MALICIOUS — tiwofedemol.pdf
MALICIOUS — tiwofedemol.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
70183e7d759209ad1b415a9a7d0ea8f1000476f7aae88bbf9cc7b66cf5273853 - SHA-1:
5e34bd7979c8c7b4e7a02a78652e0c243198d926 - MD5:
5cb3799238ff50d439edd8a41d667012 - ssdeep:
1536:kN37Ww/eOtigObuYsKLFdq5UDOVVxFHXJHUb5Wxd7nNXjW8pO+IzhB7u2P:wWw2lgOHq5UyVTueXK+IjB - TLSH:
T10738BFF3206BDD5C770BAB439DFE11B97486E28C2022DA9054987BAC997C87D7F04A50 - Submitted as: tiwofedemol.pdf
- File type: pdf · Size: 82280 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://hitechdentalhouston.com/uploads/files/26828122214.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://hitechdentalhouston.com/uploads/files/26828122214.pdf, https://hopefor.today/wp-content/plugins/super-forms/uploads/php/files/97e2f08bac43760b2d91d82ba2d7f6a5/86072126603.pdf, https://bokseinstituttet.dk/wp-content/plugins/formcraft/file-upload/server/content/files/1613ece0a7046b---34488408464.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1KS0DP0cxss/uplcv?utm_term=linear+algebra+done+right+3rd+edition+pdf
- http://hitechdentalhouston.com/uploads/files/26828122214.pdf
- https://hopefor.today/wp-content/plugins/super-forms/uploads/php/files/97e2f08bac43760b2d91d82ba2d7f6a5/86072126603.pdf
- https://bokseinstituttet.dk/wp-content/plugins/formcraft/file-upload/server/content/files/1613ece0a7046b---34488408464.pdf
- https://proff-doors.ru/wp-content/plugins/super-forms/uploads/php/files/a5231402dc29528ecd734b455bbd4ab5/39721497745.pdf
- https://dottoridegregorio.it/public/file/nutonupuxiroru.pdf
- http://shuimotongyuan.com/userfiles/file/56938587617.pdf
- http://fotosvatba.net/userfiles/file/kotasebusajarelugo.pdf
- http://www.stratcareerservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/16137b7d3845c0---lupagetuxuman.pdf
- https://buddingheights.org/wp-content/plugins/formcraft/file-upload/server/content/files/1613af3d0b0020---10441214915.pdf
- https://tenekedjieva.com/uploads/file/ruwenilazudifo.pdf
- http://shinserviceodi.ru/wp-content/plugins/super-forms/uploads/php/files/69962dbf897ede726d2b9e2f1ae344f0/22759542009.pdf
- https://vrrc.heart.net.tw/ckfinder/ckfiles/files/vapurugobamifowaketaruru.pdf
- http://urdu-hadith.com/survey/userfiles/files/barujidirizuxufux.pdf
- http://studiotecnicodambra.eu/userfiles/files/42894101526.pdf
- http://punaide.com/userfiles/files/begafaropotadenefibaful.pdf
- http://www.cemeba.com/uploads/ckfinder/files/sopusa.pdf
- https://wilocom.ro/ckfinder/userfiles/files/gumegonozobotawizu.pdf
- http://jingluo.net/uploadfiles/files/retoterakipera.pdf
- http://suriyedostlukdernegi.org/image/files/pogisuxixumadalo.pdf
- http://www.pattyn360.com/upload/forum/files/60712014921.pdf
- http://sanmorales.es/userfiles/files/2530720241.pdf
- https://takipcisec.com/calisma2/files/uploads/kixekebokog.pdf
- http://petra-koparki.pl/Upload/file/nowaxagokisiz.pdf
- https://sibiucuratenie.ro/fckeditor/userfiles/file/rewozopolezawigivi.pdf
Embedded domains
- feedproxy.google.com
- hitechdentalhouston.com
- hopefor.today
- proff-doors.ru
- dottoridegregorio.it
- shuimotongyuan.com
- fotosvatba.net
- www.stratcareerservices.com
- buddingheights.org
- tenekedjieva.com
- shinserviceodi.ru
- vrrc.heart.net.tw
- urdu-hadith.com
- studiotecnicodambra.eu
- punaide.com
- www.cemeba.com
- jingluo.net
- suriyedostlukdernegi.org
- www.pattyn360.com
- sanmorales.es
- takipcisec.com
- petra-koparki.pl
- hanasushi6.com
- solener.info
- staropolski.net
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report