MALICIOUS — xuselatas.pdf
MALICIOUS — xuselatas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0f9dae55fcd0839764477530af710ae583ae3db36037105263d81d55be8bc492 - SHA-1:
9a2e1226a0e4086af908944f51cd16a52233c496 - MD5:
93e2491ed11517e53e250223df09bec3 - ssdeep:
1536:obbcsdAv9oLs/9y0r8piWDsfV8Ytw45WOpOwrKWGuBxVqYw06hg8F34b9l23vK8:CAks/xr8piWtwr4uBxEPbhg8F34b/2 - TLSH:
T1F039C0F720E7DE8CB6C9AF035DFA10AC608AD7886562E9508588A27CD97C27E7F00551 - Submitted as: xuselatas.pdf
- File type: pdf · Size: 90252 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://1970fchs50thclassreunion.com/clients/1/19/19770213778af891f1b13fa25f964f50/File/70124943061.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://crewmak.ru/uplcv?utm_term=kendall+county+tx+criminal+case+search, http://1970fchs50thclassreunion.com/clients/1/19/19770213778af891f1b13fa25f964f50/File/70124943061.pdf, http://www.circoloaletrium.it/wp-content/plugins/formcraft/file-upload/server/content/files/160c1ba151ec41---tanusikesekanofizesetiba.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crewmak.ru/uplcv?utm_term=kendall+county+tx+criminal+case+search
- http://1970fchs50thclassreunion.com/clients/1/19/19770213778af891f1b13fa25f964f50/File/70124943061.pdf
- http://www.circoloaletrium.it/wp-content/plugins/formcraft/file-upload/server/content/files/160c1ba151ec41---tanusikesekanofizesetiba.pdf
- http://adveotec.com/img/file/25667552902.pdf
- https://www.bouldersudbury.org/wp-content/plugins/formcraft/file-upload/server/content/files/160edffa69501b---71675983275.pdf
- https://grandplaza.bg/uploads/assets/file/senepoxojoxogufuku.pdf
- https://riverasphotovideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160de70f64a0d6---20797145248.pdf
- https://led7.ru/file/nukezosanarujokufina.pdf
- https://www.charroninc.com/wp-content/plugins/super-forms/uploads/php/files/b2ef5e18d77011d68b48310255a47261/27143005626.pdf
- http://studiomontironi.eu/userfiles/files/56119193318.pdf
- https://cashmeredreams.com/wp-content/plugins/super-forms/uploads/php/files/137e20bf9238e738bd3940894911b4bc/jewilanedatajalarame.pdf
- http://rogo-rotterdam.nl/files/65807562540.pdf
- https://cedarcreeksauce.com/wp-content/plugins/super-forms/uploads/php/files/c1e5cb30880201fa10474a6a8b955149/67563803041.pdf
- http://detikakdeti.ru/img/file/22925749370.pdf
- http://soflocops.com/clients/67403/File/kudopebidavalajazusos.pdf
- https://transcendenceit.com/wp-content/plugins/super-forms/uploads/php/files/6e1b7160b20a907b0d5b0363db8d0cd6/sobitalazepu.pdf
- https://nisahanpin.com/calisma2/files/uploads/52712515846.pdf
- https://siyata.co.il/wp-content/plugins/formcraft/file-upload/server/content/files/1609b96f577527---11244612452.pdf
- https://lotteppta.com/beta/assets/file/82385633252.pdf
- http://juniorsmagazine.com/wp-content/plugins/formcraft/file-upload/server/content/files/160933c5cce26b---61490795827.pdf
- https://cristalensi.com/public/File/wozevapawixofoguzobazog.pdf
- http://akicgiyim.com/userfiles/file/dasipomo.pdf
- https://proff-doors.ru/wp-content/plugins/super-forms/uploads/php/files/ddfc4de87323e818aacf37df1cc97088/87201735289.pdf
- http://ventilyatsia-v-sochi.ru/ckfinder/userfiles/files/gejalazirekeduw.pdf
- https://alternativecarrepair.com/userfiles/file/13234070610.pdf
Embedded domains
- crewmak.ru
- 1970fchs50thclassreunion.com
- www.circoloaletrium.it
- adveotec.com
- www.bouldersudbury.org
- riverasphotovideo.com
- led7.ru
- www.charroninc.com
- studiomontironi.eu
- cashmeredreams.com
- rogo-rotterdam.nl
- cedarcreeksauce.com
- detikakdeti.ru
- soflocops.com
- transcendenceit.com
- nisahanpin.com
- lotteppta.com
- juniorsmagazine.com
- cristalensi.com
- akicgiyim.com
- proff-doors.ru
- ventilyatsia-v-sochi.ru
- alternativecarrepair.com
- www.akutrans.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report