MALICIOUS — kafaxavage.pdf
MALICIOUS — kafaxavage.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
43ab11095792076add4b42653f8ba8cb59c8debeafbf34167c1887ace29ecf41 - SHA-1:
ae0b9e604cfcc64524640a0a4e11c38cce11b3c1 - MD5:
66714ce5f908bfc7e728e3dd1ab247b1 - ssdeep:
1536:7pig73a9OGtE1Ck4wGD1YWnrDmufH84qk2XGF0Wg4MTBOUOWQpOCf66:Fig7qDWCvDDmuU47c4YBOUBCP - TLSH:
T16D38D1F32053EDCCB7978B072AAB11AD7449EB986612EA80118CF61D946CAFD7F10550 - Submitted as: kafaxavage.pdf
- File type: pdf · Size: 83298 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.andimoda.com/wp-content/plugins/super-forms/uploads/php/files/a6445f90eb52ce44fe152256a070db3f/34138840289.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cian.hr/userfiles/file/tetulen.pdf, https://hometutorsdelhi.com/userfiles/files/zizotokekekepiber.pdf, https://www.andimoda.com/wp-content/plugins/super-forms/uploads/php/files/a6445f90eb52ce44fe152256a070db3f/34138840289.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/FevRqgeaUVY/uplcv?utm_term=mobilego+for+android+windows+free+download
- https://cian.hr/userfiles/file/tetulen.pdf
- https://hometutorsdelhi.com/userfiles/files/zizotokekekepiber.pdf
- https://www.andimoda.com/wp-content/plugins/super-forms/uploads/php/files/a6445f90eb52ce44fe152256a070db3f/34138840289.pdf
- http://thebeautyofdesign.nl/ckfinder/userfiles/files/jadazazizofoxegofunupuz.pdf
- http://thetsaban3watnuea.com/UserFiles/file/95223221959.pdf
- http://stringquartet.biz/web/images/fck/file/masexodubunomoxobelut.pdf
- http://paykaaluminiya.ru/ckfinder/userfiles/files/fuduvim.pdf
- http://p-itos.net/admin/userfile/image/file/mosutebe.pdf
- http://agriturismolescuderie.eu/userfiles/files/59820402044.pdf
- https://girilawfirm.com/content_files/files/90193791023.pdf
- https://travelone.ae/userfiles/files/sufudetuje.pdf
- https://118highschool.am/wp-content/plugins/super-forms/uploads/php/files/11997ff97f3f58771f3da0eb08df2eda/53617863532.pdf
- http://lafiestadelmoto.cz/files/file/71247362137.pdf
- http://daiduongmetal.com/uploads/ckfinder/files/30490211565.pdf
- https://michelbarbot.com/upload/files/31743621381.pdf
- https://jamuiboe.com/webroot/upload_media/mabitojotekumedaluxatode.pdf
- https://uzunlarpeynir.com/dursun/upload/files/vofobunewuxetefojilarup.pdf
- http://appli-veolia.net/ckfinder/userfiles/files/zojuruvevonomibisopitur.pdf
- http://radio-salsa.fr/php/rs/filesupload/file/47898774115.pdf
- http://trendstyleimage.com/uploads/ckfinder/userfiles/files/86507861954.pdf
- http://111-orte.com/testarea/cwsCMSlight/media/files/luvimaruz.pdf
- http://phuongsen.com/img-chamthi/files/digafedipuvoziwik.pdf
- http://controldellaves.com/app/webroot/arxius/file/zogix.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- hometutorsdelhi.com
- www.andimoda.com
- thebeautyofdesign.nl
- thetsaban3watnuea.com
- stringquartet.biz
- paykaaluminiya.ru
- p-itos.net
- agriturismolescuderie.eu
- girilawfirm.com
- daiduongmetal.com
- michelbarbot.com
- jamuiboe.com
- uzunlarpeynir.com
- appli-veolia.net
- radio-salsa.fr
- trendstyleimage.com
- 111-orte.com
- phuongsen.com
- controldellaves.com
- www.w3.org
- purl.org
- ns.adobe.com
- cian.hr
- travelone.ae
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report