MALICIOUS — likobowomasofubobub.pdf
MALICIOUS — likobowomasofubobub.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
38d67d2386dbf2d550fe8c5f96ef69c65641c69065dabb11ffe604f8f00e9785 - SHA-1:
3d72c030e8201966e20c931474880126b6b85b27 - MD5:
9133b339b5d17745f6a6347f63c00235 - ssdeep:
1536:fCXAvZ55Uj/GDkiiPb/IWw/FLWOzWwpOSSlJ:KwvvyjGoPb/gJN2Se - TLSH:
T15937BFF321D7EDCC76CA4B57A5AB11AC9186D39C1272EE508488F27C99BC97DBE00640 - Submitted as: likobowomasofubobub.pdf
- File type: pdf · Size: 70703 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://lookupagency.es/wp-content/plugins/formcraft/file-upload/server/content/files/161397a69f39b4---62347841819.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://lab4050.com/upload/editor/file/49378169972.pdf, https://xuantruongtech.com/images/ckeditor/files/1167843598.pdf, https://mgs-on-track.com/uploads/misc/files/25477479043.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/3CAf4wW3hvY/uplcv?utm_term=pi+browser+apk
- http://lab4050.com/upload/editor/file/49378169972.pdf
- https://xuantruongtech.com/images/ckeditor/files/1167843598.pdf
- https://mgs-on-track.com/uploads/misc/files/25477479043.pdf
- http://lookupagency.es/wp-content/plugins/formcraft/file-upload/server/content/files/161397a69f39b4---62347841819.pdf
- https://stcatherine.ac.ug/wp-content/plugins/formcraft/file-upload/server/content/files/161389d3ff3cb4---zivonamoka.pdf
- http://cephedanismani.com/images/pages/file/84878298124.pdf
- http://zoncmswebsitebeheer.nl/files/editor/file/fiseni.pdf
- http://tonyprins.nl/images/uploads/file/nixagipadidobejetuzot.pdf
- http://materialdeestudo.top/userfiles/files/pajirofukiwolakobaz.pdf
- https://www.andyselfstorage.co.uk/wp-content/plugins/super-forms/uploads/php/files/mq1sok0594lf666taihsq2ahav/37127123090.pdf
- http://www.combatsim.eu/wp-content/plugins/formcraft/file-upload/server/content/files/1614662bbea5ad---37455666913.pdf
- http://carneiro-sa.pnh.pt/js/ckfinder/userfiles/files/59143795149.pdf
- https://techson-cctv.com/upload/file/81791565414.pdf
- https://rocksoliddesigns.biz/userfiles/file/doripujuzogebox.pdf
- http://ecohouse-lab.de/userfiles/file/82532706650.pdf
- http://cohn-vossen.com/wp-content/plugins/formcraft/file-upload/server/content/files/161466c78e4a50---bamebozakijolaxumi.pdf
- http://ultraljud.nu/bild/files/xotagavagatorasuv.pdf
- https://fier-forjat-valimet.ro/ckfinder/userfiles/files/68056256066.pdf
- http://ituor.ir/basefile/chartermeinfo/files/jifasi.pdf
- http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/25bd2f2f25d375294de67017f71f8586/fanadezufifitirus.pdf
- http://solarexperten.ch/fckeditor/editor/images/file/59424239133.pdf
- http://gmkms.net/upfile_editor/2021/files/78167840175.pdf
- https://www.dooleysnaturalgas.com/ckfinder/userfiles/files/59395917309.pdf
- http://hangtatmj.com/userfiles/tadokamunovugixigenibusa.pdf
Embedded domains
- feedproxy.google.com
- lab4050.com
- xuantruongtech.com
- mgs-on-track.com
- lookupagency.es
- cephedanismani.com
- zoncmswebsitebeheer.nl
- tonyprins.nl
- materialdeestudo.top
- www.andyselfstorage.co.uk
- www.combatsim.eu
- techson-cctv.com
- rocksoliddesigns.biz
- ecohouse-lab.de
- cohn-vossen.com
- ituor.ir
- chagatea.ru
- solarexperten.ch
- gmkms.net
- www.dooleysnaturalgas.com
- hangtatmj.com
- bndweb.nl
- greenlakepaint.com
- stroyvodservice.ru
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report