MALICIOUS — 160fe2fff4c9fb---kokizorunogowogojos.pdf
MALICIOUS — 160fe2fff4c9fb---kokizorunogowogojos.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4f754845d2250c5dfc528508852f7409c7162bbe9638158add2e712fc03f2124 - SHA-1:
13d0e048b594cdc472df229f6d403c691cd789b4 - MD5:
75fe98d549d702028a32b5c9caf1d76f - ssdeep:
1536:mMhFIENgC+Opt3LBi7YFhYTADVXhA4SVbr92wniu8+65EWLowHsFGe0iWcpOmZER:L391FhYkZXhA4SVbr92wniuITe0Fm8 - TLSH:
T15E39CFF321E7DD5CBB4A8B4369BB106C958AE7886262E9500584F36CC4BC6BDBF24510 - Submitted as: 160fe2fff4c9fb---kokizorunogowogojos.pdf
- File type: pdf · Size: 89730 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://michaels-limo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607ae6063add9---videnamavifuwapela.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://drivingschoolofnorthtexas.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c29cd2c0c70---71454422664.pdf, https://greshamgilessalon.com/wp-content/plugins/super-forms/uploads/php/files/bf85f46da87bab99e8a447966c6cde9c/63990265797.pdf, https://neavocats.com/wp-content/plugins/super-forms/uploads/php/files/793f608ad69cfdf14fc4ae7475c9e31a/90075858692.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/6naE_Nh8_CY/uplcv?utm_term=abasyn+university+islamabad+admission+form+2018
- https://drivingschoolofnorthtexas.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c29cd2c0c70---71454422664.pdf
- https://greshamgilessalon.com/wp-content/plugins/super-forms/uploads/php/files/bf85f46da87bab99e8a447966c6cde9c/63990265797.pdf
- https://neavocats.com/wp-content/plugins/super-forms/uploads/php/files/793f608ad69cfdf14fc4ae7475c9e31a/90075858692.pdf
- http://www.waetsukai.jp/system/ckfinder/userfiles/files/dukixukigukuturesib.pdf
- https://hartwellcook.com/wp-content/plugins/super-forms/uploads/php/files/71f25cb633723bdd8022e927ec367918/85232964455.pdf
- https://michaels-limo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607ae6063add9---videnamavifuwapela.pdf
- http://for-rent-leuven.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a00fd4b01ed---firekibajup.pdf
- https://aihr-iadh.org/uploads/FCK_files/file/bolekugor.pdf
- http://aiswaryamatrimonials.com/fck_uploads/file/63217238643.pdf
- https://www.kiteschule-kiel.de/wp-content/plugins/formcraft/file-upload/server/content/files/160e188a957410---sowanis.pdf
- http://www.mvdisposal.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c463be26482---nuduwumekinatuzezowev.pdf
- https://presstone.hu/userfiles/file/16495183391.pdf
- http://artecgroupservices.com/imagenes/file/dawad.pdf
- http://stalmost.pl/userfiles/file/xivelevokoxofi.pdf
- https://dazzlin.co.uk/wp-content/plugins/super-forms/uploads/php/files/6836e69704e94cfcc0995c0af1e824d9/50190382620.pdf
- http://plafondchauffant.fr//img/user/file/zefezukoronivixeg.pdf
- http://bertrandetgastineaudesigners.com/userfiles/file/45821373092.pdf
- https://ecoinkworld.com/wp-content/plugins/super-forms/uploads/php/files/7870d9fb70f3b406fcc6abb1c4ce8c54/49868803028.pdf
- http://tsradviseurs.nl/mailing/images/photo/file/foselifubefulevo.pdf
- https://adm.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/2a92847013dded99be182d03144ff145/7068061021.pdf
- https://www.andimoda.com/wp-content/plugins/super-forms/uploads/php/files/6ebe749f71f43dc11ff39c6d320e4aba/98417299767.pdf
- http://svs-pm.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a5d80cf3356---kuwulolives.pdf
- http://ne-moloko.ee/wp-content/plugins/super-forms/uploads/php/files/109fd3bc93fd144994be686fd50c9642/2929821765.pdf
- http://ahsaipu.com/v15/Upload/file/20214291649124259.pdf
Embedded domains
- feedproxy.google.com
- drivingschoolofnorthtexas.com
- greshamgilessalon.com
- neavocats.com
- www.waetsukai.jp
- hartwellcook.com
- michaels-limo.com
- for-rent-leuven.com
- aihr-iadh.org
- aiswaryamatrimonials.com
- www.kiteschule-kiel.de
- www.mvdisposal.com
- artecgroupservices.com
- stalmost.pl
- dazzlin.co.uk
- plafondchauffant.fr
- bertrandetgastineaudesigners.com
- ecoinkworld.com
- tsradviseurs.nl
- adm.allianceflooring.net
- www.andimoda.com
- svs-pm.com
- ahsaipu.com
- novichiha.ru
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report