MALICIOUS — repop.pdf
MALICIOUS — repop.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
e1d4c83ecb12515f5301fffa6b2a716f51b2671f1bb63f94e4b27b6031fcd52c - SHA-1:
ed112cea6c67ac9d0cbbee2efa759489dda5dc61 - MD5:
d57b93d5973c22979cc9cc9db1512712 - ssdeep:
1536:LGWEhjdEhvlG4B9I+PE3JhklXnIb8uW6pOu26WrkqXg2XKT3fxrX:n3PG4B9I++hkl36mu2S6DaDfx - TLSH:
T15D38D0F76167DC5C76CBDB035AAD0298A089E7C42261EB504488BB7CC4BC8BDBF11961 - Submitted as: repop.pdf
- File type: pdf · Size: 81741 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=third+grade+grammar+worksheets+pdf, https://www.tri-or.fr/tri-or/ckfinder/userfilesfiles/57048693910.pdf, http://hyundai-baoloc.com/luutru/files/15538461420.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=third+grade+grammar+worksheets+pdf
- https://www.tri-or.fr/tri-or/ckfinder/userfilesfiles/57048693910.pdf
- http://hyundai-baoloc.com/luutru/files/15538461420.pdf
- https://laneopx.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608d97b5cf3ea---98476884719.pdf
- http://drivescuolaguida.it/userfiles/files/vajadezowivumawefa.pdf
- http://montpellier-business-plan.eu/mbp/upload/images/images/upload/ckfinder/wogajojefuniwesunuku.pdf
- http://www.naturhalles.fr/fckeditor/userfiles/file/94454515034.pdf
- http://nprofit.hk/userfiles/59104833092.pdf
- http://artospace.com/pics/file/xonaxubavovojulisuxur.pdf
- https://www.hediyevideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ff0296f32e---jedulasitobiwatibu.pdf
- https://tomaszbizon.tomaszbizon.pl/web/uploads/files/genaperuv.pdf
- http://argentum.com/wp-content/plugins/super-forms/uploads/php/files/ouqqmog2acc3nftivoc16dkl21/vakeredale.pdf
- https://avonsteel.com/UserFiles/file/77129181233.pdf
- https://besi.co/ckfinder/userfiles/files/fasupagekusonu.pdf
- https://dgaspcsm.ro/ckfinder/userfiles/files/99226884833.pdf
- http://bandenplaats.nl/cmsimages/file/40762479815.pdf
- https://afd.me.uk/wp-content/plugins/super-forms/uploads/php/files/s0l63fss2g1g2cgu619t41r90h/95106032076.pdf
- http://allmedicus.com/userfiles/file/24243649499.pdf
- https://glaze-metalart.com/upload/files/28260926749.pdf
- https://suacuacuontoanphat.com/upload/files/rabolobajimusewowa.pdf
- https://apoc.com.au/wp-content/plugins/super-forms/uploads/php/files/f42f2cb06f62eeabbd73d4bb1e09a572/jarowalokexideja.pdf
- https://vaytieudungtragop.com.vn/wp-content/plugins/super-forms/uploads/php/files/taojovqr39ggpd7qs12h8kcesv/nebovapilogetevejigajeso.pdf
- https://gearforfree.com/wp-content/plugins/super-forms/uploads/php/files/fa9rs2fe159b9pg8f5p8o4qu5j/29104051866.pdf
- https://rffsev.ru/wp-content/plugins/super-forms/uploads/php/files/5861dbd5b31e03c96556e4ade2516402/55621671609.pdf
- https://ubitanduk.com/contents//files/xizun.pdf
Embedded domains
- huntic.ru
- www.tri-or.fr
- hyundai-baoloc.com
- laneopx.com
- drivescuolaguida.it
- montpellier-business-plan.eu
- www.naturhalles.fr
- nprofit.hk
- artospace.com
- www.hediyevideo.com
- tomaszbizon.tomaszbizon.pl
- argentum.com
- avonsteel.com
- besi.co
- bandenplaats.nl
- afd.me.uk
- allmedicus.com
- glaze-metalart.com
- suacuacuontoanphat.com
- apoc.com.au
- gearforfree.com
- rffsev.ru
- ubitanduk.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report