MALICIOUS — vevekavenupezixo.pdf
MALICIOUS — vevekavenupezixo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
59c24188c6173cefb2824490506abdd5c5d00ae40aa488719faaac85306a3f6f - SHA-1:
baa37f4946395b31e1a185977387027c83d9e4e1 - MD5:
09fa46193590658801118c6014d280bc - ssdeep:
1536:NY1buYG/6489FhZXQKwldJA31SZUIWC9/Q5uJ0MMvWspORVjS:e1yFRiFhdrCzcYyZ5uCMM+Rc - TLSH:
T13337BFF320D7DD9C775B8B0759F614A9A08ED7886132EA404188B76C91BC2BE7E14B50 - Submitted as: vevekavenupezixo.pdf
- File type: pdf · Size: 71198 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://truhlarstvisollner.cz/data/file/28414288929.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://www.partyshuttlebus.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1613d5c496b0fb---kibomowogobusur.pdf, http://tyextractor.com/d/files/zejidadotexawuvitivupidal.pdf, http://autosoftware.company/autoresponders_images/files/gikenebarubo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/DOqCt-cVA4I/uplcv?utm_term=how+to+log+out+of+my+hotmail+account
- https://www.partyshuttlebus.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1613d5c496b0fb---kibomowogobusur.pdf
- http://tyextractor.com/d/files/zejidadotexawuvitivupidal.pdf
- http://autosoftware.company/autoresponders_images/files/gikenebarubo.pdf
- http://toyotarent.kr/FileData/ckfinder/files/20210916_75342DEC16C03EDC.pdf
- http://abwingsmd.com/uploads/files/29291534344.pdf
- http://b40555.handyfriendship.com/upload/files/54301513145.pdf
- https://dm288.rs/slicice/file/gepexogebif.pdf
- http://truhlarstvisollner.cz/data/file/28414288929.pdf
- https://sistemagestiondpr.com/userfiles/file/varuvamixul.pdf
- https://sg-design.top/wp-content/plugins/super-forms/uploads/php/files/90fe10811e80c9eede8b9bb58d0a5c5a/35633820629.pdf
- https://giga-tronics.com/userfiles/files/zewulegetadabalej.pdf
- http://aucoindeshalles.com/menu/file/73566684879.pdf
- http://maryalo.com/userData/board/file/towugadus.pdf
- http://studiodispirito.it/userfiles/file/xivivulukojuxudaje.pdf
- http://thm-holding.ru/wp-content/plugins/super-forms/uploads/php/files/c7196804237fe1e7d3d232a891fe2c14/33561402538.pdf
- https://deepex.hu/hirek/files/xozuvatazekasenogiluw.pdf
- http://slenderclub.cz/ckfinder/userfiles/files/bavijapusepejogiwexupe.pdf
- http://ed-web.cz/userfilesfile/mupododuwa.pdf
- http://www.bluefashion.cz/ckfinder/userfiles/files/sikiwitusubules.pdf
- http://www.pzkexie.com/up_files/file/76698940330.pdf
- http://pibar.tw/uploads/files/202109120958289436.pdf
- http://bastola.org/userfiles/file/10724226815.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- www.partyshuttlebus.com.au
- tyextractor.com
- toyotarent.kr
- abwingsmd.com
- b40555.handyfriendship.com
- sistemagestiondpr.com
- sg-design.top
- giga-tronics.com
- aucoindeshalles.com
- maryalo.com
- studiodispirito.it
- thm-holding.ru
- www.pzkexie.com
- pibar.tw
- bastola.org
- www.w3.org
- purl.org
- ns.adobe.com
- autosoftware.company
- dm288.rs
- truhlarstvisollner.cz
- deepex.hu
- slenderclub.cz
- ed-web.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report