MALICIOUS — tijiwoxajes.pdf
MALICIOUS — tijiwoxajes.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
54f66c8cbeb6d7e049246a7d0edcd77a2fa1b530774300101bc25b014143acc5 - SHA-1:
2b059fd2bece543b016434322e20b7260f96adf1 - MD5:
f0b82b75be0c5f2a8cb1b1da5adc58e8 - ssdeep:
1536:80ImRTSRDfhuuUvFE3PZhd5tsBOssEIGuQoBWHpOvTWKHRj6jwvcZz:QyoDfhutvF0RhyBOsvNWv5l6j8G - TLSH:
T18538C0F321EBDD5CB68A9B036EBB0158714ED68830A2EB905584766CD0BC5BC3F14E52 - Submitted as: tijiwoxajes.pdf
- File type: pdf · Size: 80525 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://autoscuolepintozzi.it/userfiles/files/maxibib.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://leakefamilyreunion.com/clients/63964/File/paraniv.pdf, http://lamgi.pl/ckfinder/userfiles/files/62253667474.pdf, https://vico-domrep.com/ckfinder/userfiles/files/dofigarikerirutixeta.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/3CAf4wW3hvY/uplcv?utm_term=convert+jfif+to+pdf+online
- http://leakefamilyreunion.com/clients/63964/File/paraniv.pdf
- http://lamgi.pl/ckfinder/userfiles/files/62253667474.pdf
- https://vico-domrep.com/ckfinder/userfiles/files/dofigarikerirutixeta.pdf
- http://bagiez.de/userfiles/file/bibofovemurifazozisobiz.pdf
- http://adabaskimerkezi.com/upload/file/sotogolo.pdf
- http://autoscuolepintozzi.it/userfiles/files/maxibib.pdf
- https://mosoptagro.ru/wp-content/plugins/super-forms/uploads/php/files/3c0c14db91161317994c5af73134618a/87003040217.pdf
- http://nuyewpilot.academy/wp-content/plugins/super-forms/uploads/php/files/0cd48e8e8c25b2e2daf670d895977e89/39298189576.pdf
- https://www.ltgpartners.com/wp-content/plugins/super-forms/uploads/php/files/514151c62574f7b5f0e3bb6e2eb348d8/netinuliduka.pdf
- http://skup-laptopow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b4fe43d293---juxivuxigukegutuziwofemu.pdf
- http://vudafrique.com/wp-content/plugins/super-forms/uploads/php/files/0871fc8bb0e168db7b5c021a282f01c4/baxadusalamiwata.pdf
- http://aitrans.cn/UploadFile/file/F1202107181313358635.pdf
- http://laweasy.kr/userfiles/file/5373023006.pdf
- https://eurouniversal.eu/ckfinder/userfiles/files/kelaloxunekaduwifud.pdf
- https://fanaf.org/article_ressources/file/firiremojajajabiri.pdf
- http://handlpc.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/podurunifalipaxokigirituf.pdf
- http://ufnk.fr/app/webroot/files/file/98981982673.pdf
- http://alfonsoguiggiarchitetto.it/userfiles/files/dotemuduborewo.pdf
- http://americanewbie.com/userfiles/file/44335800612.pdf
- https://agsposure.org/wp-content/plugins/super-forms/uploads/php/files/d5f4c86ccfa4b6424eb105fbc735d238/vivujotigenimazal.pdf
- http://charivne.info/images/file/90257948631.pdf
- https://wilsonbarrera.com/inicio/wp-content/plugins/formcraft/file-upload/server/content/files/160f981347518f---54856975152.pdf
- http://svs-pm.com/wp-content/plugins/formcraft/file-upload/server/content/files/1611b0a81aed88---18317233463.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- leakefamilyreunion.com
- lamgi.pl
- vico-domrep.com
- bagiez.de
- adabaskimerkezi.com
- autoscuolepintozzi.it
- mosoptagro.ru
- www.ltgpartners.com
- skup-laptopow.com
- vudafrique.com
- aitrans.cn
- laweasy.kr
- eurouniversal.eu
- fanaf.org
- handlpc.com
- ufnk.fr
- alfonsoguiggiarchitetto.it
- americanewbie.com
- agsposure.org
- charivne.info
- wilsonbarrera.com
- svs-pm.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report