MALICIOUS — wesukedeborazabinulatem.pdf
MALICIOUS — wesukedeborazabinulatem.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 6 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2921e764a3477160ceb5e913c79d653e99185e5dbbd1fb823dfa149f3babfd0e - SHA-1:
c015dab72b7dfab88edd4e98d713cd3609eff292 - MD5:
97c1bc48bb22321a41204db2c6ae1995 - ssdeep:
1536:5GSyyape626VQpgZmIzOS+zLs8ke/FRaTw9ArgX1eIoMn:5tao6OcBzOS+zlke/FM2YM1Xf - TLSH:
T18837D0F3A297ED4CBD837B03EEEA401D544AD28D6167E7599484B76CCAB83BD8E10500 - Submitted as: wesukedeborazabinulatem.pdf
- File type: pdf · Size: 70830 bytes
- Verdict: malicious (94/100)
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!97C1BC48BB22
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://suhrsmad.dk/wp-content/plugins/formcraft/file-upload/server/content/files/16086a0b53b070---94881974584.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://www.peopleoftheheath.com/wp-content/plugins/formcraft/file-upload/server/content/files/16084a59e16276---61438751115.pdf, https://wacee.net/wp-content/plugins/formcraft/file-upload/server/content/files/16071f28e13827---77732058029.pdf, https://sipare.com.ar/wp-content/plugins/super-forms/uploads/php/files/6slfa2kqol43j1cc6f1s0e3h43/zoxaxogewobokuviw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/S30rS-6n6vg/uplcv?utm_term=checkmate+opt+out+form
- http://www.peopleoftheheath.com/wp-content/plugins/formcraft/file-upload/server/content/files/16084a59e16276---61438751115.pdf
- https://wacee.net/wp-content/plugins/formcraft/file-upload/server/content/files/16071f28e13827---77732058029.pdf
- https://sipare.com.ar/wp-content/plugins/super-forms/uploads/php/files/6slfa2kqol43j1cc6f1s0e3h43/zoxaxogewobokuviw.pdf
- https://masterok-kovka.ru/wp-content/plugins/super-forms/uploads/php/files/44a76490604889db0b11f0fc9b6658a5/62630448846.pdf
- http://www.primalegal.eu/wp-content/plugins/super-forms/uploads/php/files/5db4uto64b0p9c4ggm0imvmi05/43080730834.pdf
- http://mijneigenlift.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1608b707110710---51324374266.pdf
- https://suhrsmad.dk/wp-content/plugins/formcraft/file-upload/server/content/files/16086a0b53b070---94881974584.pdf
- http://makaeximworld.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607080abc1cee---83961306863.pdf
- https://hotelristorantenovecento.it/wp-content/plugins/super-forms/uploads/php/files/50be77b8bde13f9fe101a060fd43d8dd/56996229179.pdf
- https://home18.ru/wp-content/plugins/super-forms/uploads/php/files/81f29c1b1104d5861287db340161e38e/77345171322.pdf
- https://tripleccompanies.com/wp-content/plugins/super-forms/uploads/php/files/dc27b958521bce8974c54d0878c0b112/75767911678.pdf
- http://www.wallisandemmanuel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f5567def1d---91899078906.pdf
- http://eduomania.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607bc26abfbc0---wobasinajujonaxet.pdf
- http://anhuishangbiao.com/upload_fck/file/2021-4-30/20210430083835797264.pdf
- https://airshow-bg.com/file/kutelufemusu.pdf
- https://www.ideaklinik.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160769a6dda55b---74446292994.pdf
- https://www.cdscabling.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160851f12073fe---27234907608.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- www.peopleoftheheath.com
- wacee.net
- masterok-kovka.ru
- www.primalegal.eu
- mijneigenlift.nl
- makaeximworld.com
- hotelristorantenovecento.it
- home18.ru
- tripleccompanies.com
- www.wallisandemmanuel.com
- eduomania.com
- anhuishangbiao.com
- airshow-bg.com
- www.cdscabling.co.uk
- www.w3.org
- purl.org
- ns.adobe.com
- sipare.com.ar
- suhrsmad.dk
- www.ideaklinik.com.tr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report