MALICIOUS — mutanel.pdf
MALICIOUS — mutanel.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
13370635bbbfbfc6f27f34261e533ecd0cbbcca7c12cd3838f515fcabecaa876 - SHA-1:
0e21aa557fe0a19077dd58aa1340a2d4879c8a0e - MD5:
be8acde44c947614e052f0562cfcd20e - ssdeep:
1536:z9H+eweRpuxYQ+OlVLqjgt7onNH0datYkSw0bcBpyb5vngUYWXQU+HovKAD8bF7U:lZj6R37WjPn92L7wHBmngUeIJWJcBCW - TLSH:
T1E639CFF3118BDC9CBB4BEF572DBA11ACA04DD6492271E78150C8BA2CD46C6BD6F14A40 - Submitted as: mutanel.pdf
- File type: pdf · Size: 87745 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://peaceinsrilanka.lk/userfiles/file/30146146491.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://acornschoolcharleston.org/wp-content/plugins/super-forms/uploads/php/files/6bf7974034f99a6d6a029dc4188343c4/gofagelewetebuxojimowi.pdf, http://www.britocunhaadvocacia.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/160947ff409b25---nurorukapobovo.pdf, https://dusunceokulu.net/resimler/files/pujovuwadejilimegoveti.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1KS0DP0cxss/uplcv?utm_term=do+you+ever+meaning
- https://acornschoolcharleston.org/wp-content/plugins/super-forms/uploads/php/files/6bf7974034f99a6d6a029dc4188343c4/gofagelewetebuxojimowi.pdf
- http://www.britocunhaadvocacia.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/160947ff409b25---nurorukapobovo.pdf
- https://dusunceokulu.net/resimler/files/pujovuwadejilimegoveti.pdf
- https://carparts-fixture.com/file/file/95044120577.pdf
- https://a2designbg.com/userfiles/file/nomitumixugoveki.pdf
- https://themodernla.com/wp-content/plugins/super-forms/uploads/php/files/8de9dd268476fcda510d0dfed85e17c4/wonezegesetos.pdf
- http://ladyqueen.it/userfiles/files/86778396284.pdf
- http://peaceinsrilanka.lk/userfiles/file/30146146491.pdf
- https://realwebguys.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609c2846e427b---9283633672.pdf
- http://www.wallisandemmanuel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607ef136df4a9---48529046995.pdf
- https://protechlighting.com/wp-content/plugins/super-forms/uploads/php/files/c734f639a46559b1f1941e0c3beec39e/nadigamula.pdf
- http://pvsystexperts.com/wp-content/plugins/super-forms/uploads/php/files/l851ec7vb2695pg5g6q8sqrqs1/11185095551.pdf
- https://estidevelopers.com/wp-content/plugins/super-forms/uploads/php/files/c23fbed8fc996dc012c5d499769cc000/nobumu.pdf
- http://yearbookplus.com/uploads/ckfinder/files/81508853559.pdf
- https://www.cir.cloud/wp-content/plugins/formcraft/file-upload/server/content/files/160bfb2a761561---rudogejevodov.pdf
- http://shinserviceodi.ru/wp-content/plugins/super-forms/uploads/php/files/bfaea357d8b9d6409dc7623ec5da552a/78133163008.pdf
- http://www.virtualaid.eu/wp-content/plugins/formcraft/file-upload/server/content/files/1607ef71632d21---37950281605.pdf
- http://zoncmswebsitebeheer.nl/files/editor/file/kexuditab.pdf
- https://pikewallis.no/wp-content/plugins/formcraft/file-upload/server/content/files/160b8eb1076b52---38857391237.pdf
- https://webtechnocrats.com/upload/file/tubovudevonepuzam.pdf
- http://www.deopendeur.org/imgUser/file/7688530507.pdf
- https://awlights.com/wp-content/plugins/super-forms/uploads/php/files/3c27d9d746ec6808d022acfa5ca92778/52622502587.pdf
- http://ekachaiguitarist.com/ckfinder/userfiles/files/21105021683.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- acornschoolcharleston.org
- www.britocunhaadvocacia.com.br
- dusunceokulu.net
- carparts-fixture.com
- a2designbg.com
- themodernla.com
- ladyqueen.it
- realwebguys.com
- www.wallisandemmanuel.com
- protechlighting.com
- pvsystexperts.com
- estidevelopers.com
- yearbookplus.com
- www.cir.cloud
- shinserviceodi.ru
- www.virtualaid.eu
- zoncmswebsitebeheer.nl
- pikewallis.no
- webtechnocrats.com
- www.deopendeur.org
- awlights.com
- ekachaiguitarist.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report