MALICIOUS — xosukunazoregebesokozup.pdf
MALICIOUS — xosukunazoregebesokozup.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8ca72c02de513333c3c6bc93228e6f9437abb33b96163fff3a2f3016c062c787 - SHA-1:
cc34fb78c7a4722d6246bf47be1195392cce6de3 - MD5:
7a17f0c8e654c0082f49182e229fc348 - ssdeep:
1536:fuPWCPYulaZLtcBsqaCm+rbK4bo4Wj9/cJ5Y9uEAf9WUpO7ZJ4:cRPJMZCBHnzoB/EAu/fg7U - TLSH:
T1BD39D0F31157CD8C778B9F8769EB029C684AD7441266E7A05088B66CC4BCAFDBF00921 - Submitted as: xosukunazoregebesokozup.pdf
- File type: pdf · Size: 90164 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://blog.crowdly.com/wp-content/plugins/formcraft/file-upload/server/content/files/160763ac1c9847---vigonerix.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=full+board+meal+meaning, https://www.saenger-ohg.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609fe91dbab2d---tizorefigenidarejanubavi.pdf, http://escalierdurire.fr/ckfinder/userfiles/files/42678664830.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/uplcv?utm_term=full+board+meal+meaning
- https://www.saenger-ohg.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609fe91dbab2d---tizorefigenidarejanubavi.pdf
- http://escalierdurire.fr/ckfinder/userfiles/files/42678664830.pdf
- http://blog.crowdly.com/wp-content/plugins/formcraft/file-upload/server/content/files/160763ac1c9847---vigonerix.pdf
- https://macleanpinesdrivingschool.com.au/wp-content/plugins/super-forms/uploads/php/files/041fdc79a5adf5737e9956e78d1ea39d/ranirabadonawopibag.pdf
- http://diagonal.org.ar/wp-content/plugins/formcraft/file-upload/server/content/files/16080cd6ab365e---nelovesaxazazugelazozej.pdf
- http://qboardapp.com/wp-content/plugins/super-forms/uploads/php/files/52483b093ca13bca1ebb042c7589a25c/panoxuj.pdf
- http://forter.vn/hinhanh/file/82196626848.pdf
- https://maxim-catering.de/wp-content/plugins/super-forms/uploads/php/files/2s1cgqb3ur9k6g4fp521buv6ft/koxosejitovalu.pdf
- http://ahlhy.com/uploads/file/060201077465.pdf
- http://usarsenal.it/userfiles/files/letejimenete.pdf
- https://rhythmcprandfirstaid.com/wp-content/plugins/super-forms/uploads/php/files/bd02fe604aeb4f1eaa0e0b01cf9851ae/donerumapinomob.pdf
- http://mko-yug.ru/wp-content/plugins/super-forms/uploads/php/files/144b4f5bbf30197d9c5a6a149e8a97d0/remutagud.pdf
- http://www.idenet.net/wp-content/plugins/formcraft/file-upload/server/content/files/1609d268f8cb77---lonilazusasuvi.pdf
- http://cbcom.eu/ressource/site-image/files/wajetovasumabaraxo.pdf
- https://www.tai.gr/wp-content/plugins/formcraft/file-upload/server/content/files/16075159c82a72---pisapejita.pdf
- http://automsystem.com/UploadFile/file/20210519091758916.pdf
- https://www.lamuccacompany.com/wp-content/plugins/super-forms/uploads/php/files/02892beeafe8e5496f94d92226f972ec/duzisimawibijabekogusi.pdf
- http://jirehenl.com/userfiles/file/200753434812.pdf
- https://alakharia.com/public_html/userfiles/file/zagif.pdf
- https://bwawarszawa.pl/upload/file/zimozokivimapimunapewa.pdf
- http://skiflogistics.ru/userfiles/file/kepetugujimexuxolage.pdf
- http://dorisemitchell.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/sadatimavufezozuvelop.pdf
- https://kaptenhoki.net/contents//files/fokusixulexukafaxubako.pdf
- https://dollarplus98.com/images/upload/files/54557086342.pdf
Embedded domains
- medvor.ru
- www.saenger-ohg.de
- escalierdurire.fr
- blog.crowdly.com
- macleanpinesdrivingschool.com.au
- qboardapp.com
- maxim-catering.de
- ahlhy.com
- usarsenal.it
- rhythmcprandfirstaid.com
- mko-yug.ru
- www.idenet.net
- cbcom.eu
- automsystem.com
- www.lamuccacompany.com
- jirehenl.com
- alakharia.com
- bwawarszawa.pl
- skiflogistics.ru
- dorisemitchell.com
- kaptenhoki.net
- dollarplus98.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report