MALICIOUS — bedubomuzojifiwugu.pdf
MALICIOUS — bedubomuzojifiwugu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1e27847cb71eeec4aae00cb683add23889773163ee918315dcf3d561a8cd95fd - SHA-1:
77ee697b351f58d2cb2a3670ad3dc76e39c97339 - MD5:
2dc60ef838f7133af248e43809f499cb - ssdeep:
1536:FPRT6Um2PE0KymoR+r2QqjYL/ViL6wGwYlOfG7PhTXW6pOu206bCVHW/+J9BfaLZ:LTn9IoRA2Q7/ViL61lBhQu20J4+J/aLZ - TLSH:
T1B539E1F3A2A3ED5C36869F4365A5135CA08AD38C2131EA9041C5B7BCC5BC6BDEF50A11 - Submitted as: bedubomuzojifiwugu.pdf
- File type: pdf · Size: 84540 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://threadworx.com/thread/admin/uploads/file/61039899852.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://threadworx.com/thread/admin/uploads/file/61039899852.pdf, http://crystalnymph.by/wp-content/plugins/super-forms/uploads/php/files/e0fb0157dcf72b11bdf14ffab8823d60/31600563598.pdf, https://basalyemek.com/ckfinder/userfiles/files/10813505427.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/DOqCt-cVA4I/uplcv?utm_term=baixar+aplicativo+para+android
- https://threadworx.com/thread/admin/uploads/file/61039899852.pdf
- http://crystalnymph.by/wp-content/plugins/super-forms/uploads/php/files/e0fb0157dcf72b11bdf14ffab8823d60/31600563598.pdf
- https://basalyemek.com/ckfinder/userfiles/files/10813505427.pdf
- http://aaas.handyfriendship.com/upload/files/99117902907.pdf
- http://yongchengtech.com/uploads/files/202109130447483274.pdf
- https://registracijakoncar.com/webroot/js/ckfinder/userfiles/files/11358651307.pdf
- http://mywayrtk.org/userfiles/file/kowanakowiz.pdf
- https://magnanelli.com/userfiles/file/nisegavegonafugidefeb.pdf
- http://savvyais.com/userfiles/file/gaxerononifa.pdf
- http://travelspace.pl/userfiles/file/tuxowokulilobepolunupew.pdf
- https://www.passion-rnd.com/upfile/files/2021/09/20/rulebinuzovidoja.pdf
- https://tasivn.com/upload/ck/files/bususo.pdf
- http://cukierniabrzezinski.pl/www/artizam/fck/file/fegumoweto.pdf
- https://kolorubursztynu.kolorubursztynu.pl/web/uploads/files/62227535353.pdf
- http://mya1fc.com/files/ckuploads/files/jigijuvijojudasa.pdf
- https://ijpdua.com/contents/files/webokuvapavubujaxiboze.pdf
- https://alternativecarrepair.com/userfiles/file/38659191833.pdf
- http://boonfagrandhome.com/user_img/files/41018126489.pdf
- https://ikomsolutions.com/admin/userfiles/file/nulomelurazemasab.pdf
- https://journeypeople.cc/wp-content/plugins/super-forms/uploads/php/files/586a80335ed860c90a21a4806a6bf7c9/70055984643.pdf
- https://rowsontw.com/shopadmin/upload/files/20664109572.pdf
- http://maiodi.com/userfiles/files/pugud.pdf
- http://www.de.ruben.pl/ckfinder/userfiles/files/tuweruwikijur.pdf
- https://tese.in/ckfinder/userfiles/files/gumozajonamosera.pdf
Embedded domains
- feedproxy.google.com
- threadworx.com
- basalyemek.com
- aaas.handyfriendship.com
- yongchengtech.com
- registracijakoncar.com
- mywayrtk.org
- magnanelli.com
- savvyais.com
- travelspace.pl
- www.passion-rnd.com
- tasivn.com
- cukierniabrzezinski.pl
- kolorubursztynu.kolorubursztynu.pl
- mya1fc.com
- ijpdua.com
- alternativecarrepair.com
- boonfagrandhome.com
- ikomsolutions.com
- journeypeople.cc
- rowsontw.com
- maiodi.com
- www.de.ruben.pl
- tese.in
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report