MALICIOUS — nafowigonenamet.pdf
MALICIOUS — nafowigonenamet.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
77e12b122c2db0698ce5c446cfd4c375564156c3782e8bf1a5cc105af7fe64a4 - SHA-1:
2c674c225159e9aaeb05d5f066ef479099992109 - MD5:
c792d0d83ecc717919435f8066f305fe - ssdeep:
3072:nEYDupfdKZQFE/j4+7cXT3xbkj5e00pn3Gt7MvQ9i:aomFE/jJcXVofh7e - TLSH:
T1213ADFF310A7EE8C6B8B9F0359F6119CA14AD7583666E640408CF66CC87CA7CBF10A51 - Submitted as: nafowigonenamet.pdf
- File type: pdf · Size: 99253 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://golden-candies.ru/webroot/files/files/51672876181.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://lovemyskindayspa.com/clients/d/d9/d99ed7cf7cbac978b7326c22a81d1608/File/35433359272.pdf, https://brahmagnanam.org/fck_uploads/file/ximotegibosi.pdf, https://noukos.gr/wp-content/plugins/formcraft/file-upload/server/content/files/1609a33d681f2a---71777369583.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/BvfzZFkJO3s/uplcv?utm_term=concepts+of+programming+languages+solutions
- http://lovemyskindayspa.com/clients/d/d9/d99ed7cf7cbac978b7326c22a81d1608/File/35433359272.pdf
- https://brahmagnanam.org/fck_uploads/file/ximotegibosi.pdf
- https://noukos.gr/wp-content/plugins/formcraft/file-upload/server/content/files/1609a33d681f2a---71777369583.pdf
- https://hps-gruppe.com/wp-content/plugins/super-forms/uploads/php/files/6um0hlab808s4bk4t4i72ob4sa/84710977378.pdf
- https://metroguards.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160b7e950d1b1c---kusulukowinakikok.pdf
- https://seataclightingalaska.com/wp-content/plugins/super-forms/uploads/php/files/8fdc036d1a803f91fad56d706b81adc4/zesekomusegi.pdf
- https://www.financedeclined.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160a85bbddc903---17176378899.pdf
- http://golden-candies.ru/webroot/files/files/51672876181.pdf
- https://www.medipratik.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cfc83b64ded---29884041797.pdf
- http://files.ibiza-ferien.de/file/7120226688.pdf
- http://toyteepee.com/uploadfiles/file/210517195342772754x2wwk7.pdf
- http://orderkiwicafe.com/uploads/files/xuwokurafedopafewudimitum.pdf
- http://www.advancedevents.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1609c7818924e5---vixakadinivokogomenivupus.pdf
- https://orkhaconstruction.com/wp-content/plugins/super-forms/uploads/php/files/q87812ko7ul9aot8b0c5f4ut9d/553461412.pdf
- http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606eca19f1646---46164938445.pdf
- http://cedresarquitectura.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c8ffc37dd5b---14004705690.pdf
- http://schokobrunnen.com/idata/jezati.pdf
- https://songhong.info/userfiles/file/baditotimepirugaviv.pdf
- http://philippinesroadshow.com/wp-content/plugins/super-forms/uploads/php/files/3100641af2203761097169f7ddba130d/20886972102.pdf
- http://willtorock.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cad60e5d5a0---gowexonozezujo.pdf
- https://www.truesdalepainting.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078aba412db4---6962023675.pdf
- http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16094751212393---retafaxawitokugupufubeg.pdf
- http://lalitas-thaimassage-spa.de/wp-content/plugins/formcraft/file-upload/server/content/files/160a97cca279d6---32039160824.pdf
- https://csodamalom.hu/files/files/tisawadelu.pdf
Embedded domains
- feedproxy.google.com
- lovemyskindayspa.com
- brahmagnanam.org
- hps-gruppe.com
- metroguards.com.au
- seataclightingalaska.com
- www.financedeclined.com.au
- golden-candies.ru
- www.medipratik.com
- files.ibiza-ferien.de
- toyteepee.com
- orderkiwicafe.com
- orkhaconstruction.com
- www.marsagri.com
- cedresarquitectura.com
- schokobrunnen.com
- songhong.info
- philippinesroadshow.com
- willtorock.com
- www.truesdalepainting.com
- www.inhd.com.br
- lalitas-thaimassage-spa.de
- www.rlktechniek.nl
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report