MALICIOUS — supozat.pdf
MALICIOUS — supozat.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3f3914aff99624643a8da80b4179fa756d0d97cd01ddd3ba1f788ff79d541080 - SHA-1:
685f985dc6068ca8895efda866bf58a0b59d90ff - MD5:
845293fb2e4f48801a11a1c5d534a6bf - ssdeep:
1536:80yTPjIX0MzLkzQuCcRn5Mla1myLHkk84oFC/EnWaMj25LRM2eHW8pO7LxiT:8rj/iG7CcRn5MlylLHCZE/wlRM2ea7Y - TLSH:
T12038CFF330DBEDDC7B8B6F4369EA51D9608ED7C42121AA400488B66C897C5BE7F14A11 - Submitted as: supozat.pdf
- File type: pdf · Size: 84026 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://gyndoktors.de/ckfinder/userfiles/files/7303490662.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cructi.ru/uplcv?utm_term=que+es+un+extranjerismo, http://www.dawnrotaryclub.tw/UserFiles/files/junopasifezavenuze.pdf, http://gyndoktors.de/ckfinder/userfiles/files/7303490662.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cructi.ru/uplcv?utm_term=que+es+un+extranjerismo
- http://www.dawnrotaryclub.tw/UserFiles/files/junopasifezavenuze.pdf
- http://gyndoktors.de/ckfinder/userfiles/files/7303490662.pdf
- http://pcwenhua.com/uploadimg/file/1626564618288111645.pdf
- http://bettynblue.com/upload/fck_img/20210725/file/jezuvogarodege.pdf
- https://ville-saintleonard.fr/pdf/gixejakafepisadudavev.pdf
- http://totalfinance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/161056b3a3bf6f---25635350997.pdf
- https://batdongsandothanh.vn/luutru/files/tureveli.pdf
- http://shadesvalleymounties1969.com/clients/868959/File/68399546160.pdf
- http://www.theflightfest.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609e029ab0c9d---87289746878.pdf
- https://joepromenshealth.com/wp-content/plugins/super-forms/uploads/php/files/3ef9946d90cc1353f80fa7931568aa76/lujosovulorovesaxi.pdf
- http://smeeing.com/userfiles/files/fokewawupuviwine.pdf
- https://www.pal-kont.hu/wp-content/plugins/super-forms/uploads/php/files/e252913fdeb089a0ef9ce6f8300402eb/58676947974.pdf
- http://mixline.ru/img/lib/file/17242287625.pdf
- https://mls.lighting/wp-content/plugins/super-forms/uploads/php/files/b05bc59b6749f54850ce738569130f5b/71919531181.pdf
- http://www.firengo.com/userfiles/files/9441546729.pdf
- http://shlawllc.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/gopufesamaziwa.pdf
- https://laps.pl/userfiles/file/26740032811.pdf
- http://www.sensible-seeds-premium.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b12cadef8bd---42688434484.pdf
- http://www.pianoszimmermann.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16070945078f55---30645446016.pdf
- http://caratow.nl/userfiles/file/fodavudatatuminatanefe.pdf
- https://powermailer.in/userfiles/file/nolavut.pdf
- https://aykutemlak.com/upload/ckfinder/files/31973965125.pdf
- https://finestblogger.de/wp-content/plugins/super-forms/uploads/php/files/4eu0o481eusmfgp42kaf4de2vm/tidulaga.pdf
- https://sahyadrisevasanstha.in/userfiles/file/zuninu.pdf
Embedded domains
- cructi.ru
- www.dawnrotaryclub.tw
- gyndoktors.de
- pcwenhua.com
- bettynblue.com
- ville-saintleonard.fr
- totalfinance.ca
- shadesvalleymounties1969.com
- www.theflightfest.com
- joepromenshealth.com
- smeeing.com
- mixline.ru
- www.firengo.com
- shlawllc.com
- laps.pl
- www.sensible-seeds-premium.com
- www.pianoszimmermann.com.br
- caratow.nl
- powermailer.in
- aykutemlak.com
- finestblogger.de
- sahyadrisevasanstha.in
- revapackers.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report