MALICIOUS — xoxufusunupugipizu.pdf
MALICIOUS — xoxufusunupugipizu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0a60298ba4cee5c4f9b167136f06c34094cf33a9844dd7895a12782eea73cb14 - SHA-1:
25a84072ceda6e459048266effc84a87b0c7f882 - MD5:
49588a749f5e1ff2251346a6ecec2da4 - ssdeep:
1536:qxRy6Hy272KIPviFfaibC6+I1WMIYligDW8pO73mE+tPh8e:UJHyFIyir7hIYligu73mEOPT - TLSH:
T15237D1F330ABDD4C7A8BCF43A9DA127D918AE78415A1EA900488B67CD57C97DBF40610 - Submitted as: xoxufusunupugipizu.pdf
- File type: pdf · Size: 73385 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://shopgraeagle.com/ckeditor/uploads/files/dileziwupazuko.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://westernstudioservice.com/admin/userfiles/file/68309927597.pdf, https://maychieuvinh.vn/upload/files/13897745309.pdf, http://clingac.es/d/files/mufixezuzuferivemetepiz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/3CAf4wW3hvY/uplcv?utm_term=hiccups+after+soda
- http://westernstudioservice.com/admin/userfiles/file/68309927597.pdf
- https://maychieuvinh.vn/upload/files/13897745309.pdf
- http://clingac.es/d/files/mufixezuzuferivemetepiz.pdf
- http://shopgraeagle.com/ckeditor/uploads/files/dileziwupazuko.pdf
- https://tonymusic.se/UserFiles/files/beriwoxafolawig.pdf
- http://twtipa.com/upfile/files/2021/09/29/jajigigitupabisox.pdf
- http://worldcar.jp/userfiles/files/wozukukisalazolowalodize.pdf
- https://satbietthu.com/luutru/files/47984123036.pdf
- http://alda.pl/ckfinder/userfiles/files/vebovurifolemexakin.pdf
- https://bamfieldrental.com/userfiles/file/97452764409.pdf
- http://netichikawaya.com/userfiles/file/76268666004.pdf
- http://www.pointcookelectrician.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1614b049bcf7fd---63736238056.pdf
- https://trucraftsmanship.com/wp-content/plugins/formcraft/file-upload/server/content/files/161523fddbcd4f---kofer.pdf
- http://hoshitorionline.com/uploads/files/66494357972.pdf
- http://dautuck.com/uploads/userfiles/file/jakabexewoxu.pdf
- https://cvenhancer.com/wp-content/plugins/super-forms/uploads/php/files/4c338c2bbce219819886660fe4eb63b2/17488193054.pdf
- http://centralgiving.com/media/userfiles/file/rawigiredaloziseli.pdf
- https://happycustomerservice.com/wp-content/plugins/super-forms/uploads/php/files/18bff4924e56a35264c4b072fcdfca9a/jigagiporibivudamev.pdf
- https://igescanada.com/ckfinder/userfiles/files/81175533791.pdf
- https://bisleriuber.genefied.co/ckfinder/userfiles/files/norigodefef.pdf
- http://ophirtonhotel.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/161437676bc376---90970681864.pdf
- https://patriot.ch/wp-content/plugins/super-forms/uploads/php/files/uj18fkmaj3viptlgca35t54s9h/mejebizut.pdf
- http://clubmaniacr.com/campannas/file/babajaju.pdf
- http://ordineveterinarivenezia.eu/userfiles/files/xabufetixijute.pdf
Embedded domains
- feedproxy.google.com
- westernstudioservice.com
- clingac.es
- shopgraeagle.com
- tonymusic.se
- twtipa.com
- worldcar.jp
- satbietthu.com
- alda.pl
- bamfieldrental.com
- netichikawaya.com
- www.pointcookelectrician.com.au
- trucraftsmanship.com
- hoshitorionline.com
- dautuck.com
- cvenhancer.com
- centralgiving.com
- happycustomerservice.com
- igescanada.com
- bisleriuber.genefied.co
- ophirtonhotel.co.za
- patriot.ch
- clubmaniacr.com
- ordineveterinarivenezia.eu
- giritrademark.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report