MALICIOUS — pusojifixozokotopeb.pdf
MALICIOUS — pusojifixozokotopeb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
86b6ba1358e773f1a0c0804ba5009da737f5b9a0fa49d2e61c0fca64b9ff085d - SHA-1:
10d8aeea22ece80f0b2c51b201058dcf55a8d4e9 - MD5:
789d0db28851fa13e6c1db5b4ee1ef34 - ssdeep:
1536:fzehGc2qGgpJiHUxl3UTqrgWp0YAJCMGvczxyZz3zK5WSDsTIAqyM7b3+W8pO7A4:yhGc2qGvU3Hxp0oo+XK3wTIApMP397V - TLSH:
T12039C0F321DBDC8C3A969B036EAB119DA046D6CC5172DB505188763CE57CAEDBF00921 - Submitted as: pusojifixozokotopeb.pdf
- File type: pdf · Size: 86074 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://www.abaco-engineering.it/wp-content/plugins/formcraft/file-upload/server/content/files/160a2fa5feba71---79814854528.pdf, https://rosemonttherapy.health/wp-content/plugins/super-forms/uploads/php/files/j4k45qa8epur5u81pkigvp7c76/zepuzu.pdf, https://wamsconference.com/wp-content/plugins/super-forms/uploads/php/files/af159ecea328b3a7bbe357cf9c333c89/waxometuxilabe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/YTWXjIUwRh0/uplcv?utm_term=dvrt+ultimate+sandbag+training+book+pdf
- https://www.abaco-engineering.it/wp-content/plugins/formcraft/file-upload/server/content/files/160a2fa5feba71---79814854528.pdf
- https://rosemonttherapy.health/wp-content/plugins/super-forms/uploads/php/files/j4k45qa8epur5u81pkigvp7c76/zepuzu.pdf
- https://wamsconference.com/wp-content/plugins/super-forms/uploads/php/files/af159ecea328b3a7bbe357cf9c333c89/waxometuxilabe.pdf
- http://www.linkkorea.co.kr/wp-content/plugins/formcraft/file-upload/server/content/files/1607ad5e4bdcef---sebaluwapilezazizojofoto.pdf
- http://cocoal.com/uploads/file/boretizumofevujipedokose.pdf
- https://gitedu.in/ckfinder/userfiles/files/vubumewebadofepot.pdf
- https://vmkstroi.ru/wp-content/plugins/super-forms/uploads/php/files/1b76fe3900c9b302d402c35f53139485/59625763475.pdf
- http://angarakshaksecurity.com/userfiles/file/rulusopafenupo.pdf
- http://soosanfix.com/upload/fckeditor/file/71858885889.pdf
- https://cualuoihoanmy.com/uploads/userfiles/file/9699392502.pdf
- https://binarbaidservices.com/public_html/userfiles/file/dubamab.pdf
- https://www.tai.gr/wp-content/plugins/formcraft/file-upload/server/content/files/1607e07d44bac1---nogewoxagijapineza.pdf
- https://ahha.az/userfiles/file/favaparubid.pdf
- https://www.histoiresdegroupes.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606fd25090b23---xaxafigakelamogesuba.pdf
- http://3e-recycling.ru/app/webroot/filesfiles/11907088997.pdf
- http://strandedtattoo.com/file/tupewetamupumisef.pdf
- http://rosg.net/sa_upload/userfiles/file/20210805001111.pdf
- http://www.psychophonie-tarbes.com/ckfinder/userfiles/files/wusid.pdf
- https://nevisnews.com/userfiles/moxekupuvekekomosuritun.pdf
- https://wsbe17hongkong.hk/_bin/ckfinder/userfiles/files/nolamerikagewatiko.pdf
- http://leap-egypt.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cf5e8e5e9d2---waxejamasigimavur.pdf
- http://architettoseneca.com/userfiles/files/gefiji.pdf
- http://wphs69.com/clients/1/13/13dd0a1135c99f886ff4006aa3c820ba/File/6639609296.pdf
- http://baybayankaauamo.com/clients/c/c9/c9e0f772d4a556598cfa564a27137582/File/jabagubabusutafun.pdf
Embedded domains
- feedproxy.google.com
- www.abaco-engineering.it
- wamsconference.com
- www.linkkorea.co.kr
- cocoal.com
- gitedu.in
- vmkstroi.ru
- angarakshaksecurity.com
- soosanfix.com
- cualuoihoanmy.com
- binarbaidservices.com
- www.histoiresdegroupes.com
- 3e-recycling.ru
- strandedtattoo.com
- rosg.net
- www.psychophonie-tarbes.com
- nevisnews.com
- wsbe17hongkong.hk
- leap-egypt.com
- architettoseneca.com
- wphs69.com
- baybayankaauamo.com
- fertilizerproductionprocess.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report