MALICIOUS — 95857256960.pdf
MALICIOUS — 95857256960.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
f76e312cc5a52b8c56e9d620152af5589ad82fdde72416693e4d4a2c16ca9ad9 - SHA-1:
f75feea311c89aafc137cfa9794139fe9af32fac - MD5:
cbcfaff8514a16c0563172108503f4aa - ssdeep:
1536:55RlIrPtx8ZvBtYAKNU9n38etAJSNQZxNKiQlH8WwpOS9W/bbF6GJlYzEZ1Ss:DRMUZvjY1hbSsxNKh5bSYF6GJlbZT - TLSH:
T14D38CFF36087DE4C764B4B57A9DA1198B48AD3486632E690408CBBBCC4BC6BCBF05651 - Submitted as: 95857256960.pdf
- File type: pdf · Size: 82211 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://queure.ru/uplcv?utm_term=cuaderno+de+trabajo+5+grado+respuestas+leirem+contestado, http://studiomistretta.com/userfiles/files/35325968421.pdf, http://www.peplex.it/wp-content/plugins/formcraft/file-upload/server/content/files/160b343510a4fa---50301138255.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://queure.ru/uplcv?utm_term=cuaderno+de+trabajo+5+grado+respuestas+leirem+contestado
- http://studiomistretta.com/userfiles/files/35325968421.pdf
- http://www.peplex.it/wp-content/plugins/formcraft/file-upload/server/content/files/160b343510a4fa---50301138255.pdf
- http://raegcafe.com/uploads/files/44537967620.pdf
- http://extracam.es/app/webroot/arxius/file/zogowilu.pdf
- http://mmbc.cz/_data/user_files/file/40141839972.pdf
- https://bxthirteen.wpengine.com/wp-content/plugins/super-forms/uploads/php/files/db951ec65b766949df23bb2b314fd69c/79522463593.pdf
- https://desertflying.club/wp-content/plugins/formcraft/file-upload/server/content/files/16081416488590---kijifavulusefevipe.pdf
- https://na-nule.ru/wp-content/plugins/super-forms/uploads/php/files/fb38fa8b6tv4t2f7n60oe4cac7/32470109303.pdf
- https://assurancemauricie.com/wp-content/plugins/formcraft/file-upload/server/content/files/160890e9e541ee---35469046575.pdf
- http://matras-devison.com/upload/file/17443511276.pdf
- https://osikovo.eu/webroot/img/content/files/18805895619.pdf
- https://drivingschoolofnorthtexas.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a5bbfc4ddd8---85625791099.pdf
- http://manufim.co.il/wp-content/plugins/formcraft/file-upload/server/content/files/1607bb71b4d27b---xojeratofadowiwomurujafon.pdf
- https://loan-financial.com/wp-content/plugins/super-forms/uploads/php/files/0c9a6b2b150d0688fa145cb3bea6189b/tegivafar.pdf
- http://www.immiflex.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c8abb480f6---85593357225.pdf
- http://southportrubbish.com/wp-content/plugins/formcraft/file-upload/server/content/files/160beab5a86cf2---96832404935.pdf
- https://jclifeschools.org/wp-content/plugins/super-forms/uploads/php/files/733ca03218446d873e7291ebfacfc2a0/rakodo.pdf
- https://www.pharmaright.ca/wp-content/plugins/super-forms/uploads/php/files/qjng6kpegmtgf4utrj4ddbv9er/kuvusuzomew.pdf
- https://www.sir.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1606cfd50acc3c---15446296939.pdf
- http://coalcreekcentenary.com/clients/5/52/52f735e63eff8706e1a2a73a20aef632/File/xupipazuxikutujenerok.pdf
- https://aykutemlak.com/upload/ckfinder/files/wumofixopulunu.pdf
- http://bougerpourstarlight.com/clients/c/c6/c668404594a1c08d975ab50c7bec58f6/File/dobazapolejudubixuri.pdf
- https://medbillings.us/lightspeedweb1/file/17763978842.pdf
- https://www.quatainvestimentos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160de01f60c7a3---buvulepewawu.pdf
Embedded domains
- queure.ru
- studiomistretta.com
- www.peplex.it
- raegcafe.com
- extracam.es
- bxthirteen.wpengine.com
- desertflying.club
- na-nule.ru
- assurancemauricie.com
- matras-devison.com
- osikovo.eu
- drivingschoolofnorthtexas.com
- loan-financial.com
- www.immiflex.com
- southportrubbish.com
- jclifeschools.org
- www.pharmaright.ca
- www.sir.co.uk
- coalcreekcentenary.com
- aykutemlak.com
- bougerpourstarlight.com
- medbillings.us
- www.quatainvestimentos.com.br
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report