MALICIOUS — 64790542548.pdf
MALICIOUS — 64790542548.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e5f2c4aabb652d212333523b6b02dcecc05828605776756865bfa3580661ee91 - SHA-1:
561857de73af16ca04d31f53df2ccc6ef92c6fb7 - MD5:
50494d8b5d885203d31937516f53ea5a - ssdeep:
1536:a6nnaKNagNpVkM+yrfOx6WHFpVJdvhuFGsmkLhtXtWwJ2nFeKvICm7sOW6zdwskL:DnawaWVEbRFp3LuTmkLhPJ2Fe/Cm7sI0 - TLSH:
T1A43ADFF3519BDD4C77C69F43ADAB0069A0C6E3C87122EA90518C766C817C9BE6E10B61 - Submitted as: 64790542548.pdf
- File type: pdf · Size: 94192 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://mudrberanova.cz/userfiles/file/62764624639.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://nexxosrealty.com/userfiles/files/19802384031.pdf, http://sghr.ca/upload/ckfinder/files/90468549196.pdf, http://awfiowv.love-mrt.com/upload/files/zivawajigojalivariwuf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/ngfLrbzwjls/uplcv?utm_term=android+ui+version
- http://nexxosrealty.com/userfiles/files/19802384031.pdf
- http://sghr.ca/upload/ckfinder/files/90468549196.pdf
- http://awfiowv.love-mrt.com/upload/files/zivawajigojalivariwuf.pdf
- http://csc-0411.com/userfiles/file/20210907233534_b2mnec.pdf
- http://www.cuerpomenteyespiritu.es/wp-content/plugins/formcraft/file-upload/server/content/files/1612eb3b18db5f---97198514348.pdf
- http://ebd.su/UFD/7623/files/68869939472.pdf
- https://www.sharpeningfactory.com/wp-content/plugins/formcraft/file-upload/server/content/files/161327307b06b9---xolobaralixolakowusafi.pdf
- http://nhakhoasaigonkimcuong.com/uploads/images/files/83384661435.pdf
- http://themadthinker.com/temp/vinney/HTML/userfiles/file/84165420701.pdf
- http://mudrberanova.cz/userfiles/file/62764624639.pdf
- https://nhatthiengroup.com/files/uploaded/files/moratajawalapapakimarul.pdf
- https://sananselmo.com/wysiwygfiles/file/futejagur.pdf
- https://binarbaidtrading.com/public_html/userfiles/file/40544831105.pdf
- https://juhaszautovill.hu/userfiles/file/28180138546.pdf
- http://e3edu.vn/public/ckfinder/core/connector/php/connector.phppublic/uploadsfiles/xoserowop.pdf
- https://www.potterycommercials.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1613855371132d---wufebakipiragesava.pdf
- http://opusbiz.kr/data/editor/file/130234320613baf0b195c1.pdf
- https://kubermatkaplay.com/ckfinder/userfiles/files/finovegadedabomugupo.pdf
- http://emeraldcovepartners.com/_data/images/file/48564097721.pdf
- https://partroyfuneralhome.com/partroy/assets/file/getutofajababavaboniba.pdf
- https://www.sir.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/161428f9a2c59b---wezosotizin.pdf
- http://pro-group.ru/userfiles/files/mobenine.pdf
- https://laneopx.com/wp-content/plugins/formcraft/file-upload/server/content/files/161410e5e0c1e7---3480198787.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- nexxosrealty.com
- sghr.ca
- awfiowv.love-mrt.com
- csc-0411.com
- www.cuerpomenteyespiritu.es
- ebd.su
- www.sharpeningfactory.com
- nhakhoasaigonkimcuong.com
- themadthinker.com
- nhatthiengroup.com
- sananselmo.com
- binarbaidtrading.com
- www.potterycommercials.co.uk
- opusbiz.kr
- kubermatkaplay.com
- emeraldcovepartners.com
- partroyfuneralhome.com
- www.sir.co.uk
- pro-group.ru
- laneopx.com
- www.w3.org
- purl.org
- ns.adobe.com
- mudrberanova.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report