MALICIOUS — potukirexokitonabus.pdf
MALICIOUS — potukirexokitonabus.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
37652b685dcc2750c3bd9791da1bf01dff63e565e18f64b23231a564a8e5b0e3 - SHA-1:
bf72b1b634ae0747099f3a9817f7a7b56331d75b - MD5:
171fa7827ace25c21ffed47b4e55dffd - ssdeep:
1536:FiwCd3I9Xa/cOKxRIAwueo5oqrvlPzg5imMw99RCxgCkySDWkNpOPaWlHzwyLqBx:c/gxUSRrvlUt0PkBTowaOH - TLSH:
T1743AD1F3B09BED4C7286DF4395B7116CB45ADA846362EB900488BB3C84BC6BE6F10551 - Submitted as: potukirexokitonabus.pdf
- File type: pdf · Size: 96104 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://flightshop.jp/images/blog/file/35964791275.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://carraracucinecomponibilitrapani.it/userfiles/files/27477449905.pdf, https://gradeagroup.com/wp-content/plugins/super-forms/uploads/php/files/na3h1gob4jtl1cdjr44sp7una7/22167973057.pdf, http://boschvietnam.com/files/usersfiles/files/woditanejefozupufejaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/YTWXjIUwRh0/uplcv?utm_term=centurion+scientific+k3+series+manual
- http://carraracucinecomponibilitrapani.it/userfiles/files/27477449905.pdf
- https://gradeagroup.com/wp-content/plugins/super-forms/uploads/php/files/na3h1gob4jtl1cdjr44sp7una7/22167973057.pdf
- http://boschvietnam.com/files/usersfiles/files/woditanejefozupufejaf.pdf
- http://serendipityorlando.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078ce34c29b7---69646851673.pdf
- https://tocgia247.com/wp-content/plugins/super-forms/uploads/php/files/pvvebuahq4nohvrequigja84am/93508817839.pdf
- https://hsse.cl/files/38611873132.pdf
- https://hpx.com.ua/wp-content/plugins/super-forms/uploads/php/files/5404a4778406577b048a44b507e511f4/5601905766.pdf
- http://ghrnightinwhite.com/clients/7/72/721f26fb9237119891afe8d29dbdfc29/File/42984662698.pdf
- http://cl-metalparts.com/d/files/jagopo.pdf
- http://flightshop.jp/images/blog/file/35964791275.pdf
- http://app8itebarandgrill.com/admin/images/file/39654902706.pdf
- https://samiznojmo.cz/wp-content/plugins/super-forms/uploads/php/files/dcf9594aa8460327f711a65360f5223a/36031435993.pdf
- http://guides2alpes.fr/uploads/file/vusetex.pdf
- https://fietenhaardenenkachels.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160774158625a6---gukat.pdf
- https://socialacademy.gr/wp-content/plugins/super-forms/uploads/php/files/5caa5f712bc9e37de150aa01d8a329bf/tedadujap.pdf
- http://viral-list-machine.com/ckfinder/userfiles/publics/files/likisomolunodor.pdf
- https://oknoplus-omsk.ru/wp-content/plugins/super-forms/uploads/php/files/a3ccd34e395da01e337062c9792ed3af/98196118042.pdf
- http://boek.se/bilder_umeny/File/1052531028.pdf
- http://rufullthrottle.com/wp-content/plugins/formcraft/file-upload/server/content/files/160722ca9efe34---xudavabojumizor.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- feedproxy.google.com
- carraracucinecomponibilitrapani.it
- gradeagroup.com
- boschvietnam.com
- serendipityorlando.com
- tocgia247.com
- hpx.com.ua
- ghrnightinwhite.com
- cl-metalparts.com
- flightshop.jp
- app8itebarandgrill.com
- guides2alpes.fr
- fietenhaardenenkachels.nl
- viral-list-machine.com
- oknoplus-omsk.ru
- boek.se
- rufullthrottle.com
- www.w3.org
- purl.org
- ns.adobe.com
- hsse.cl
- samiznojmo.cz
- socialacademy.gr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report