MALICIOUS — bulixafi.pdf
MALICIOUS — bulixafi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8fc38ef198a85b6cd6f117fd7eaba57da2ed9153fffa0c045d88d19f28d97dc2 - SHA-1:
8eed42697e50fe1e1472e346aeecd385a60dff5b - MD5:
a112f334592c7c855ce3d491b107d797 - ssdeep:
1536:XsuevC2V3dUVRz8PRipX7BsjL9Oeez84M7WFFtAASWypOlLd8y0DLufWY52g9EtQ:cuevTV3QR9p5Lz846WfO2lLCy0DSXUgp - TLSH:
T16539CFF32197EC8C3B8B9B5365DB21A9E08EE3483262E6504588A67CD17C5BF7F04851 - Submitted as: bulixafi.pdf
- File type: pdf · Size: 88537 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://ezgoe.com/10005001208290177/ckfinder/userfiles/files/fomepirizogomaditepuk.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://globaltruthmediagroup.com/clients/a/aa/aa8380eac451876ae6ab993bf3a720d6/File/91314624723.pdf, http://anandamsanyal.com/userfiles/file/memok.pdf, https://ezgoe.com/10005001208290177/ckfinder/userfiles/files/fomepirizogomaditepuk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=cbt+for+relationship+anxiety
- http://globaltruthmediagroup.com/clients/a/aa/aa8380eac451876ae6ab993bf3a720d6/File/91314624723.pdf
- http://anandamsanyal.com/userfiles/file/memok.pdf
- https://ezgoe.com/10005001208290177/ckfinder/userfiles/files/fomepirizogomaditepuk.pdf
- https://mls.lighting/wp-content/plugins/super-forms/uploads/php/files/e65073d92cef7ee61ad106291bcc1c38/80975777811.pdf
- http://pamatudarbai.lt/ckfinder/userfiles/files/56308356457.pdf
- https://mayurherbal.com/userfiles/file/kufos.pdf
- https://nepalimodelagency.com/userfiles/file/77350690249.pdf
- http://outspokenholland.com/userfiles/fckFile/20210515231019.pdf
- http://mikomisushi.com/uploads/files/ririp.pdf
- https://suma.ca/upload/editor/file/62219161033.pdf
- https://t4g.nasscomfoundation.org/wp-content/plugins/super-forms/uploads/php/files/19n2ornn16t1ru23rps0da2j41/58870034850.pdf
- http://amadpich.com/userfiles/file/55196196499.pdf
- https://www.visitrwanda.com/wp-content/plugins/super-forms/uploads/php/files/a4b229ad89da3a5b29469fbb85b80c16/rupulapolumakutube.pdf
- http://nc-israel.ru/upload/files/25131690384.pdf
- http://sklepjola.pl/userfiles/file/bedemojikonupubamet.pdf
- http://www.carolglassman.com/wp-content/plugins/formcraft/file-upload/server/content/files/16083703b0be64---kususiberurerew.pdf
- http://kotolantopeni.cz/file/kopeval.pdf
- https://bursaceviritercume.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a8f4a274b15---bomajuj.pdf
- https://www.sixteengrams.com/wp-content/plugins/super-forms/uploads/php/files/1c5a1ko937c48oo94v09nb506n/wufoxixapikepubome.pdf
- https://briljant-maleri.se/UserFiles/files/94841921561.pdf
- http://ugyvednok.hu/userfiles/file/vevidolilaporebujezizoles.pdf
- http://worthingtonpark101.com/userimages/72330633423.pdf
- http://eschool365.in/js/admin/uploadfiles/file/91318068550.pdf
- https://relleno-acidohialuronico.com/wp-content/plugins/super-forms/uploads/php/files/d63953e3b8113f9bf04c0b2dce1d1c7f/tifebuxadotipubanof.pdf
Embedded domains
- feedproxy.google.com
- globaltruthmediagroup.com
- anandamsanyal.com
- ezgoe.com
- mayurherbal.com
- nepalimodelagency.com
- outspokenholland.com
- mikomisushi.com
- suma.ca
- t4g.nasscomfoundation.org
- amadpich.com
- www.visitrwanda.com
- nc-israel.ru
- sklepjola.pl
- www.carolglassman.com
- bursaceviritercume.com
- www.sixteengrams.com
- briljant-maleri.se
- worthingtonpark101.com
- eschool365.in
- relleno-acidohialuronico.com
- aimhc.com
- studiodispirito.it
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report