MALICIOUS — boxipabuxow.pdf
MALICIOUS — boxipabuxow.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
35d222881bd2ceb188e2e82eb59d4cbe5dcdb639fc0f46d6fa7b132168f391ab - SHA-1:
7be3cf5b6771fad4e7c8879861bdd8e3bafab595 - MD5:
1a62ca192edd09dc0f34de14e5a0f8be - ssdeep:
1536:/V3igRu7ekt1R5spF93aFDbMTOGgnfR/zBf1YBQG8hmjoeUWo67kt1JKLar3y4As:N3tq5EFBaFsTOGKplfiBVQ5skdrRAr7k - TLSH:
T1C239D0F351A7ED0C375B8B07A9EB11A86489D7845672DBA0048CB67C987CEBD7F00A11 - Submitted as: boxipabuxow.pdf
- File type: pdf · Size: 86912 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://srtcivilnorth.com/ckeditor_file/files/liwozigumajodasafosizaso.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://chcial.ru/uplcv?utm_term=new+battle+royale+game+android, http://srtcivilnorth.com/ckeditor_file/files/liwozigumajodasafosizaso.pdf, http://www.hz-kontejnery.cz/ckfinder/userfiles/files/ribasigos.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://chcial.ru/uplcv?utm_term=new+battle+royale+game+android
- http://srtcivilnorth.com/ckeditor_file/files/liwozigumajodasafosizaso.pdf
- http://www.hz-kontejnery.cz/ckfinder/userfiles/files/ribasigos.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/0qe0vmo48ur2j6m3fgnnfoh9h7/97253018141.pdf
- http://www.musicboxpiano.com/contentfiles/37579139866.pdf
- http://www.chinahkcarplate.com/wp-content/plugins/formcraft/file-upload/server/content/files/16131d0a2dc37f---jawonegitobipe.pdf
- http://www.catalogodecineargentino.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613bbcda8cc2f---kokataj.pdf
- https://kenkochaya.com/user_data/ckfinder/files/fuvisuva.pdf
- http://pedraferro.com/files/files/werepupegarivatetuvaze.pdf
- http://casaperferiesantamariagoretti.com/writable/public/userfiles/file/33711058444.pdf
- https://www.simcoerecovery.net/wp-content/plugins/super-forms/uploads/php/files/ge6johp3o8o5bugdr6a2g87o2t/6458954887.pdf
- http://ettorebelfioreliutaio.it/userfiles/files/49056142122.pdf
- http://andrenickels.de/ckfinder/userfiles/files/3914589552.pdf
- https://bruceleevideos.org/images/file/ruvip.pdf
- http://henghuitong.com/jingkelun/userfiles/files/20210908212726.pdf
- http://grupopiscis.com/upload/files/39915856547.pdf
- http://mpu-beratung-brendle.de/userfiles/file/tolumatetizitorid.pdf
- http://pinedafoundation.org/imageuploads/file/luralakusuniki.pdf
- https://tanhaithanhvalves.com/quangcao/admin/file/8266908734.pdf
- http://jjc-dev.com/userfiles/file/80968344894.pdf
- http://dachastyle.com/userfiles/file/gupoziponowunokawaxoz.pdf
- http://skuplaptop.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1613674dba51ef---72484188037.pdf
- http://bentleyplemtech.ru/userfiles/file/30440560137.pdf
- http://extreamtuning.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1612ee30375156---54164777086.pdf
- http://abwvictory.com/uploads/files/kedojawabunirizi.pdf
Embedded domains
- chcial.ru
- srtcivilnorth.com
- www.nuricomuvakfi.org
- www.musicboxpiano.com
- www.chinahkcarplate.com
- www.catalogodecineargentino.com
- kenkochaya.com
- pedraferro.com
- casaperferiesantamariagoretti.com
- www.simcoerecovery.net
- ettorebelfioreliutaio.it
- andrenickels.de
- bruceleevideos.org
- henghuitong.com
- grupopiscis.com
- mpu-beratung-brendle.de
- pinedafoundation.org
- tanhaithanhvalves.com
- jjc-dev.com
- dachastyle.com
- skuplaptop.pl
- bentleyplemtech.ru
- extreamtuning.ru
- abwvictory.com
- grandhotelbulgaria.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report