MALICIOUS — 16088a219b1c3a---gitebixufe.pdf
MALICIOUS — 16088a219b1c3a---gitebixufe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
044f73e4d419dddfd729c49a5e576f92032486acd17e09a3df3437e2d14345e1 - SHA-1:
243a77e846c19e56343f3cba241e2ebfe8d12bf3 - MD5:
fd612413d984369b0cd7af8b97fd430c - ssdeep:
1536:ANb9ShxEkYwveU4NTjcDX/c7/IKygbAtgS1hh47xZ10:m9gxEkYOeLNTITI/IKA+Yhh47xI - TLSH:
T14137C0F3629BDE4D6F46AF077B6A10392049D2886073A6148488BFACC4F4B7C7E24955 - Submitted as: 16088a219b1c3a---gitebixufe.pdf
- File type: pdf · Size: 70112 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!FD612413D984
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://travelselection.us/wp-content/plugins/formcraft/file-upload/server/content/files/1608852277842a---zesetovenuvow.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://maugli24.ru/wp-content/plugins/super-forms/uploads/php/files/28ed918ab70978bd59cb82fb66d75f29/jokasoretasukakumolek.pdf, https://travelselection.us/wp-content/plugins/formcraft/file-upload/server/content/files/1608852277842a---zesetovenuvow.pdf, https://binhruamuinanobac.com/wp-content/plugins/super-forms/uploads/php/files/gpesncahkjpujplqfe7057l30i/85959658873.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/YTWXjIUwRh0/uplcv?utm_term=clergy+housing+allowance+worksheet+2018+irs
- https://maugli24.ru/wp-content/plugins/super-forms/uploads/php/files/28ed918ab70978bd59cb82fb66d75f29/jokasoretasukakumolek.pdf
- https://travelselection.us/wp-content/plugins/formcraft/file-upload/server/content/files/1608852277842a---zesetovenuvow.pdf
- https://binhruamuinanobac.com/wp-content/plugins/super-forms/uploads/php/files/gpesncahkjpujplqfe7057l30i/85959658873.pdf
- https://genesisbehaviorcenter.com/wp-content/plugins/super-forms/uploads/php/files/6bdad5b9754dbbefef5aaf4cb99d9213/lewiveniloledemato.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/r8af0c22442c2998u9ik4s86k2/nogufuzojuzereke.pdf
- https://refundsrefunds.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607dde701efb4---jorajisunax.pdf
- https://www.hdcorp.com.br/wp-content/plugins/super-forms/uploads/php/files/67cdkepto26pf40od74q3p9sjj/39849482322.pdf
- http://jockmurray.com/wp-content/plugins/formcraft/file-upload/server/content/files/160710bc8ba54c---34940059900.pdf
- https://dmvassociates.com/wp-content/plugins/super-forms/uploads/php/files/9d8da4fae94e1eb36575f0d304fb75be/73097547903.pdf
- http://www.birapart.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607d6d6e86894---88657653561.pdf
- http://www.playerclub.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1607f6cb67ee92---waxenuwezanepojarip.pdf
- https://olgapopovaphoto.com/wp-content/plugins/super-forms/uploads/php/files/eedc74cadc3f38e01333464cedf98eaf/77641077536.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- maugli24.ru
- travelselection.us
- binhruamuinanobac.com
- genesisbehaviorcenter.com
- www.nuricomuvakfi.org
- refundsrefunds.com
- www.hdcorp.com.br
- jockmurray.com
- dmvassociates.com
- www.birapart.com
- olgapopovaphoto.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.playerclub.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report