MALICIOUS — gituvuwa.pdf
MALICIOUS — gituvuwa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1a99c02acc405a88a3ccde14ffade0305e8e364188f05680313e8b0681b01324 - SHA-1:
0e9dd993270ab168e81fc752b231acd43dc6f1ca - MD5:
d0d01a7badf3c1954634c5253640a3f7 - ssdeep:
3072:fj9Z7+iLLwbh3EvGAA3X2lYfnKxYZWLZKytWUcfYivqTpEDpp9g5+I:xZ7+iQl34TEmlYf9OcfY6qTp4a - TLSH:
T1C93DF2F320DBDD0C7A6AEB07D9EB226CE086D6952570DB904411726CC0BC6BD7F20A61 - Submitted as: gituvuwa.pdf
- File type: pdf · Size: 126139 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/160838ebf31060---53548768999.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/160838ebf31060---53548768999.pdf, http://bazatalty.pl/wp-content/plugins/super-forms/uploads/php/files/56762d46bff73e76154ba8e2af5239cc/60154232186.pdf, https://www.siemers-deutschmann.de/wp-content/plugins/super-forms/uploads/php/files/fuv377elqq8hopklf28ousaclo/16623936146.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=swift+parse+json+to+object
- http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/160838ebf31060---53548768999.pdf
- http://bazatalty.pl/wp-content/plugins/super-forms/uploads/php/files/56762d46bff73e76154ba8e2af5239cc/60154232186.pdf
- https://www.siemers-deutschmann.de/wp-content/plugins/super-forms/uploads/php/files/fuv377elqq8hopklf28ousaclo/16623936146.pdf
- https://adepotcustom.com/UploadFiles/file/20210430182517103.pdf
- http://writtenmail.com/upload_images/file/wumavedizuwiwevefebak.pdf
- https://www.tifdip.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609f3d506cd30---69452316153.pdf
- http://barudan.hk/UploadFile/file/20210621165310105.pdf
- https://hmv.ir/wp-content/plugins/formcraft/file-upload/server/content/files/1608448745608e---divew.pdf
- https://bluebeakbranding.com/wp-content/plugins/super-forms/uploads/php/files/05e20d5127466bb39da79ae20d8158ee/wedemabaxas.pdf
- https://acryl-bg.com/userfiles/file/purojo.pdf
- https://antoinepanau.com/wp-content/plugins/super-forms/uploads/php/files/f3a0e606dfa269cb57b861ac5cc8b6d2/286228625.pdf
- https://www.brunosistemi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cac25932379---86611436192.pdf
- https://hacunamatata.ru/wp-content/plugins/super-forms/uploads/php/files/cf97a6e7a815dcf9c192d64f4e066498/gerunawufuteduneneme.pdf
- http://painttechvina.com/webroot/img/files/nujobesikolatet.pdf
- https://www.tai.gr/wp-content/plugins/formcraft/file-upload/server/content/files/160c2d26d4d929---kexisapuzojuzabugadug.pdf
- https://clearpatth.com/userfiles/file/16713522826.pdf
- https://dewalt-naradi.cz/media/upload/editor/file/27779429816.pdf
- https://canvasations.com/wp-content/plugins/super-forms/uploads/php/files/dguqvtg2tlrifcaf9v8fs10383/batepibar.pdf
- http://berallebags.com/UploadFiles/FCKeditor/20210508232925.pdf
- http://gfb.it/upload/fck/file/17795884025.pdf
- http://paymentsbusiness.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160983f8a816f3---pinutenebubalazarufajipa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- leap-egypt.com
- bazatalty.pl
- www.siemers-deutschmann.de
- adepotcustom.com
- writtenmail.com
- www.tifdip.com
- barudan.hk
- hmv.ir
- bluebeakbranding.com
- acryl-bg.com
- antoinepanau.com
- www.brunosistemi.com
- hacunamatata.ru
- painttechvina.com
- clearpatth.com
- canvasations.com
- berallebags.com
- gfb.it
- paymentsbusiness.ca
- www.w3.org
- purl.org
- ns.adobe.com
- www.tai.gr
- dewalt-naradi.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report