MALICIOUS — 1608852277842a---zesetovenuvow.pdf
MALICIOUS — 1608852277842a---zesetovenuvow.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
616eeb434d84e14d83dc316c5a156443d62a5181bea235eac02a45e2a88dd348 - SHA-1:
1f03bb2b315160f09261ff50baf0a56de8abedf9 - MD5:
3e2b8d6707fa544fcc895a0ceacd5c43 - ssdeep:
1536:FoYcwvv6I34oDeFYbfjWDGDYEUS22Y/MAoqLcnKf9kP0G2cWcS:OwX74DSjUGDLUSTY0qLwcqP0G2c8 - TLSH:
T10B39E1F371CBCDCC6A4BAB537AD510643441D798B1339B684484FB9CC058BBEAE64A11 - Submitted as: 1608852277842a---zesetovenuvow.pdf
- File type: pdf · Size: 91395 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071efdf30b64---3941184961.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://dodici12.ru/wp-content/plugins/super-forms/uploads/php/files/dgajp1d5qf9ud7h0ltp9le19j1/30119217802.pdf, http://bazatalty.pl/wp-content/plugins/super-forms/uploads/php/files/ee4ed46e5a3e26e2818152d2e26670b6/86834421396.pdf, https://akdenizokullari.k12.tr/wp-content/plugins/super-forms/uploads/php/files/esh81uc5iu6v1vv14fgsnso3d7/9840933032.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/PmAiG5ZyT-k/uplcv?utm_term=apes+biogeochemical+cycles+worksheet+answers
- http://dodici12.ru/wp-content/plugins/super-forms/uploads/php/files/dgajp1d5qf9ud7h0ltp9le19j1/30119217802.pdf
- http://bazatalty.pl/wp-content/plugins/super-forms/uploads/php/files/ee4ed46e5a3e26e2818152d2e26670b6/86834421396.pdf
- https://akdenizokullari.k12.tr/wp-content/plugins/super-forms/uploads/php/files/esh81uc5iu6v1vv14fgsnso3d7/9840933032.pdf
- https://funkydrop.shop/wp-content/plugins/super-forms/uploads/php/files/4dd3ba46e5791fca6edefd0592dd4e84/vififowexusofonuberali.pdf
- http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071efdf30b64---3941184961.pdf
- https://gift-edu.ru/wp-content/plugins/super-forms/uploads/php/files/66cfe4d910070f5181d6b3fe9f040a41/bunasezozepadevedu.pdf
- https://gift-edu.ru/wp-content/plugins/super-forms/uploads/php/files/93b061932a1d394c05c5d9b6d7f6682e/8238707217.pdf
- https://centar-znr-zop.hr/wp-content/plugins/formcraft/file-upload/server/content/files/16070539aeaf0c---mavigo.pdf
- http://kwik-it.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1606f2b152e89e---94696790997.pdf
- https://alignerco.com/wp-content/plugins/super-forms/uploads/php/files/84c463f8467bbedc669d017547ef6c22/63437560855.pdf
- http://inspirationallabels.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1607a250ebd0dc---62093601775.pdf
- https://www.andimoda.com/wp-content/plugins/super-forms/uploads/php/files/eba64ab973d690601421d706dba116d4/nasujugitowutozurexavosa.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160726c058d983---62182057057.pdf
- https://drivingschoolofnorthtexas.com/wp-content/plugins/formcraft/file-upload/server/content/files/16072f6ed28f89---64331747975.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- dodici12.ru
- bazatalty.pl
- funkydrop.shop
- leap-egypt.com
- gift-edu.ru
- kwik-it.ru
- alignerco.com
- inspirationallabels.co.uk
- www.andimoda.com
- www.1000ena.com
- drivingschoolofnorthtexas.com
- www.w3.org
- purl.org
- ns.adobe.com
- akdenizokullari.k12.tr
- centar-znr-zop.hr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report