MALICIOUS — newovexalijatudinonuva.pdf
MALICIOUS — newovexalijatudinonuva.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4779f2339dc4ea4519d295fffba271eab90433fb9d5e09f5b53c496e32369099 - SHA-1:
987a3e5b3109016debe2a51e65916dc81efcb9db - MD5:
8f797cf49fb2652d71d207916cb2dc3e - ssdeep:
1536:LDuv8vfYu5HD5gzPXi3KPjoLor3xgfNJJWML87yZ2nW8pO7ygA:/ukvvHDSi6PULTfNJxL87k267g - TLSH:
T1F137CFF322EBED8CBA5FDB0365E611A9644AD3485236EB50408CBB6C957C5BD7B00640 - Submitted as: newovexalijatudinonuva.pdf
- File type: pdf · Size: 71255 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://tchid.net/userfiles/file/92688160600.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://stroynerud-sm.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1613d520875f06---27692516802.pdf, http://koyomisushi.com/uploads/files/wewabemulirudux.pdf, http://bbpcosmetics.com/admin/upFiles/2021-9/file/11663845847.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/3vuEKuznOb8/uplcv?utm_term=download+movie+flix+apk
- http://stroynerud-sm.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1613d520875f06---27692516802.pdf
- http://koyomisushi.com/uploads/files/wewabemulirudux.pdf
- http://bbpcosmetics.com/admin/upFiles/2021-9/file/11663845847.pdf
- http://enslev-anlaegsservice.dk/userfiles/file/73199827327.pdf
- http://tchid.net/userfiles/file/92688160600.pdf
- http://kbautotech.com/board/datafiles/imagefile/2256767858.pdf
- https://derya.afmiletisimajansi.info/resimler/files/26013625408.pdf
- http://www.tecnobor.com/ckfinder/userfiles/files/pufigero.pdf
- http://seowonbattery.com/files/fckeditor/file/4788035756135c959e7220.pdf
- https://polytex.de/sites/default/files/dowojedavuzolorebofovizew.pdf
- http://eugensa.lt/app/webroot/uploads/userfiles/files/68096238286.pdf
- http://talleresjpg.es/img/file/golon.pdf
- https://casabresciani.it/uploads/file/53785032332.pdf
- http://hattrick-sports.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612e9f7606c6e---92244054050.pdf
- https://rpaxis.net/userfiles/file/witega.pdf
- http://yuli-china.ru/d/files/jinemabutujowave.pdf
- https://protum.se/file/febila.pdf
- https://drddvichitra.com/userfiles/file/20304931998.pdf
- http://rabotatver.ru/userfiles/admin/56481086952.pdf
- http://hitplus.eu/userfiles/file/10619783449.pdf
- http://www.lukoilmarine.com/ckfinder/userfiles/files/gozutososopuruziz.pdf
- https://e-ssuances.com/ckfinder/userfiles/files/juxebogokigof.pdf
- https://odlingfamily.com/userfiles/file/57211351363.pdf
- http://tayles.com/uploaded/39792702192.pdf
Embedded domains
- feedproxy.google.com
- stroynerud-sm.ru
- koyomisushi.com
- bbpcosmetics.com
- tchid.net
- kbautotech.com
- derya.afmiletisimajansi.info
- www.tecnobor.com
- seowonbattery.com
- polytex.de
- talleresjpg.es
- casabresciani.it
- hattrick-sports.com
- rpaxis.net
- yuli-china.ru
- protum.se
- drddvichitra.com
- rabotatver.ru
- hitplus.eu
- www.lukoilmarine.com
- e-ssuances.com
- odlingfamily.com
- tayles.com
- pantanalmsnews.com.br
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report