MALICIOUS — bofevof.pdf
MALICIOUS — bofevof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
5659ffcee1f4a8bfb42c62f6e7337d369f262ad6aa8d32572c2b0043c3d920b4 - SHA-1:
aadbd9b49a85b4e9c0b64d66497acbd35daa1b44 - MD5:
403f855c716170db64dfb65b7e0dd133 - ssdeep:
1536:fJhSMMfKvQgdxaT+UX6zvDf1oBV+WYpO2+WGckqLfaSakn:OMqKvZdxDZHWVF2AqLfJV - TLSH:
T12B38CFF3614BEC4C779A8B437EEA11B9A04ED3882156E75144C8766CC6BC9FCAF00952 - Submitted as: bofevof.pdf
- File type: pdf · Size: 79777 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://www.benvenutialmare.com/wp-content/plugins/formcraft/file-upload/server/content/files/160803b91b9424---toxig.pdf, https://www.keystonecare.co.uk/wp-content/plugins/super-forms/uploads/php/files/7c4a9ea7a8655a853a9cf8a1f85ea92f/ganipoj.pdf, https://mytalk7.com/_UploadFile/Images/file/57850839138.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/YTWXjIUwRh0/uplcv?utm_term=powershell+convert+base64+to+pdf
- http://www.benvenutialmare.com/wp-content/plugins/formcraft/file-upload/server/content/files/160803b91b9424---toxig.pdf
- https://www.keystonecare.co.uk/wp-content/plugins/super-forms/uploads/php/files/7c4a9ea7a8655a853a9cf8a1f85ea92f/ganipoj.pdf
- https://mytalk7.com/_UploadFile/Images/file/57850839138.pdf
- http://www.k-24.com/wp-content/plugins/formcraft/file-upload/server/content/files/16070a3537a289---regutirakepevesa.pdf
- http://tw-go.org/files/93898108953.pdf
- http://makesomenoise.hu/upload/file/welejatopoxese.pdf
- http://ikkosushi.com/uploads/files/90978610111.pdf
- http://enerkonelektrik.com/ckfinder/userfiles/files/sivuvunodokirebugeben.pdf
- http://www.telsercom.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608415159cfc4---42152933684.pdf
- http://dchs80.com/clients/c/cb/cbc185099defa3274d3d4f74835fd64f/File/88217395250.pdf
- https://www.reparaciondebomba.com.ar/wp-content/plugins/super-forms/uploads/php/files/k3ii0sfjp70sjaglcg826aikc0/kosujomaxozako.pdf
- https://sharidendesignasphalt.com/wp-content/plugins/super-forms/uploads/php/files/d71ce8e6d278cabee7654c45a1ccf8da/vegerol.pdf
- https://www.sussexweddingservices.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160d019ca04710---71631325510.pdf
- https://ph2020.org/ckfinder/userfiles/files/47244741304.pdf
- https://churchosonline.com/wp-content/plugins/super-forms/uploads/php/files/b2e653144a68ed8f9d77da543617386e/69172837446.pdf
- http://pahsclassof2005.com/clients/d/d6/d61c4c031b0f3af13d3e88110ef3a3e1/File/77790036872.pdf
- http://www.verneteco.com/ckfinder/userfiles/files/21587281255.pdf
- http://huiking.cn/uploads/file/200815464624.pdf
- https://yellowstonewildlife.com/tinewogokuvetakobaju.pdf
- https://idea-web.ro/app/webroot/files/userfiles/files/rexubabalurirogeju.pdf
- http://yi-xiang-yuan.com/CKEdit/upload/files/kegukuvemizamulutizivad.pdf
- http://szolnokepul.hu/userfiles/file/40323282587.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- www.benvenutialmare.com
- www.keystonecare.co.uk
- mytalk7.com
- www.k-24.com
- tw-go.org
- ikkosushi.com
- enerkonelektrik.com
- www.telsercom.com
- dchs80.com
- sharidendesignasphalt.com
- www.sussexweddingservices.co.uk
- ph2020.org
- churchosonline.com
- pahsclassof2005.com
- www.verneteco.com
- huiking.cn
- yellowstonewildlife.com
- yi-xiang-yuan.com
- www.w3.org
- purl.org
- ns.adobe.com
- makesomenoise.hu
- www.reparaciondebomba.com.ar
- idea-web.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report