MALICIOUS — baroboxo.pdf
MALICIOUS — baroboxo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
793b27e665518bcd8977ff52e79f7a0e7f0c2bb7122fb698167dd8cb53ef33b1 - SHA-1:
87a372d826b06d276c8d42303cec5e576ad22b04 - MD5:
cd3e6bcae2e7e62f4f2a72f122a0ed55 - ssdeep:
1536:hVaVKSY5l4c0gpnFCBWNMKOvJMq1LJMaKDdQXsSkcwOPUeRfHYU1lI51:7aVl0scnIQoRjCRQc8rRPY8l21 - TLSH:
T15C37D1F3A057DE8D7D8A1F036AE60119E48BD64C243BF6245458B7ACD0AC3BE6F14A41 - Submitted as: baroboxo.pdf
- File type: pdf · Size: 69653 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!CD3E6BCAE2E7
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=is+demon+slayer+season+2+out, https://ipcare.nl/wp-content/plugins/super-forms/uploads/php/files/eiovbbjhvr867ch5082ipqboeo/bojizum.pdf, https://414movement.com/wp-content/plugins/super-forms/uploads/php/files/9d0cd016dd18e49021d77cd5f3a0c756/vagutok.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pistant.ru/uplcv?utm_term=is+demon+slayer+season+2+out
- https://ipcare.nl/wp-content/plugins/super-forms/uploads/php/files/eiovbbjhvr867ch5082ipqboeo/bojizum.pdf
- https://414movement.com/wp-content/plugins/super-forms/uploads/php/files/9d0cd016dd18e49021d77cd5f3a0c756/vagutok.pdf
- http://dzbnf.com/upload/file/%5C/2353716934.pdf
- http://inspirationallabels.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16078a80aed550---24087041940.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/3kvlanrigepb0h0k7lfcn4qba6/40851923399.pdf
- https://vate-tire.ru/wp-content/plugins/super-forms/uploads/php/files/d6e11cae3921c481394542c7b74504cf/vetemeneda.pdf
- https://stpetejazz.com/wp-content/plugins/super-forms/uploads/php/files/139cjbo4io51enrmlttga0jgsu/62106676105.pdf
- https://www.northwoodmedical.ca/wp-content/plugins/super-forms/uploads/php/files/d5em1ohkaqu2dtm2fob3milb40/53661827334.pdf
- http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606e4ec75267e---46648763370.pdf
- http://bestforfishing.com/wp-content/plugins/super-forms/uploads/php/files/d1ac0979aa7109a16212790115e050f6/moximigefe.pdf
- https://www.histoiresdegroupes.com/wp-content/plugins/formcraft/file-upload/server/content/files/16072091380e6f---xefejadavikokena.pdf
- https://mobistore.co.nz/wp-content/plugins/super-forms/uploads/php/files/6a76a6a3ccdde04c2bcecba97c932505/wekepowuzofavun.pdf
- https://stakeoutllc.com/wp-content/plugins/super-forms/uploads/php/files/86e4434f83bc3d1e475a1895516bc954/tepitowusibuzu.pdf
- https://bokseinstituttet.dk/wp-content/plugins/formcraft/file-upload/server/content/files/160709255f2cef---mitonenogirupofirumugu.pdf
- https://area34.info/wp-content/plugins/super-forms/uploads/php/files/8suq6rpfben02epa0qid8tekp0/vijorevenupife.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- pistant.ru
- ipcare.nl
- 414movement.com
- dzbnf.com
- inspirationallabels.co.uk
- www.nuricomuvakfi.org
- vate-tire.ru
- stpetejazz.com
- www.northwoodmedical.ca
- hellnocancershow.com
- bestforfishing.com
- www.histoiresdegroupes.com
- stakeoutllc.com
- area34.info
- www.w3.org
- purl.org
- ns.adobe.com
- mobistore.co.nz
- bokseinstituttet.dk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report