MALICIOUS — nafakebenevoxeji.pdf
MALICIOUS — nafakebenevoxeji.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
86765bf0c2b865aee4c266f5396456f371afac190ca437b4702a9b7d3f3a1bb6 - SHA-1:
d4b6212dda5f8ab3043e9fe022a6c430a754a63d - MD5:
35a13713284094facda4ff9cae375d7f - ssdeep:
1536:AGi7twip5k0PGXVByTJcXu7XScj9zRiviyRoROeJFwmdmJtrNVzrkGx9WUnOgDno:89Zae7XRjjidyrJKm05VzrPFn3bo - TLSH:
T1453AD0B7219BCD8C6ECB9B5328B61539608DE38C6532D67454C87B3DC17C2BD2E20A52 - Submitted as: nafakebenevoxeji.pdf
- File type: pdf · Size: 97954 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://lestyprin.online/831133864693qpsm.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://baarspo.ru/wb?keyword=where%20is%20the%20book%20of%20enoch%20referenced%20in%20the%20bible, https://uploads.strikinglycdn.com/files/f516558e-3328-4ee5-a3ae-cdf4d13a2267/lasko_ceramic_heater_costco_canada.pdf, http://soregoboredu.rf.gd/dixukutibim.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://baarspo.ru/wb?keyword=where%20is%20the%20book%20of%20enoch%20referenced%20in%20the%20bible
- https://uploads.strikinglycdn.com/files/f516558e-3328-4ee5-a3ae-cdf4d13a2267/lasko_ceramic_heater_costco_canada.pdf
- http://soregoboredu.rf.gd/dixukutibim.pdf
- http://lestyprin.online/831133864693qpsm.pdf
- http://pelobana.66ghz.com/45192001995.pdf
- http://dozawudefe.iblogger.org/economically_weaker_section_application_form.pdf
- https://49432a94-54bc-4d13-9d12-ea41d731e1b8.filesusr.com/ugd/a7c689_b47fcd0a9848464f95dea101bbe9c82c.pdf?index=true
- http://vukelas.rf.gd/64948238143.pdf
- https://b6d28218-96ba-4f98-b9c1-0d78b4e6fe84.filesusr.com/ugd/47aa88_d4676eef06d342d69708e400d7b61a77.pdf?index=true
- https://6eed613e-cbae-405e-b458-9655ef9033f8.filesusr.com/ugd/e4f6f0_6986c918b4f3431cacb482f1edb4527e.pdf?index=true
- http://thedouche.xyz/17418854983wfo32.pdf
- http://panekad.rf.gd/datepicker_date_format_is_not_working.pdf
- https://uploads.strikinglycdn.com/files/1d3cc573-350d-45c3-85dd-9a0138c524ff/32053871259.pdf
- https://b46c4cda-4951-41c0-816f-bbf02eee4d9b.filesusr.com/ugd/4ff992_0633d32d5df349a381a9d7c2b536989d.pdf?index=true
- http://lemijafuw.epizy.com/82018843985.pdf
- https://uploads.strikinglycdn.com/files/6d18d4b6-3c0f-405a-8191-05bd1ed96e0a/west_bend_82707b_stir_crazy_electric_hot_oil_popcorn_popper_machine.pdf
- http://ratonawe.iblogger.org/celiac_disease_questionnaire.pdf
- https://uploads.strikinglycdn.com/files/14586f5e-6863-4645-ab0f-8ed5501ec5e0/do_you_use_commas_or_semicolons_in_a_list.pdf
- http://tojozojorezew.epizy.com/da_de_la_madre_en_mxico_2019.pdf
- http://golofup.rf.gd/66453725778.pdf
- https://4c5ad993-366d-4b3a-aa99-9b6f56583180.filesusr.com/ugd/01e791_9979cabc8f474ebc8bf4bcdf2ba62319.pdf?index=true
- http://vodepafituxeta.rf.gd/bharti_axa_life_insurance_plans.pdf
- http://xofajenakimexo.iblogger.org/analysing_bank_financial_statements.pdf
- https://uploads.strikinglycdn.com/files/da8aa3a0-b927-4169-b5b8-91c07b60ff62/used_firefly_2_vaporizer_for_sale.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- baarspo.ru
- uploads.strikinglycdn.com
- lestyprin.online
- pelobana.66ghz.com
- dozawudefe.iblogger.org
- 49432a94-54bc-4d13-9d12-ea41d731e1b8.filesusr.com
- b6d28218-96ba-4f98-b9c1-0d78b4e6fe84.filesusr.com
- 6eed613e-cbae-405e-b458-9655ef9033f8.filesusr.com
- thedouche.xyz
- b46c4cda-4951-41c0-816f-bbf02eee4d9b.filesusr.com
- lemijafuw.epizy.com
- ratonawe.iblogger.org
- tojozojorezew.epizy.com
- 4c5ad993-366d-4b3a-aa99-9b6f56583180.filesusr.com
- xofajenakimexo.iblogger.org
- www.w3.org
- purl.org
- ns.adobe.com
- soregoboredu.rf.gd
- vukelas.rf.gd
- panekad.rf.gd
- golofup.rf.gd
- vodepafituxeta.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report