MALICIOUS — 88660265765.pdf
MALICIOUS — 88660265765.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fa9b53db36191987c9737617dc0c9f6a834307c5c87530ba0af06538a89d0653 - SHA-1:
0a58d31bee4913d6b99a6726ab591d3f5415ed87 - MD5:
41e409757f11ddb73e5f10de4d951116 - ssdeep:
1536:DAfBlf3HCVOBgv9B37vHn3jysppdr4WmU44gNozpEOrVWOpOZCH0:cfBlf3JBgv9B37vHTyspp1O/oF1+Zj - TLSH:
T15538BFE361E7DE4C76975F835AFB119CA04DDB886272EAA00088BA6CD53C17DBF04511 - Submitted as: 88660265765.pdf
- File type: pdf · Size: 78319 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/7d4be31eed581f6fc14c6bdbbd7a6bc2/82226988948.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://mobilesamara.com/img/files/file/59002976393.pdf, https://earthchartercities.org/wp-content/plugins/formcraft/file-upload/server/content/files/1612955afb991c---15538614114.pdf, https://boldvision.tv/wp-content/plugins/formcraft/file-upload/server/content/files/160ecaaf7c8c74---ganepuxakosodovoxexizaz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/S30rS-6n6vg/uplcv?utm_term=work+environment+definition+pdf
- http://mobilesamara.com/img/files/file/59002976393.pdf
- https://earthchartercities.org/wp-content/plugins/formcraft/file-upload/server/content/files/1612955afb991c---15538614114.pdf
- https://boldvision.tv/wp-content/plugins/formcraft/file-upload/server/content/files/160ecaaf7c8c74---ganepuxakosodovoxexizaz.pdf
- https://shiprapublication.com/uniformkontakt/userfiles/image/files/zojadevikusedifivasoke.pdf
- https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/7d4be31eed581f6fc14c6bdbbd7a6bc2/82226988948.pdf
- http://3bbb.fr/ckeditor/upload/files/98988419079.pdf
- https://www.charityweiss.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609c77e17431c---jemazinok.pdf
- http://www.scmphotography.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16076c2c770311---vekalepebijojag.pdf
- https://rdsdealers.com/ckfinder/userfiles/files/23550604899.pdf
- https://realestateconnect.us/wp-content/plugins/super-forms/uploads/php/files/tv7k0d83alanmio0ls5ica0j46/54479990892.pdf
- http://atthaya.com/file_media/file_image/file/fefusetubaj.pdf
- http://miamiwars.pl/wp-content/plugins/super-forms/uploads/php/files/131bbc946ee6fa0fcd24741c9d209044/rokufezigitofeji.pdf
- http://www.colegiometa.net/home/wp-content/plugins/formcraft/file-upload/server/content/files/16123b89485a86---25585891261.pdf
- http://arunimaflavours.com/userfiles/file/85835988291.pdf
- https://www.travelticket.com.au/wp-content/plugins/super-forms/uploads/php/files/592f37ofacga01ikceb9i8dkgh/31925153511.pdf
- http://dorrstrechy.cz/UserFiles/File/63112139581.pdf
- http://xfswchem.com/upload/files/7403944270.pdf
- http://bandenplaats.nl/cmsimages/file/tuxosukifukanafoxigudosoz.pdf
- https://sdyh.gr/wp-content/plugins/super-forms/uploads/php/files/e2hg5lo4kvhbgb81pmh9atuo03/79397400228.pdf
- https://ietc-oman.com/userfiles/files/64947192467.pdf
- https://yuktiedu.com/wp-content/plugins/super-forms/uploads/php/files/1dfac92189694e085cf3132131954f4a/ruzowanamevilokowe.pdf
- http://turnwealthy.com/ckfinder/userfiles/files/zisadatupat.pdf
- http://bizwd.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b56b8d16631---58126344954.pdf
- https://broadstripe.com/wp-content/plugins/super-forms/uploads/php/files/587effaab597b825fa829c007cc58b3d/28043859149.pdf
Embedded domains
- feedproxy.google.com
- mobilesamara.com
- earthchartercities.org
- boldvision.tv
- shiprapublication.com
- alenakovalchuk.ru
- 3bbb.fr
- www.charityweiss.de
- www.scmphotography.co.uk
- rdsdealers.com
- realestateconnect.us
- atthaya.com
- miamiwars.pl
- www.colegiometa.net
- arunimaflavours.com
- www.travelticket.com.au
- xfswchem.com
- bandenplaats.nl
- ietc-oman.com
- yuktiedu.com
- turnwealthy.com
- bizwd.com
- broadstripe.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report