MALICIOUS — kosipafejamidasukom.pdf
MALICIOUS — kosipafejamidasukom.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1f447929b94d2b9d14215f515984edfc2d4a66289d956d9226308806cbd68680 - SHA-1:
2ea6d09a8cb0a74796e7e6d27778d3e71e136216 - MD5:
8a68fc9e1bd21d615abf2be78d863a07 - ssdeep:
3072:Q9dFpOBHe/k3HTgoFnbETBor68B5HlKe9Tf6ID9dqwsM:QHFg0AgAbOB+pFKm76Cv - TLSH:
T1A73CE0F36197DF4C6AC7DB87BAA75299618DE3C82122EA105484771CC5FC1AE7F10A20 - Submitted as: kosipafejamidasukom.pdf
- File type: pdf · Size: 122653 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://46a1ac71-481d-4a85-b709-d40f3a189542.filesusr.com/ugd/143c98_f4e474990d87410693e1b301a77a5d3c.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://leonvi.ru/strik?utm_term=mem%25C3%25B3rias+p%25C3%25B3stumas+de+br%25C3%25A1s+cubas+resenha+critica, https://46a1ac71-481d-4a85-b709-d40f3a189542.filesusr.com/ugd/143c98_f4e474990d87410693e1b301a77a5d3c.pdf?index=true, https://werukubafufu.weebly.com/uploads/1/3/4/0/134000234/topivifataruna.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://leonvi.ru/strik?utm_term=mem%25C3%25B3rias+p%25C3%25B3stumas+de+br%25C3%25A1s+cubas+resenha+critica
- https://46a1ac71-481d-4a85-b709-d40f3a189542.filesusr.com/ugd/143c98_f4e474990d87410693e1b301a77a5d3c.pdf?index=true
- https://werukubafufu.weebly.com/uploads/1/3/4/0/134000234/topivifataruna.pdf
- https://s3.amazonaws.com/zoxewudunigus/lefilexelidap.pdf
- http://fasekafalig.scienceontheweb.net/syntactic_structures_revisited.pdf
- http://kulanefimolon.mypressonline.com/79963326750.pdf
- http://doriponesarom.myartsonline.com/adverbs_of_frequency_exercises_b1.pdf
- http://shoppermarket.online/the_little_prince_1974_full_movie_online_stream5wl09.pdf
- https://30b7a97f-6117-4fff-8876-4b3c2220b6c6.filesusr.com/ugd/15cd4d_7f816f73bb0b4ddfb3b66c29f13a167c.pdf?index=true
- https://3c8197b3-f999-4f29-b3da-fbdfea3dbf34.filesusr.com/ugd/0047a4_6c737872f4cb4e40b1512bf1c5a53945.pdf?index=true
- https://f395d2f2-f939-483b-815f-81062d4747ff.filesusr.com/ugd/be2697_9bc82ba41c3a4645a8050bfcb083b0d2.pdf?index=true
- https://gajitiromivalot.weebly.com/uploads/1/3/4/4/134475956/2706398.pdf
- http://shoppingyxplus.xyz/lorabobigasijifukobu3nmm0.pdf
- http://suxikikafib.epizy.com/wupavi.pdf
- http://ruxenawuxovogu.getenjoyment.net/2331493098.pdf
- https://wosaboler.weebly.com/uploads/1/3/4/4/134496590/3352697.pdf
- http://instapresent.site/baby_girl_names_2020_listg8jp4.pdf
- http://santecmb-sarl.com/the_anarchist_cookbook_portugues_downloadmity6.pdf
- https://s3.amazonaws.com/muvevanepen/malaria_prophylaxis_cdc_guidelines.pdf
- http://pivojowemetobiv.mywebcommunity.org/john_deere_4045_parts_list.pdf
- http://pasebuda.epizy.com/26307015345.pdf
- https://36425c1f-c329-48aa-845d-1f8252cb45c8.filesusr.com/ugd/01d500_2a7d2e8546bb473b977d3995fbc523c7.pdf?index=true
- https://s3.amazonaws.com/senodiw/55185439304.pdf
- https://s3.amazonaws.com/tokatefozude/zosobanisibamonepuwuregap.pdf
- https://bonikelebosobi.weebly.com/uploads/1/3/2/8/132814552/001d4.pdf
Embedded domains
- leonvi.ru
- 46a1ac71-481d-4a85-b709-d40f3a189542.filesusr.com
- werukubafufu.weebly.com
- s3.amazonaws.com
- fasekafalig.scienceontheweb.net
- kulanefimolon.mypressonline.com
- doriponesarom.myartsonline.com
- shoppermarket.online
- 30b7a97f-6117-4fff-8876-4b3c2220b6c6.filesusr.com
- 3c8197b3-f999-4f29-b3da-fbdfea3dbf34.filesusr.com
- f395d2f2-f939-483b-815f-81062d4747ff.filesusr.com
- gajitiromivalot.weebly.com
- shoppingyxplus.xyz
- suxikikafib.epizy.com
- ruxenawuxovogu.getenjoyment.net
- wosaboler.weebly.com
- instapresent.site
- santecmb-sarl.com
- pivojowemetobiv.mywebcommunity.org
- pasebuda.epizy.com
- 36425c1f-c329-48aa-845d-1f8252cb45c8.filesusr.com
- bonikelebosobi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report