MALICIOUS — bafopupo.pdf
MALICIOUS — bafopupo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
13fdcc95dd7b1874d520e030c682a89487cca922a49e23fd29c4a3e253b7b00c - SHA-1:
b4cc5735d1d9a5c390328be68199a06cb82d6507 - MD5:
ccce39ec7af6194eb0bd016dfd4d9829 - ssdeep:
1536:ym151KGkp1nAMMTzH77pqUN53fcegEkDGWkNpOP7sRPaWKjPGW8p0U:5vkppAlvEUnf0bP7sRPMjPgd - TLSH:
T13D39DFF320A7DC9C7797DF0329BA21A860CAD78CA462E7514188736CC07C6BDBE14652 - Submitted as: bafopupo.pdf
- File type: pdf · Size: 84756 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://dok-vo.ru/userfiles/file/97090535930.pdf, https://jdlpartnerss.com/userfiles/file/55741319568.pdf, https://latrinquette.com/upload/editor/file/53062525327.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/YTWXjIUwRh0/uplcv?utm_term=sikuli+manual+pdf
- http://dok-vo.ru/userfiles/file/97090535930.pdf
- https://jdlpartnerss.com/userfiles/file/55741319568.pdf
- https://latrinquette.com/upload/editor/file/53062525327.pdf
- https://fanaf.org/article_ressources/file/lipazel.pdf
- http://chicagohalo.com/wp-content/plugins/formcraft/file-upload/server/content/files/16079968566488---bokexukepatasova.pdf
- http://ahcxdq.com/uploads/file/041206114899.pdf
- https://cms.blauraum.com/wp-content/plugins/super-forms/uploads/php/files/f4c0f13b8b3f75643f7313c32f1bde71/30093795481.pdf
- https://studio45.live/wp-content/plugins/super-forms/uploads/php/files/udjlo7mu79javnvgl9n76s316p/julelugodikakavurere.pdf
- http://vitrine-prof.com/files/wosomopexaporixamibe.pdf
- https://www.tangelo.no/wp-content/plugins/formcraft/file-upload/server/content/files/1607174485fa88---subofijelikokudupar.pdf
- http://graphicon.hu/wp-content/plugins/formcraft/file-upload/server/content/files/1606d21e24d11a---2553506691.pdf
- http://bigyikesmedia.com/home/xtremweb/public_html/consultinstitute/web/upload/files/40228550660.pdf
- https://appvid.eus/userfiles/files/98063970425.pdf
- http://naosgym.com/userfiles/files/93009629508.pdf
- http://metzpaintings.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e062e44283---93601608982.pdf
- https://lakeshoresmilesdentistry.com/wp-content/plugins/super-forms/uploads/php/files/siimbsbap7ub2kihbsav87sjk7/89502387853.pdf
- http://pp-aqua.com/userfiles/files/zumunodonovogusekuwinunol.pdf
- http://alternativefitness.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16079d2f3c2da0---sapezizusimopetujivugomes.pdf
- https://kingwaterpure.com/ckfinder/userfiles/files/91846769657.pdf
- https://solarconsulting.org/wp-content/plugins/super-forms/uploads/php/files/0d8f584df0441f7372733cd77bfd150c/55953923736.pdf
- https://tcufroghouses.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d62a2071eab---siwam.pdf
- http://angelcabrera.com/FCKfiles/file/59239511985.pdf
- https://atlasautoglass.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606e5dbe5cc40---napax.pdf
- https://www.straightmyteeth.eu/wp-content/plugins/super-forms/uploads/php/files/cd65bdbe121052c6f58b9e33573d9c44/10758335901.pdf
Embedded domains
- feedproxy.google.com
- dok-vo.ru
- jdlpartnerss.com
- latrinquette.com
- fanaf.org
- chicagohalo.com
- ahcxdq.com
- cms.blauraum.com
- studio45.live
- vitrine-prof.com
- www.tangelo.no
- bigyikesmedia.com
- naosgym.com
- metzpaintings.com
- lakeshoresmilesdentistry.com
- pp-aqua.com
- alternativefitness.com.au
- kingwaterpure.com
- solarconsulting.org
- tcufroghouses.com
- angelcabrera.com
- atlasautoglass.com
- www.straightmyteeth.eu
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report