MALICIOUS — wafizepafowedudof.pdf
MALICIOUS — wafizepafowedudof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
082a29ca8b73f50915f13e516e37ca743fb443ffab6d7d2545129a74d23a038f - SHA-1:
1b25d25d010c9c9702c7747196cc39a36d65cad4 - MD5:
6b7a353971aefea29c75d9c50b2cb1ff - ssdeep:
1536:F1fAuUpzXOYHq4s9/j4063Xg9jJsa85g9PaG6Sc6vzT/3vqHORgmQWWCpOViz3Dy:ItpHKF0HyJ2gJawc8/qHOCDViNUZ5 - TLSH:
T1303BD1F710C7ED8C7687DB83699A11BCA449E3483162E6800588FABCD97C9BC7F14961 - Submitted as: wafizepafowedudof.pdf
- File type: pdf · Size: 107209 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://kimhoatra.vn/upload/fckimagesfile/mukenupelire.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://irlanc.ru/uplcv?utm_term=margo+as+the+world+turns, https://www.waterlooarmsnewforest.co.uk/wp-content/plugins/super-forms/uploads/php/files/ed43313f20d049b97294c4a4c56ed292/rupipebagojaferatesetem.pdf, http://alnadaoil.com/userfiles/file/xomekesotovu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://irlanc.ru/uplcv?utm_term=margo+as+the+world+turns
- https://www.waterlooarmsnewforest.co.uk/wp-content/plugins/super-forms/uploads/php/files/ed43313f20d049b97294c4a4c56ed292/rupipebagojaferatesetem.pdf
- http://alnadaoil.com/userfiles/file/xomekesotovu.pdf
- https://media-get.ru/userfiles/files/bukanodagagu.pdf
- https://iamluno.com/wp-content/plugins/formcraft/file-upload/server/content/files/160aad3ce36cba---5634090043.pdf
- http://chingyi.tw/userfiles/files/ziborebifujokon.pdf
- https://kalatranslation.co.uk/wp-content/plugins/super-forms/uploads/php/files/jel548jn758qlueic938ap7bvd/56249589948.pdf
- http://wadirumshootingstars.com/userfiles/file///65852650117.pdf
- https://tedvandergulik.nl/userimages/file/sapokinipugurakuwal.pdf
- http://kimhoatra.vn/upload/fckimagesfile/mukenupelire.pdf
- https://amenajarisiconstructii.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16084a87b363ff---11937258284.pdf
- https://joefairless.com/wp-content/plugins/super-forms/uploads/php/files/89fe398f48a4da3e30cc9ec76b70c1b1/wodupifoterilolotorogunaw.pdf
- http://teraval.cz/res/file/najonizega.pdf
- http://dangkyidol.com/wp-content/plugins/super-forms/uploads/php/files/fk7ah7taj9g8esdvudq2c73vjl/barevijexule.pdf
- http://botanicgardenscafe.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1608d872838839---15575063582.pdf
- http://samuiluxurytravel.com/Uploads/file/gorejiletal.pdf
- https://www.ciabrini-immobilier.com/wp-content/plugins/super-forms/uploads/php/files/co1ohq29ut1ua2lvk3h3fk2bfi/27468205037.pdf
- http://maidnheaven.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607378ba4f436---roxetefu.pdf
- https://auf.vn/wp-content/plugins/super-forms/uploads/php/files/jhflrpdrt1e8bpuqvqh0a8evk6/waxapizajetil.pdf
- http://qtjdb.com/UploadFile/2021/05/17/file/20210517_193221_176.pdf
- https://ambient-interier.cz/files/files/49161407640.pdf
- http://jl-vacuum.com/upload/files/36825939945.pdf
- https://nanyangtextile.com/userfiles/file/94315178985.pdf
- https://renfrewareahealthvillage.ca/ckfinder/userfiles/files/pivujoxu.pdf
- http://geology.ie/wp-content/plugins/formcraft/file-upload/server/content/files/160b5df5f86a73---31381411657.pdf
Embedded domains
- irlanc.ru
- www.waterlooarmsnewforest.co.uk
- alnadaoil.com
- media-get.ru
- iamluno.com
- chingyi.tw
- kalatranslation.co.uk
- wadirumshootingstars.com
- tedvandergulik.nl
- joefairless.com
- dangkyidol.com
- botanicgardenscafe.com.au
- samuiluxurytravel.com
- www.ciabrini-immobilier.com
- maidnheaven.com
- qtjdb.com
- jl-vacuum.com
- nanyangtextile.com
- renfrewareahealthvillage.ca
- piemonteforyou.it
- cbelmira.com
- www.w3.org
- purl.org
- ns.adobe.com
- kimhoatra.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report