MALICIOUS — pakebaz.pdf
MALICIOUS — pakebaz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0b17a729133e1e5a54cd7b7dc7b85f058bbfbdcb8ca4e6daa3abd474c9fabd98 - SHA-1:
e6e62e51849baacce97409cd69ec9779b2171f3c - MD5:
c2a92cc798843e74bff2cf6a74c419fe - ssdeep:
1536:by6LRFFwZLldQ/y+RRJBr1uWGpOK8qxgWCmB2PpTnB2ICZ4cAk:2Oydn+fvr13K8qxaJpgN - TLSH:
T16A37CFF31093DD8C7B8BAB0776EA215C904BD7886261DB808188B66CD53C2BE7F14865 - Submitted as: pakebaz.pdf
- File type: pdf · Size: 76451 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://innovatepc.com/userfiles/file/99760054825.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://sh8ke.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607bb23d8a2ca---pupaxutafun.pdf, https://amenagementsoleil.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b0150506a3c---potuzoxevirutavuzodifam.pdf, http://merwepizza.com/upload/file/gapatojuned.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/BkSY9tpko7c/uplcv?utm_term=switchgear+and+protection+by+jb+gupta+pdf
- http://sh8ke.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607bb23d8a2ca---pupaxutafun.pdf
- https://amenagementsoleil.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b0150506a3c---potuzoxevirutavuzodifam.pdf
- http://merwepizza.com/upload/file/gapatojuned.pdf
- http://dtyxbpzx.com/filespath/files/20210823210913.pdf
- http://innovatepc.com/userfiles/file/99760054825.pdf
- http://aliancegroup.su/wp-content/plugins/formcraft/file-upload/server/content/files/1609ee49cc0328---zebiwejofavivemejo.pdf
- http://hani-bee.com/userfiles/files/24965672666.pdf
- http://tianfonmm.com/d/files/wikiloxugatuwovorutiwab.pdf
- http://kath-kiga-bw.de/bilder/berichte/file/28882021492.pdf
- http://bubblesoflove.net/wp-content/plugins/formcraft/file-upload/server/content/files/16091ec897581f---fobirirosuwos.pdf
- http://amoy-art.com/Upload/file/beputebugaja.pdf
- http://residenceraffaellotorino.com/userfiles/files/37239202283.pdf
- http://mwflower.com/upimagesfile///47005399474.pdf
- http://jullien38.com/ressource/site-image/files/zuwuxajijedosab.pdf
- http://savvyais.com/userfiles/file/dadolubufeximoji.pdf
- https://fiambreszav.com/wp-content/plugins/super-forms/uploads/php/files/bb37c752ab0b4e8980956babfadbf331/96328537440.pdf
- https://autotrans911.com/thread/admin/uploads/file/74059603640.pdf
- https://led7.ru/file/vasepipajedilotuz.pdf
- https://schreinerheusi.de/wp-content/plugins/formcraft/file-upload/server/content/files/160a614c5b51a8---gededakavolisiviga.pdf
- http://webs123.com/userfiles/file/90527877228.pdf
- http://www.gcsystem.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160d2a9fa0b0a4---78652349483.pdf
- http://www.mezmat.ru/ckfinder/userfiles/files/gimujub.pdf
- http://minhledtran.com/luutru/files/tirefogewumogusinapoloba.pdf
- http://atrsara.ir/resource/files/ziletagoveluzo.pdf
Embedded domains
- feedproxy.google.com
- sh8ke.com
- amenagementsoleil.com
- merwepizza.com
- dtyxbpzx.com
- innovatepc.com
- aliancegroup.su
- hani-bee.com
- tianfonmm.com
- kath-kiga-bw.de
- bubblesoflove.net
- amoy-art.com
- residenceraffaellotorino.com
- mwflower.com
- jullien38.com
- savvyais.com
- fiambreszav.com
- autotrans911.com
- led7.ru
- schreinerheusi.de
- webs123.com
- www.gcsystem.pl
- www.mezmat.ru
- minhledtran.com
- atrsara.ir
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report