MALICIOUS — witofuto.pdf
MALICIOUS — witofuto.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
113a0f7e05c1c3fb88acc0aff6c11ac393f97641c03220263b26aa46b1bba2ba - SHA-1:
17219d75020dd30ed298bc6813146dbb13f67f35 - MD5:
931e773d376346a04df3fb3e065f8b38 - ssdeep:
1536:GMxJfoTsmB6aiEEJ1zIvR1Vq24sP4EJUMoWRElt4GaWOpOaZzmyNCHcqS3:lFQsSuEE7m1H4sP4EJMb4GPaZDNScD - TLSH:
T1F438D0F3619BDD9CA78B4F473AA621956449D39C2026EF0110C97A6CC4BC8FDBE10A51 - Submitted as: witofuto.pdf
- File type: pdf · Size: 77756 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://alfonsoguiggiarchitetto.it/userfiles/files/rajunavivegexa.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://zaun-produzent.de/userfiles/file/14564988255.pdf, http://twinmd.ru/userfiles/file/fopetunidegoturiso.pdf, http://ccsctda.com/ckfinder/userfiles/files/20210905_103854.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/zMnd8XtcwSM/uplcv?utm_term=indian+train+simulator+android
- http://zaun-produzent.de/userfiles/file/14564988255.pdf
- http://twinmd.ru/userfiles/file/fopetunidegoturiso.pdf
- http://ccsctda.com/ckfinder/userfiles/files/20210905_103854.pdf
- https://dafelia.com/files/burulerubilukajibegoji.pdf
- https://b2cexpressdemo.com/userfiles/file/12970565751.pdf
- https://futuresbuilder.net/dayafter/uploadimages/newsimages/file/silijewupebawelitito.pdf
- http://mariondhuique-mayer.com/data/file/12361755293.pdf
- http://alfonsoguiggiarchitetto.it/userfiles/files/rajunavivegexa.pdf
- http://www.commandinglife.com/wp-content/plugins/formcraft/file-upload/server/content/files/16138a37ecda6b---natanusi.pdf
- http://spellenindex.nl/images/uploads/ginevojivirawutaxoj.pdf
- https://dafelia.com/files/2833146693.pdf
- http://meta-min.com/files/42955461066.pdf
- http://thevale.us/userimages/bikuna.pdf
- http://www.gieskestukadoors.nl/ckfinder/files/files/lugerirutupidibu.pdf
- https://sunkamalzemecilik.com/userfiles/file/tumelagorixone.pdf
- http://autostyle-japan.com/js/upload/files/92988561036.pdf
- http://sualpturizm.com/userfiles/file/zufoniriniwokatafunibomen.pdf
- https://too.kg/wp-content/plugins/super-forms/uploads/php/files/dd47673c1d1993dfd6ad88e453fb9b0a/gegatuw.pdf
- http://ihdbd.org/upload/files/baragapopaxi.pdf
- https://szabobuszrendeles.hu/files/files/92800659574.pdf
- http://elfuklid.cz/foto/Image/file/pavurobupikusimokidubam.pdf
- http://compow.net/ckfinder/userfiles/files/88931057016.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- zaun-produzent.de
- twinmd.ru
- ccsctda.com
- dafelia.com
- b2cexpressdemo.com
- futuresbuilder.net
- mariondhuique-mayer.com
- alfonsoguiggiarchitetto.it
- www.commandinglife.com
- spellenindex.nl
- meta-min.com
- thevale.us
- www.gieskestukadoors.nl
- sunkamalzemecilik.com
- autostyle-japan.com
- sualpturizm.com
- ihdbd.org
- compow.net
- www.w3.org
- purl.org
- ns.adobe.com
- too.kg
- szabobuszrendeles.hu
- elfuklid.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report