MALICIOUS — rebotiziruzeta.pdf
MALICIOUS — rebotiziruzeta.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4b6237a52a6947fdb668b2a157dc701cd5de24bb70397a7675e70f2455fc6928 - SHA-1:
b730afe71a46ce63218d310f43e55b85ae700a7a - MD5:
a848744dd5e6b7030229fffb2fd08294 - ssdeep:
1536:OlI9BmyUUMoedDWWT2tHjnG2htgtc9I5hPVZ9driz0YBBMy0KW6pOu2SyIg1Xlk0:N9EyjyDWaqN/gt9VZ903f0Xu2fI8XlJb - TLSH:
T17638CFF3225BDC8C779B9B0379AA126D508ED3882266EB5044C8F7BC94BC5BDBE14110 - Submitted as: rebotiziruzeta.pdf
- File type: pdf · Size: 82045 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://www.bakkersvlaanderen.be/resources/plugins/ckfinder/userfiles/0/files/78227924750.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://www.bakkersvlaanderen.be/resources/plugins/ckfinder/userfiles/0/files/78227924750.pdf, https://khonggiansangtao.com/platformecom/img/upload/file/98087954944.pdf, http://ladakhtripmaker.com/userfiles/files/bipimunarolelek.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/1xuhb7AK25c/uplcv?utm_term=mcsa+course+notes+pdf
- https://www.bakkersvlaanderen.be/resources/plugins/ckfinder/userfiles/0/files/78227924750.pdf
- https://khonggiansangtao.com/platformecom/img/upload/file/98087954944.pdf
- http://ladakhtripmaker.com/userfiles/files/bipimunarolelek.pdf
- http://cameronhaddock.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b075fd9464b---59935676520.pdf
- http://razaviota.ir/basefile/razaviotair/files/rupopedexowejuwa.pdf
- http://nw-line.ru/generic/uploaded/18077141223.pdf
- https://www.apartamentselsllacs.com/wp-content/plugins/super-forms/uploads/php/files/auldk5o5lcs5tuge502sr3224c/42274683119.pdf
- https://www.dentaltaxpros.com/wp-content/plugins/super-forms/uploads/php/files/37d5b557446fff18ab252449d833f7b5/vidudimokotigusu.pdf
- https://hrmconsulting.biz/upload/files/lidufawipizojeno.pdf
- http://yey.uw52.com/upload/files/guwine.pdf
- https://vidolamerica.org/wp-content/plugins/super-forms/uploads/php/files/d02d253a9f5aad73e7f8c1e3fa3f40dc/xenukutolagaz.pdf
- http://tipiland.net/upload/file/poxowijijos.pdf
- http://www.veronicaneal.com/wp-content/plugins/formcraft/file-upload/server/content/files/1/1608819d49b72e---33993833652.pdf
- https://atamergranit.com/userfiles/file/worukofedewufi.pdf
- http://humanitool.ru/userfiles/file/lixolobomis.pdf
- http://forglass.sk/userfiles/file/1999833418.pdf
- http://www.homefacelifters.com/wp-content/plugins/super-forms/uploads/php/files/30a41c002c4d5e3e3c0970973acea5ed/dolewuvejomo.pdf
- http://pferdefreunde-brueckenhof.de/sites/default/files/userfiles/file/57213132183.pdf
- http://airconbank.com/upload/fckeditor/file/ridigirixikumabune.pdf
- http://cristal-in.fr/userfiles/file/89879857847.pdf
- https://www.straightmyteeth.com/wp-content/plugins/super-forms/uploads/php/files/de4dc89182a822b053d7950bfd8537e8/54381829030.pdf
- http://adhunikjewellers.com/ckfinder/userfiles/files/37693135638.pdf
- https://ateneoarbonaida.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ac9e6acc604---lenumadagej.pdf
- http://rsti.biz/files/fck/file/85661757435.pdf
Embedded domains
- feedproxy.google.com
- www.bakkersvlaanderen.be
- khonggiansangtao.com
- ladakhtripmaker.com
- cameronhaddock.com
- razaviota.ir
- nw-line.ru
- www.apartamentselsllacs.com
- www.dentaltaxpros.com
- hrmconsulting.biz
- yey.uw52.com
- vidolamerica.org
- tipiland.net
- www.veronicaneal.com
- atamergranit.com
- humanitool.ru
- www.homefacelifters.com
- pferdefreunde-brueckenhof.de
- airconbank.com
- cristal-in.fr
- www.straightmyteeth.com
- adhunikjewellers.com
- ateneoarbonaida.com
- rsti.biz
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report