MALICIOUS — waluxobezax.pdf
MALICIOUS — waluxobezax.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8b9b9292a8117278cee3b0cb34f3c9f26d0d6358ff7ac638aaf2ce85f5fb13de - SHA-1:
5309ce4e37b0d7e109913780a5abb16c6d8249aa - MD5:
39bc58163d36fab0d5d46c376296e5ea - ssdeep:
1536:PKC+vobvg6fFsEtYtzGzYPVx6bxvADbdCDHXM8nWBvOzklCrD4jIglW8pO+NnO:TbvgCsEIfPz6bJAtccCzrDYr0+k - TLSH:
T1FC39C0F371A7ED8CBA8B9F036EAA1158B0CAD6C82116E6904548777C847C5BDBF10A50 - Submitted as: waluxobezax.pdf
- File type: pdf · Size: 89522 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://sxhk365.com/uploads/file///pilizamusomenotusepalada.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://kardelendalgicpompa.com/uploadfiles/file/76835030762.pdf, http://adria-ex.com/images/blog//file/33056664111.pdf, https://kvartira-zalog.ru/wp-content/plugins/super-forms/uploads/php/files/b157e48a5243b38801fa088dafb0727d/mixawukodazaxim.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/LPIa9PGmDLg/uplcv?utm_term=republic+kitchen+and+taphouse
- http://kardelendalgicpompa.com/uploadfiles/file/76835030762.pdf
- http://adria-ex.com/images/blog//file/33056664111.pdf
- https://kvartira-zalog.ru/wp-content/plugins/super-forms/uploads/php/files/b157e48a5243b38801fa088dafb0727d/mixawukodazaxim.pdf
- https://rugsinc.in/UserFiles/files/51362442522.pdf
- https://kvartira-zalog.ru/wp-content/plugins/super-forms/uploads/php/files/61de19469ac9619c9d4596dc603e8f75/setodebateduzikese.pdf
- http://sxhk365.com/uploads/file///pilizamusomenotusepalada.pdf
- https://nailseasupportgroup.com/wp-content/plugins/super-forms/uploads/php/files/795b0e98a97dced0154afea3cfc17166/nenobevitukaxubowugibiz.pdf
- https://sharadsangam.org/UserFilesTwo/file/mutawejapejinilive.pdf
- https://www.bluegreenshouseboats.in/wp-content/plugins/formcraft/file-upload/server/content/files/16073e2f38fb4d---dereviwi.pdf
- http://urbancollab.com/userfiles/Proj_Name//files/nuwuterugukemarebojo.pdf
- http://tfforming.ru/d/files/2341135920.pdf
- https://www.rekalibracija.com/wp-content/plugins/super-forms/uploads/php/files/9768682a9545ec789bd3127d70b299d2/74788736799.pdf
- https://foodphotoshop.com/userfiles/files/wibisokede.pdf
- http://www.klpreschool.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c97ad4b783---gisalutasosofo.pdf
- https://www.pfgpartners.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1608c508a6aec7---60154315137.pdf
- https://psychologgia.pl/Upload/file/36001740734.pdf
- https://sellos-mecanicos.com/wp-content/plugins/super-forms/uploads/php/files/f04dd311e52f63be9da7a04ce50d7279/dimebebipaxukikefab.pdf
- https://thejinglelab.com/wp-content/plugins/super-forms/uploads/php/files/skcan3ftgkhtmfkj00j2kvq6th/33041418326.pdf
- http://hillandcunnreunion.com/clients/864369/File/68623174976.pdf
- https://kolodezrus.ru/wp-content/plugins/super-forms/uploads/php/files/8e115da8a6569d37ef1a90a700aa259e/10789180419.pdf
- https://www.bountyvacation.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607187102e006---51667981561.pdf
- http://www.cheapmotorcycleinsurancepa.com/wp-content/plugins/super-forms/uploads/php/files/9m9r31qjafijag5vpsb9snjdq7/78989028595.pdf
- https://www.traveltimevipp.com/wp-content/plugins/super-forms/uploads/php/files/cba06edba881e1063e081733249df4eb/76355504776.pdf
- https://prawobrzeze.info/userfiles/file/develotepajabaxise.pdf
Embedded domains
- feedproxy.google.com
- kardelendalgicpompa.com
- adria-ex.com
- kvartira-zalog.ru
- rugsinc.in
- sxhk365.com
- nailseasupportgroup.com
- sharadsangam.org
- www.bluegreenshouseboats.in
- urbancollab.com
- tfforming.ru
- www.rekalibracija.com
- foodphotoshop.com
- www.klpreschool.com
- www.pfgpartners.com.au
- psychologgia.pl
- sellos-mecanicos.com
- thejinglelab.com
- hillandcunnreunion.com
- kolodezrus.ru
- www.bountyvacation.com
- www.cheapmotorcycleinsurancepa.com
- www.traveltimevipp.com
- prawobrzeze.info
- arerp.kr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report