnw.com/wp-content/plugins/super-forms/uploads/php/files/366c8946b8167c1b08507d8039c3864b/24906730048.pdf
Embedded domains
- feedproxy.google.com
- www.skyline-recruiting.com
- www.fifatravels.com
- piau-po21inn.com
- www.ellisrasbetonwerke.co.za
- szao-spb.ru
- www.pointcookelectrician.com.au
- gulceoyunlar.com
- markaoyun.com
- reifenscho.de
- www.jfac.kr
- ontheedgeofnow.com
- flyingfish-stay.com
- kayamedbursa.com
- nowackleverkusen.de
- www.next-conseil.fr
- abworder.com
- vallejardin.com
- associatedreclaimed.reclaimedoils.com
- cremeconferences.com
- cncunse.com
- binarbaidequipment.com
- tlpnw.com
- glory-aqua.com
- www.iqubz.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report