MALICIOUS — 35994752385.pdf
MALICIOUS — 35994752385.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f055b84048971bf1158d660820f226e2e4e09ceda35d3a6569a96a821ed9f9ae - SHA-1:
2fe5fd1899d794bc5a34222adb76600c83857328 - MD5:
e74f5e652156faf8e1b3d27d9139bb4c - ssdeep:
1536:X9avxB7lSAmyy2MhsPQF+ZugylFIrQSp9Pifq3kBWHjM8nKktZWbpONde4YqSaM:tmd4R2MhDIZugylFSvis5nKktbNc1qe - TLSH:
T17739D0F36497DD8CBB4B9F13A9F60198A44ED6486152F650004CBABC85BC47E7F10E62 - Submitted as: 35994752385.pdf
- File type: pdf · Size: 84934 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://swagath.co/new/ckfinder/userfiles/files/zunirazominatoxot.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://www.techsrollout.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a6b90a2c6b4---kunamosebamixijajuvabufe.pdf, https://alliance-ic.ru/uploads/file/gifejo.pdf, https://ols.lighting/wp-content/plugins/super-forms/uploads/php/files/46494db911d28b141abc4182c3e58ee9/bokasuburojiwolemuvubagin.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/fzgW7-mxBc0/uplcv?utm_term=maths+worksheets+for+grade+5+igcse
- https://www.techsrollout.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a6b90a2c6b4---kunamosebamixijajuvabufe.pdf
- https://alliance-ic.ru/uploads/file/gifejo.pdf
- https://ols.lighting/wp-content/plugins/super-forms/uploads/php/files/46494db911d28b141abc4182c3e58ee9/bokasuburojiwolemuvubagin.pdf
- https://swagath.co/new/ckfinder/userfiles/files/zunirazominatoxot.pdf
- https://www.fliesen-brill.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609a016b18ef7---filibakug.pdf
- https://studiogeologicotrilobite.com/userfiles/files/majunemusugajepidizi.pdf
- https://spencershaulageltd.co.uk/wp-content/plugins/super-forms/uploads/php/files/e1d97b92ea436b39c55a5944413d6b98/sezudulolani.pdf
- https://csc-0898.com/userfiles/file/20210620150428_w8u640.pdf
- https://www.modianodesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/160977cb934226---33759623179.pdf
- https://www.modianodesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ccff06ed3d---saxefamevibudirolovala.pdf
- https://www.a-fairys-choice.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a5ce5ca72ec---vozejanamibemu.pdf
- https://cgpreceptor.com/ckfinder/userfiles/files/kuvuvubebojivonigolurutid.pdf
- https://geologocarmignani.com/userfiles/files/selezox.pdf
- https://niestachow.pl/data/aktualnosci_imgs/file/wedevalodituvawaz.pdf
- https://www.inkfactory.pk/wp-content/plugins/formcraft/file-upload/server/content/files/1607d77dda218b---17956784255.pdf
- https://luxcottage.ru/stroykamen/userfiles/files/wujatuvom.pdf
- https://connect.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/e4abdecf585204478fa0d26ea888bcdc/81827465405.pdf
- https://jadever.vn/Images_upload/files/84599640599.pdf
- https://jonkmp.nl/img/cms/file/24773044484.pdf
- https://ph2020.org/ckfinder/userfiles/files/zagagalepolimafebusizu.pdf
- https://www.anclupnapoli.it/userfiles/file/newoxedimemofira.pdf
- https://www.adelaarenergy.com/wp-content/plugins/super-forms/uploads/php/files/muutmhr5nnqhq95kgvhi6f72bg/sarenirufa.pdf
- https://www.w3.org/1999/02/22-rdf-syntax-ns#
- https://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- www.techsrollout.com
- alliance-ic.ru
- swagath.co
- www.fliesen-brill.de
- studiogeologicotrilobite.com
- spencershaulageltd.co.uk
- csc-0898.com
- www.modianodesign.com
- www.a-fairys-choice.com
- cgpreceptor.com
- geologocarmignani.com
- niestachow.pl
- luxcottage.ru
- connect.allianceflooring.net
- jonkmp.nl
- ph2020.org
- www.anclupnapoli.it
- www.adelaarenergy.com
- www.w3.org
- purl.org
- ns.adobe.com
- ols.lighting
- www.inkfactory.pk
- jadever.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report