MALICIOUS — mojototufunapo.pdf
MALICIOUS — mojototufunapo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
015dbc696e64707401c4cf869f1f3282dcea10cbf5fd3efa5cc48cc0590cb103 - SHA-1:
5f4e8384f89922ca5c4cd71a0241234252ab677d - MD5:
0f8c19c8c1f0685dbd1168c54245bead - ssdeep:
1536:TvLg3GpnECfa7g8RLpLcAUPsHhOaK41n/EcJmrOtFXW6pOu26W74C091gD:fXpECfa7g8RLtcAUshOaKy/EcJmrAsuY - TLSH:
T15637D1F32197ED4C77868F476ABA126CE489D784A271EA9040C9773C65BC8BDBD10A00 - Submitted as: mojototufunapo.pdf
- File type: pdf · Size: 72758 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://shipsupply.ru/userfiles/files/32904985711.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://allytemp.ru/uplcv?utm_term=update+busybox+android, http://newo.ru/files/files/xomejekavezemoxela.pdf, http://ozdesignhouse.com/app/webroot/uploads/files/95967907763.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://allytemp.ru/uplcv?utm_term=update+busybox+android
- http://newo.ru/files/files/xomejekavezemoxela.pdf
- http://ozdesignhouse.com/app/webroot/uploads/files/95967907763.pdf
- http://sns.hu/_user/file/75422207778.pdf
- http://www.mecateengenharia.com.br/ckfinder/userfiles/files/56764107193.pdf
- http://aktifimmo.lu/userfiles/files/fesipotilomezidabijigelur.pdf
- http://www.expo-hotel.com/english/wp-content/plugins/formcraft/file-upload/server/content/files/161315df770358---19931134906.pdf
- http://ewhamd.net/upFiles/ckeditor/files/43573702780.pdf
- http://www.leasebridge.com/CKUPimg/files/galavafanupunadun.pdf
- http://shipsupply.ru/userfiles/files/32904985711.pdf
- http://goforthegreengolfpools.com/userfiles/file/rakebipujulogem.pdf
- http://www.39koratmachinery.com/file_upload/files/37041740323.pdf
- http://pitchdecor-construction.com/user_img/files/xawas.pdf
- https://t2sc.me/userfiles/ravozufexizexiximam.pdf
- http://www.fsnn.se/wp-content/plugins/formcraft/file-upload/server/content/files/16146b54e7248a---dimivu.pdf
- http://hankyunget.net/userData/board/file/sunafegupovo.pdf
- https://maurinet.com/userfiles/file/46985721155.pdf
- http://kahasat.cz/data/file/fikadilelixexuravafunami.pdf
- http://uitetenindex.nl/images/uploads/16538424612.pdf
- https://cepatdaftargroup2.com/contents/files/vakiduko.pdf
- http://amandatour.ru/js/ckfinder/userfiles/files/58296141219.pdf
- http://asupuro.com/upload/save_image/files/46244683635.pdf
- https://chataigne-cevennes.fr/imgs/files/doniximumijele.pdf
- https://vntdc.com/upload/fck/file/20290247682.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- allytemp.ru
- newo.ru
- ozdesignhouse.com
- www.mecateengenharia.com.br
- www.expo-hotel.com
- ewhamd.net
- www.leasebridge.com
- shipsupply.ru
- goforthegreengolfpools.com
- www.39koratmachinery.com
- pitchdecor-construction.com
- t2sc.me
- www.fsnn.se
- hankyunget.net
- maurinet.com
- uitetenindex.nl
- cepatdaftargroup2.com
- amandatour.ru
- asupuro.com
- chataigne-cevennes.fr
- vntdc.com
- www.w3.org
- purl.org
- ns.adobe.com
- sns.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report