MALICIOUS — 1613b3ab6a4308---puxiwababu.pdf
MALICIOUS — 1613b3ab6a4308---puxiwababu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
64b9fac737a76cf9569b3797e30ad97a89aebc928b76a13672ac4ad4cb54690d - SHA-1:
451425f8d51b29474f12fc3fa3595431c91ccd7f - MD5:
448ad3ebd17da884342b6874b0dde751 - ssdeep:
1536:HyPolACS5xWAQyrTzTN7kkpzvT1USXJzt2s137rZDZWbpONghdW+H9ShCVGd0:SWAiyrfXzvTeSX5t73JDbNghF9ShQZ - TLSH:
T1E439C0F310E7DC8CB66ADF172DE60158A4D9D7C82263FA508088B76C923CABE7E14551 - Submitted as: 1613b3ab6a4308---puxiwababu.pdf
- File type: pdf · Size: 91037 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://flashdisplay.net/UploadFiles/FCKeditor/20210903091702.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://krisoc.ru/uplcv?utm_term=viva+tv+mod+apk, https://loyallcanada.net/editor_files/file/81511166596.pdf, https://stehovani-ostrava.cz/static_pages_files/file/jovuwuxubud.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://krisoc.ru/uplcv?utm_term=viva+tv+mod+apk
- https://loyallcanada.net/editor_files/file/81511166596.pdf
- https://stehovani-ostrava.cz/static_pages_files/file/jovuwuxubud.pdf
- https://lecormier-menuiserie.com/www/upload/files/82444133380.pdf
- https://www.alertgy.com/wp-content/plugins/super-forms/uploads/php/files/1c9d07c9f23559ec49a644cc3d4e5d85/49921343163.pdf
- http://viorina-deko.com/images/file/zutosisomifomamoguw.pdf
- http://flashdisplay.net/UploadFiles/FCKeditor/20210903091702.pdf
- https://kingdomdatesuae.com/userfiles/files/sagulofigibigulux.pdf
- http://ijfbn.com/editor_up/bufaridatavifivik.pdf
- http://itemclinicchina.com/ckupload/files/78807593523.pdf
- https://bluetact.com/ckfinder/userfiles/files/34211873688.pdf
- https://pastelbuilders.com/userfiles/file/bapilinukikevatuje.pdf
- http://kanoonkaraj.ir/dbmanager/filebank/htmlgallery/file///takuw.pdf
- https://truonggiangcompany.com/userfiles/file/xokakubunetatosowavej.pdf
- http://okna-dvere-online.cz/media/upload/upload/file/50399490162.pdf
- http://mko-yug.ru/wp-content/plugins/super-forms/uploads/php/files/85f13f2450092b9c7d66c42453781ce1/54046413595.pdf
- https://gobelsprofil.com/upload/files/mopaseki.pdf
- https://canionglobal.com/FCKeditor/file/vegofagobile.pdf
- http://muabannhagiare.net/images/uploads/files/65173317951.pdf
- http://epodhajska.eu/UserFiles/File/68238330805.pdf
- http://rdmsrl.it/userfiles/files/zivaferagitawe.pdf
- https://trichynext.com/wp-content/plugins/super-forms/uploads/php/files/8fdb859a04ad4a66189305f8fdda12db/muwop.pdf
- http://miet-boot.ch/images/uploadedimages/file/gajedaponutagajabanewavi.pdf
- https://papiratisk.cz/soubory/vinixiz.pdf
- http://ovartec.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613a83aa4fa94---50249770365.pdf
Embedded domains
- krisoc.ru
- loyallcanada.net
- lecormier-menuiserie.com
- www.alertgy.com
- viorina-deko.com
- flashdisplay.net
- kingdomdatesuae.com
- ijfbn.com
- itemclinicchina.com
- bluetact.com
- pastelbuilders.com
- kanoonkaraj.ir
- truonggiangcompany.com
- mko-yug.ru
- gobelsprofil.com
- canionglobal.com
- muabannhagiare.net
- epodhajska.eu
- rdmsrl.it
- trichynext.com
- miet-boot.ch
- ovartec.com
- sochi-polyana.com
- speak82.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report