MALICIOUS — 16131af2e6fcc3---gutuka.pdf
MALICIOUS — 16131af2e6fcc3---gutuka.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6939b6afb85eed3b91b5439b83d905d07aa2356e5113e6a85135cc3ccb133be6 - SHA-1:
ec5bed371bd6f014ee53270e3d0abe70814a5eeb - MD5:
26481d2e771091a744ff0eb2802b16f4 - ssdeep:
1536:SkLN/oZWvDVSA2fMBUnePGCvIQgU6b0pNt5aWvKVJV7A11WspO2Oly:RuKDVS9fPneupUYg5JKF7A1c29 - TLSH:
T1F839D0F330DBED0CB79B9F4365AA015C609AD7486125CAA0508CB37CC6BC8BD7E95A50 - Submitted as: 16131af2e6fcc3---gutuka.pdf
- File type: pdf · Size: 87514 bytes
- Verdict: malicious (97/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: http://asbufestival.com/uploads/FCK_files/file/loduguxirufaxiruvuta.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=direct+and+indirect+speech+examples+with+answers+pdf, http://www.yevres.fr/ckfinder/userfiles/files/zonasopakagurezazubur.pdf, https://micast.de/wp-content/plugins/super-forms/uploads/php/files/5s76fancekitsb7o7snpu12sgb/wupegimuvaxize.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/uplcv?utm_term=direct+and+indirect+speech+examples+with+answers+pdf
- http://www.yevres.fr/ckfinder/userfiles/files/zonasopakagurezazubur.pdf
- https://micast.de/wp-content/plugins/super-forms/uploads/php/files/5s76fancekitsb7o7snpu12sgb/wupegimuvaxize.pdf
- http://hainfelderteich.at/wafizepafowedudof.pdf
- http://asbufestival.com/uploads/FCK_files/file/loduguxirufaxiruvuta.pdf
- http://edu-tur.ru/userfiles/file/gumexapemumavarim.pdf
- https://tocgia247.com/wp-content/plugins/super-forms/uploads/php/files/mik33e7nqptrrp3vtvi3bg41et/mazogevar.pdf
- https://wcdt.co.th/wp-content/plugins/super-forms/uploads/php/files/qcbiv2jrhairoqniqdcf10mq0q/ribuzisukiperofewejez.pdf
- http://charmingcurls.se/upload/file/40110929013.pdf
- http://ne-moloko.ee/wp-content/plugins/super-forms/uploads/php/files/9a77ef8455620e5aeed056ef83830442/24811976124.pdf
- http://trips-in.com/ckupload/files/90207028925.pdf
- https://cananalimdar.com/wp-content/plugins/super-forms/uploads/php/files/23gnjbb9ol6rs287fpgvdaiu3d/93700716292.pdf
- https://avigailpekelman.com/sites/default/files/file/fixubajuwulafop.pdf
- http://rockpapersun.com/upload_mce_image/file/63849655837.pdf
- http://bergfin.se/wp-content/plugins/formcraft/file-upload/server/content/files/1607807cff2f65---98828446255.pdf
- http://mopron.ru/upload/files/30763543918.pdf
- http://bartuceviri.com/userfiles/file/82591420239.pdf
- https://ibrahimkoc.com/images/Media/files/walaxak.pdf
- https://yarsan.ru/wp-content/plugins/super-forms/uploads/php/files/aa3745eb9cd54022a97506f528335101/dujoxazoneka.pdf
- http://burragebrothers.org/demo/jolie/beta/userfiles/files/barisisivad.pdf
- https://amenagementsoleil.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078f7feae0f3---80323100388.pdf
- https://chocoinmobiliario.com/wp-content/plugins/super-forms/uploads/php/files/b3982a72622f8a1e62cb152b7ed64aaf/witogadag.pdf
- http://www.thelawchamber.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608742bb9d688---sesagarirexukadewekevi.pdf
- https://blackknowledge.com/wp-content/plugins/super-forms/uploads/php/files/689d8840b1579028de647c14af1b160b/96666950077.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- medvor.ru
- www.yevres.fr
- micast.de
- asbufestival.com
- edu-tur.ru
- tocgia247.com
- charmingcurls.se
- trips-in.com
- cananalimdar.com
- avigailpekelman.com
- rockpapersun.com
- bergfin.se
- mopron.ru
- bartuceviri.com
- ibrahimkoc.com
- yarsan.ru
- burragebrothers.org
- amenagementsoleil.com
- chocoinmobiliario.com
- www.thelawchamber.com
- blackknowledge.com
- www.w3.org
- purl.org
- ns.adobe.com
- hainfelderteich.at
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report