MALICIOUS — xufawetoleso.pdf
MALICIOUS — xufawetoleso.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
5ef5f6abdaa43dea14b3bbc58e635aa628fba9b305080e82d5fdbafca18a53dc - SHA-1:
498e35f7d151331b0e4a51c3a1ee557692c29702 - MD5:
64f52342ec4730ad8667e3fef12e71b1 - ssdeep:
1536:RBNHl4ns/JnQqbogRJB4J1pNABl+YwB0FGZsj0fG8lX008yLNISnWOpOwrKW81mR:VHl4nPqHJB013ABnwB6GZs4fN8yTkwrN - TLSH:
T1F53AC0F362ABCC5D278BCB17A9DB01A89046D2C86321E55459CCB26CD4BCE7DBF10851 - Submitted as: xufawetoleso.pdf
- File type: pdf · Size: 93521 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://www.penyembuhanholistikreiki.com/wp-content/plugins/formcraft/file-upload/server/content/files/160fd894d2e06a---mapepesinadegodo.pdf, https://monarchwinemerchants.com/wp-content/plugins/super-forms/uploads/php/files/1716cf8c695be0da02264cd191b5f51b/gajegobivurolanujomiv.pdf, https://charterfori.ir/basefile/charterforiir/files/79896409595.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/Om9ozkHLxGw/uplcv?utm_term=mitsubishi+galant+2008+manual
- https://www.penyembuhanholistikreiki.com/wp-content/plugins/formcraft/file-upload/server/content/files/160fd894d2e06a---mapepesinadegodo.pdf
- https://monarchwinemerchants.com/wp-content/plugins/super-forms/uploads/php/files/1716cf8c695be0da02264cd191b5f51b/gajegobivurolanujomiv.pdf
- https://charterfori.ir/basefile/charterforiir/files/79896409595.pdf
- https://fruzsiflame.hu/userfiles/file/memakuladelakidoviji.pdf
- http://teenaramainc.org/clients/875997/File/47626470522.pdf
- http://nessium.net/userfiles/file/balol.pdf
- http://dalaichau.com/files/23061928845.pdf
- http://nikoljski.com/ckfinder/userfiles/files/27188750623.pdf
- http://www.jimenez-casquet.com/wp-content/plugins/formcraft/file-upload/server/content/files/16081b37c15ab0---75018674110.pdf
- https://oklogistic.lv/upload/file/64654371067.pdf
- http://lavera.it/wp-content/plugins/formcraft/file-upload/server/content/files/160c87d45298ca---tafaxesinevoxexilag.pdf
- https://brothers-music.com/ckfinder/userfiles/files/52930535680.pdf
- http://giprozdraw.ru/ckfinder/userfiles/files/daruwesazurumitu.pdf
- http://zelene-centrum.cz/webpagebuilder/ckfinder/userfiles/files/76787268000.pdf
- https://kompaspt1.com/contents//files/kuwevodisobizanar.pdf
- http://unipell.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608090fc59ff1---wiriwexizakujere.pdf
- http://joy05.com/_UploadFile/Images/file/vijerogenigukosovefurijum.pdf
- https://goldengrowers.com/wp-content/plugins/super-forms/uploads/php/files/d5a2a7d2e21dd0580faab85c12675bee/wulumogijomaxedumasuji.pdf
- http://uat2.hkha.com.hk/ckfinder/userfiles/files/92563903352.pdf
- https://www.inkfactory.pk/wp-content/plugins/formcraft/file-upload/server/content/files/16117854679d9e---22692596080.pdf
- https://soft-print.pl/app/webroot/media/files/21731783256.pdf
- https://carpanea.it/wp-content/plugins/super-forms/uploads/php/files/88956350f469ce3ed0707f6efc502227/xazaji.pdf
- https://alfa-pechati.ru/wp-content/plugins/super-forms/uploads/php/files/4b926411ed1be72ff8f1d0841f0a1306/zuzefakejeror.pdf
- http://ar-intl.net/wp-content/plugins/super-forms/uploads/php/files/vpcs2onv8sbap3ocsho12klb33/8160561822.pdf
Embedded domains
- feedproxy.google.com
- www.penyembuhanholistikreiki.com
- monarchwinemerchants.com
- charterfori.ir
- teenaramainc.org
- nessium.net
- dalaichau.com
- nikoljski.com
- www.jimenez-casquet.com
- lavera.it
- brothers-music.com
- giprozdraw.ru
- kompaspt1.com
- unipell.com.br
- joy05.com
- goldengrowers.com
- uat2.hkha.com.hk
- soft-print.pl
- carpanea.it
- alfa-pechati.ru
- ar-intl.net
- www.gasserbush.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report