MALICIOUS — vulalekapabopiwa.pdf
MALICIOUS — vulalekapabopiwa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4b8bd4e7e432b51a555e9b138a3beb0d095e58a5ebb531d950ff6616a5eaa3fc - SHA-1:
44ebb8d58dfe32d097f5cd0e2b096138fe90ba52 - MD5:
a172e85f10bf87d72ebc02cbda654129 - ssdeep:
3072:KNmWI1tmTbeBX+UlEejb+l+dSXyuqOO9uNX9ZbbIjE:KsWI1Bvjb+5JUA0w - TLSH:
T1373DD0F3216BCD5CA6979F0358ED11B4548AE78C3272EA9084C8B67CC8BC1BD6F14651 - Submitted as: vulalekapabopiwa.pdf
- File type: pdf · Size: 128770 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://dawahcity.com/userfiles/file/95857256960.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=how+to+get+hypesquad+brilliance+badge, http://muszempilla.com/files/file/45481910025.pdf, http://newbusan.net/FileData/ckfinder/files/20210703_3B55A170250FADA1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/uplcv?utm_term=how+to+get+hypesquad+brilliance+badge
- http://muszempilla.com/files/file/45481910025.pdf
- http://newbusan.net/FileData/ckfinder/files/20210703_3B55A170250FADA1.pdf
- http://27derajat.com/assets/ckfinder/core/connector/php/uploads/files/42943344200.pdf
- http://la-roofers.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160b7cdc3c6665---11072451330.pdf
- http://erictex.com/ufiles/files/55079156536.pdf
- http://dawahcity.com/userfiles/file/95857256960.pdf
- http://bruisedreedfoundation.org/clients/4/4d/4d9d7eec3bf3a09fa0457ace138f6a4e/File/90623393717.pdf
- https://svingenieria.cl/userfiles/file/xorabofu.pdf
- http://yaeram.com/userData/board/file/24280819626.pdf
- http://kapalishakti.com/ckfinder/userfiles/files/43206360268.pdf
- http://iideree.org/wp-content/plugins/formcraft/file-upload/server/content/files/160b9f63bf2c9a---95974121503.pdf
- http://vipforiraq.com/userfiles/files/xokadulasoga.pdf
- http://aarogyamedico.com/userfiles/file/42048548045.pdf
- http://serdceprirody.ru/userfiles/file/57305679938.pdf
- http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160965d7b4fb79---kuravaruranekununonarimo.pdf
- https://frontiersneurophotonics.org/wp-content/plugins/formcraft/file-upload/server/content/files/1/16093cf650aba1---jojizi.pdf
- http://sun-green.nl/ckfinder/userfiles/files/gapoxogilow.pdf
- https://www.higher-energy-trampolineclub.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c481bb9eb41---kenewaved.pdf
- http://hrudolf.com/userfiles/16545689969.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a0307626a10---vademevive.pdf
- https://freedomhypnosisnyc.com/wp-content/plugins/super-forms/uploads/php/files/c007a945343c275ee3f6a5c14db9f9c9/3495974566.pdf
- http://dabien.co.kr/wp-content/plugins/formcraft/file-upload/server/content/files/160909f946001b---gudiketepagudegoj.pdf
- http://drapikowski.pl/uploaded/fck_files/file/dezer.pdf
- http://rld-carbon.ru/file/fiwogipemu.pdf
Embedded domains
- medvor.ru
- muszempilla.com
- newbusan.net
- 27derajat.com
- la-roofers.co.uk
- erictex.com
- dawahcity.com
- bruisedreedfoundation.org
- yaeram.com
- kapalishakti.com
- iideree.org
- vipforiraq.com
- aarogyamedico.com
- serdceprirody.ru
- prodesign31.ru
- frontiersneurophotonics.org
- sun-green.nl
- www.higher-energy-trampolineclub.com
- hrudolf.com
- www.1000ena.com
- freedomhypnosisnyc.com
- dabien.co.kr
- drapikowski.pl
- rld-carbon.ru
- dmddsgn.com
File paths
- y:\$WBS
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report