MALICIOUS — xilisimosanazikelu.pdf
MALICIOUS — xilisimosanazikelu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4c4135def0a17a259b2c17676ac3f63e515c7cfbdbc229086e90017d3464ad44 - SHA-1:
54c6646621c6bb67f13bb1ddc2b4c4c36d62b2e2 - MD5:
63c267287f792460fd834634c879066e - ssdeep:
1536:+jugvELdF5HYzNxQA6TK6MA+O/AwV5Omuo8A/IQr3W1CGCBAW6pOu2ElecC:e7YL4zNxo+O4wV5OeBICG8pu2ElW - TLSH:
T1BD38CFF31057DD4D7A4B8F072EEB51A4A08ADB8C3623D594408CBA6CC97C1BDBE44A61 - Submitted as: xilisimosanazikelu.pdf
- File type: pdf · Size: 83612 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://smepil.com/ckeditor/userfiles/files/71340971559.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ltgtrends.com/wp-content/plugins/super-forms/uploads/php/files/2d0e400950e66a1b2fad8945f165ee1c/tebin.pdf, http://vanhacollection.com/images/files/zisipu.pdf, https://www.criteriainvest.com.br/wp-content/plugins/super-forms/uploads/php/files/rnlde7sum9sjmfjdio1p93tonu/98217360849.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1KS0DP0cxss/uplcv?utm_term=pineal+gland+function+pdf
- https://ltgtrends.com/wp-content/plugins/super-forms/uploads/php/files/2d0e400950e66a1b2fad8945f165ee1c/tebin.pdf
- http://vanhacollection.com/images/files/zisipu.pdf
- https://www.criteriainvest.com.br/wp-content/plugins/super-forms/uploads/php/files/rnlde7sum9sjmfjdio1p93tonu/98217360849.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16081f29fa075d---kekumunenugiza.pdf
- http://kondicionery-dolgoprudny.ru/upload_picture/file/lafemujivinotel.pdf
- https://www.truesdalepainting.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606e98180b28e---49810987033.pdf
- http://smepil.com/ckeditor/userfiles/files/71340971559.pdf
- https://advicezone.org.uk/wp-content/plugins/super-forms/uploads/php/files/8e2m6gc5kcd01l6hr56pj63e03/99653872647.pdf
- https://law.myvzl.com/wp-content/plugins/super-forms/uploads/php/files/7skdl5t5kveelmfd76n5892as1/gejava.pdf
- http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a0d9c9eb3ee---42171182277.pdf
- https://justforjetscatering.com/userfiles/image/files/70364526909.pdf
- https://maintogelonline2.com/contents//files/gilimalofeba.pdf
- https://shindah.com/images/ckeditor_img/files/38700608804.pdf
- https://finestblogger.de/wp-content/plugins/super-forms/uploads/php/files/g0a12k8l3jn3hd87t236vo4537/wufala.pdf
- http://ratchadatitan.com/UserFiles/File/36965984248.pdf
- http://for-rent-antwerp.com/wp-content/plugins/formcraft/file-upload/server/content/files/16113da1492e73---74039992568.pdf
- http://cw-cut.com/uploads/file/kejebidovep.pdf
- http://allycatering.com/userfiles/81401877436.pdf
- https://nepalimodelagency.com/userfiles/file/xugunawijir.pdf
- https://edebmachine.com/images/media/files/wijidimowefov.pdf
- http://oaklandscreche.ie/userfiles/files/xatasa.pdf
- http://overtonnation.com/clients/f/f9/f97855507a39dfa58978186db9bff07a/File/35981581378.pdf
- https://rrvchefs.com/wp-content/plugins/super-forms/uploads/php/files/39945450bff40747c936a1d1dfe904ea/24721623213.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- ltgtrends.com
- vanhacollection.com
- www.criteriainvest.com.br
- www.1000ena.com
- kondicionery-dolgoprudny.ru
- www.truesdalepainting.com
- smepil.com
- advicezone.org.uk
- law.myvzl.com
- www.marsagri.com
- justforjetscatering.com
- maintogelonline2.com
- shindah.com
- finestblogger.de
- ratchadatitan.com
- for-rent-antwerp.com
- cw-cut.com
- allycatering.com
- nepalimodelagency.com
- edebmachine.com
- overtonnation.com
- rrvchefs.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report