MALICIOUS — soxos.pdf
MALICIOUS — soxos.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
273fc648a9bb3acdd3f4bfca48aedd6b983fab0c38a4939c812df1c4beae6cd2 - SHA-1:
9c0220db4349c1e65811450a508a99b8b2ebe33f - MD5:
507d0b4394f9732f59240300341f4ae1 - ssdeep:
1536:pAh+YsldXlhZU26BC7ZoB7r6Qd6zry3B1pm8BCa9fc+ypHMWyhX4CFfnRfAabWwH:MkdXjZfoVAraB5T9kxp844fnD+SF - TLSH:
T1D03AD0F361ABDC5C7BCB9F43A6E612A8B08BD7493162D7148048F2AC847D4BE2F44581 - Submitted as: soxos.pdf
- File type: pdf · Size: 95292 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.allterra.group/wp-content/plugins/super-forms/uploads/php/files/e0a784a99f590309c827dcb5d98b4a62/79991570196.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/160948d6a45309---46844659836.pdf, https://www.allterra.group/wp-content/plugins/super-forms/uploads/php/files/e0a784a99f590309c827dcb5d98b4a62/79991570196.pdf, http://ehomeforeclosure.org/images/file/94857294069.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/LPIa9PGmDLg/uplcv?utm_term=multiple+choice+questions+on+differential+equations
- http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/160948d6a45309---46844659836.pdf
- https://www.allterra.group/wp-content/plugins/super-forms/uploads/php/files/e0a784a99f590309c827dcb5d98b4a62/79991570196.pdf
- http://ehomeforeclosure.org/images/file/94857294069.pdf
- http://urbanconstructions.org/images/uploadedimages/file/56709224722.pdf
- http://www.dfdtrading.sk/ckfinder/userfiles/files/monoduxu.pdf
- https://lescourailleurs.com/upload/editor/file/67161150196.pdf
- https://fedico.ca/upload/editor/file/89906310972.pdf
- https://www.partyshuttlebus.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160b8b2d16ae91---93500439342.pdf
- http://alsumiri.net/wp-content/plugins/super-forms/uploads/php/files/7722336a799478741dac366c9e4d5560/21505049066.pdf
- http://bestapp4u.com/admin/uploadedfiles/file/ribazususitosot.pdf
- http://e1pl2.nazwa.pl/busy/fotki/file/dajix.pdf
- https://www.mclarenpress.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c973cba7ded---rajelabulisegetukaxos.pdf
- https://impariant-club.ru/wp-content/plugins/super-forms/uploads/php/files/9bbadaa97fbcbcfa4daeb5ef33cca1a2/suruw.pdf
- http://dochoiotovn.com/uploads/userfiles/file/13467032281.pdf
- http://ifa-astrologie.de/userfiles/file/xuloduvidarejovi.pdf
- https://akapacha.com/userfiles/file/52996847985.pdf
- http://www.johnknox.ch/wp-content/plugins/formcraft/file-upload/server/content/files/160b6498ae524a---58812398237.pdf
- http://www.sunarsurdurulebilir.com/wp-content/plugins/super-forms/uploads/php/files/4f23q7r6ouiskofavbudmsl2n1/puxibumumusizujowozab.pdf
- http://xedaptheduc.net/app/webroot/uploads/files/tivoxuniriwofetenod.pdf
- https://trucraftsmanship.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609c44b2d1b16---xapufatumenonevinumezi.pdf
- https://earthchartercities.org/wp-content/plugins/formcraft/file-upload/server/content/files/16079347f78afd---bogudirenawob.pdf
- http://aucoindeshalles.com/menu/file/65005041218.pdf
- https://mission4recruitment.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cef406042c---guvowunenegofopolutorukul.pdf
- http://pushgroup.lv/userfiles/files/visugepikusunewimozux.pdf
Embedded domains
- feedproxy.google.com
- www.marsagri.com
- ehomeforeclosure.org
- urbanconstructions.org
- lescourailleurs.com
- fedico.ca
- www.partyshuttlebus.com.au
- alsumiri.net
- bestapp4u.com
- e1pl2.nazwa.pl
- www.mclarenpress.com
- impariant-club.ru
- dochoiotovn.com
- ifa-astrologie.de
- akapacha.com
- www.johnknox.ch
- www.sunarsurdurulebilir.com
- xedaptheduc.net
- trucraftsmanship.com
- earthchartercities.org
- aucoindeshalles.com
- mission4recruitment.com
- www.commandinglife.com
- profbuhotchet.ru
- htfcompact.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report