MALICIOUS — timiguxazibitoxur.pdf
MALICIOUS — timiguxazibitoxur.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0dd84a7a738d46724492cdb8f4ac4c968f5b18773f5d904e437a25fde8a433e3 - SHA-1:
728e5ceb2908af73d0b94ae833afd8a0786f5eed - MD5:
19b2e475cfb69f6b154cf0b356b4dc81 - ssdeep:
1536:cWig1JOZMuZx9cfV4MrUyE8x4c6eg2bnHmkeggltIHO:nbO67fVxrU7kgo0gwtX - TLSH:
T10337C0F3A0A7CD8E778B5B037AAA29AC6047E3487131DA94095CB36CD47C7AD7E24510 - Submitted as: timiguxazibitoxur.pdf
- File type: pdf · Size: 76612 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://wepeweguwerixum.weebly.com/uploads/1/3/1/8/131856135/4028075.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://traffking.ru/wb?keyword=dexa%20scan%20guidelines%20osteoporosis, https://cdn-cms.f-static.net/uploads/4376371/normal_5fa803218fb5e.pdf, https://wepeweguwerixum.weebly.com/uploads/1/3/1/8/131856135/4028075.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/wb?keyword=dexa%20scan%20guidelines%20osteoporosis
- https://cdn-cms.f-static.net/uploads/4376371/normal_5fa803218fb5e.pdf
- https://s3.amazonaws.com/henghuili-files2/67748230369.pdf
- https://s3.amazonaws.com/rupatojuko/types_of_food_and_beverage_service.pdf
- https://wepeweguwerixum.weebly.com/uploads/1/3/1/8/131856135/4028075.pdf
- https://s3.amazonaws.com/kulinisokakewi/basic_bodice_block_pattern_drafting.pdf
- https://s3.amazonaws.com/sojebelevenex/how_the_leopard_got_his_spots_test.pdf
- https://uploads.strikinglycdn.com/files/66ef4497-5287-40e5-9800-ccb619d9351e/hit_man_a_technical_manual_for_independent_contractors_paladin_press_1983.pdf
- https://s3.amazonaws.com/viboxikuz/500_gallon_preformed_pond.pdf
- https://s3.amazonaws.com/pasawexawinogad/international_accounting_standards_2019.pdf
- https://cdn-cms.f-static.net/uploads/4386337/normal_5fa1932775d3e.pdf
- https://s3.amazonaws.com/wilugugo/25980010680.pdf
- https://s3.amazonaws.com/zubuwujoxom/density_word_problems_worksheet.pdf
- https://cdn-cms.f-static.net/uploads/4372361/normal_5f91f507eea19.pdf
- https://cdn-cms.f-static.net/uploads/4369774/normal_5f91ef4342a74.pdf
- https://uploads.strikinglycdn.com/files/921b4e55-e5bf-4a0c-981f-8f94f45e9f86/nine_algorithms_that_changed_the_future_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- wepeweguwerixum.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report