MALICIOUS — 20210801011518.pdf
MALICIOUS — 20210801011518.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
f5750a796bf35ae80cd4b109f793f4dac144d61cb6639c3e654e461429557597 - SHA-1:
6198a8181d154fc2882cb4b024d97b03eda011d2 - MD5:
04131a5a53b68560a55f69f5ab842ff4 - ssdeep:
1536:SNVjUkyeJ/XeCQ/I1b4uB7pukfD1uV3KLg9woA584e3dBNME+WPZM4tbqRcWepO3:KUkLJ/uCZ1B7L7zB9adBaEnMeORpynU - TLSH:
T1043AE0F351ABDE8C36AA8B0395FA215D944AE7983121EB10808CF73CD5BC6BD7B10611 - Submitted as: 20210801011518.pdf
- File type: pdf · Size: 94818 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=respiratory+mechanics+of+covid-19+vs.+non-covid-19+associated+acute+respiratory+distress+syndrome, http://csc028.com/userfiles/file/20210610161745_4rvgnk.pdf, http://halvani.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e3ffecbb1cd---11465648466.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/uplcv?utm_term=respiratory+mechanics+of+covid-19+vs.+non-covid-19+associated+acute+respiratory+distress+syndrome
- http://csc028.com/userfiles/file/20210610161745_4rvgnk.pdf
- http://halvani.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e3ffecbb1cd---11465648466.pdf
- https://www.expoagrogto.com/wp-content/plugins/super-forms/uploads/php/files/imhj83l2crjlvp97kjlpn6q7s0/gaziwe.pdf
- https://abeess.com/userfiles/file/gowabativemumarovifa.pdf
- http://s8radziejowice-paszkow.pl/userfiles/file/gipamizuko.pdf
- http://j1medical.com/uploaded/file/77939555513.pdf
- http://havefuntogether.com/image/upload/File/lazufora.pdf
- https://realimpacto.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160ac41815fc1d---wixibavilosivore.pdf
- https://husvagnsexpo.se/wp-content/plugins/formcraft/file-upload/server/content/files/160b32e1d0653e---pewixalunovifitotile.pdf
- http://aodaibooking.com/FileData/ckfinder/files/20210731_335C0860FC69CC29.pdf
- https://coastalstudio.com/images/main/file/kewis.pdf
- http://sbkf.org/files/files/13678666578.pdf
- https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/389719d66e51ec3cdbc7c9d3529ada1f/74199846003.pdf
- http://fullcolorspandoeken.nl/userfiles/file/98259386090.pdf
- https://harpethvalleyhealth.com/wp-content/plugins/super-forms/uploads/php/files/7436ead83885548002551cc45cf25a13/85764551759.pdf
- https://alatheir.com/atheirwsfiles/file/72250009601.pdf
- https://gk-termopanel.ru/wp-content/plugins/super-forms/uploads/php/files/5bf3908b1adfb86c1e516f71d6c12526/sodaxos.pdf
- http://www.supercarrentalsofmiami.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608e0e62bc226---vuwam.pdf
- https://client-sms.com/ckfinder/userfiles/files/22871338987.pdf
- http://paradisoseminatrici.it/userfiles/files/vufojino.pdf
- http://csc021.com/userfiles/file/20210704215614_zgnkds.pdf
- https://postscriptproductions.com/wp-content/plugins/formcraft/file-upload/server/content/files/16070b434d0d1b---9175959147.pdf
- http://mevlanaasm.com/resimler/files/tagujudazamu.pdf
- http://www.klpreschool.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608cd1b8d4575---figawudidajavemozorixugo.pdf
Embedded domains
- medvor.ru
- csc028.com
- halvani.com
- www.expoagrogto.com
- abeess.com
- s8radziejowice-paszkow.pl
- j1medical.com
- havefuntogether.com
- realimpacto.com.br
- husvagnsexpo.se
- aodaibooking.com
- coastalstudio.com
- sbkf.org
- otdelkamos.ru
- fullcolorspandoeken.nl
- harpethvalleyhealth.com
- alatheir.com
- gk-termopanel.ru
- www.supercarrentalsofmiami.com
- client-sms.com
- paradisoseminatrici.it
- csc021.com
- postscriptproductions.com
- mevlanaasm.com
- www.klpreschool.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report