MALICIOUS — lepefeboxitaje.pdf
MALICIOUS — lepefeboxitaje.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
91a33435657e5f581464a9526b943c24a798d7c13ba2216e669be47e2eb00fd6 - SHA-1:
a7fafda22235375e255d21106073868b81540af7 - MD5:
3251de2b61749ef0f30b4b983fcc95d5 - ssdeep:
1536:vdSHfYJ+jnhIO6B4rwbU582fRvS125Kvn9yiSWkk2WOpOaZEWobbVq9B:X+jh3yg582O2vwkkraZ0by - TLSH:
T14F39D0F310A7DE9C7A4B6F43196A1198B48EDA8D6132FA80805CF67CD43C6BC7B14A51 - Submitted as: lepefeboxitaje.pdf
- File type: pdf · Size: 87614 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=hitman+sniper+free+download+apk+and+obb, http://aweibel.com/Photo/file/89130744428.pdf, http://www.knickmeier.net/images/pageimg/file/xonemalanogus.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=hitman+sniper+free+download+apk+and+obb
- http://aweibel.com/Photo/file/89130744428.pdf
- http://www.knickmeier.net/images/pageimg/file/xonemalanogus.pdf
- http://www.tsssport.com/wp-content/plugins/formcraft/file-upload/server/content/files/160737e9db7d47---50383093525.pdf
- https://yuktiedu.com/wp-content/plugins/super-forms/uploads/php/files/4334ae190fadd1ffa81c75fe29316f3e/95124047397.pdf
- http://bhavalaya.org/ckfinder/userfiles/files/pemizovatezuxudupevogelu.pdf
- http://alvasari.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609b363885e25---85195608425.pdf
- https://www.themeshcowork.com/wp-content/plugins/super-forms/uploads/php/files/8f6399065f10d848586e6c65329618df/ruvejavetuvulif.pdf
- http://raisemoneyonline.org/clients/6/69/691275cf9a36cab982b2498ebdc715be/File/31280785341.pdf
- https://veritiesinstitute.com/wp-content/plugins/super-forms/uploads/php/files/3b0824a20fefb108c925c9dac71dd6f8/duparogovikaguvavag.pdf
- http://amfmeg.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607ffaf495e66---41643831488.pdf
- http://www.thelawchamber.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607743c7c89b4---61909018873.pdf
- https://www.gsccn.it/wp-content/plugins/formcraft/file-upload/server/content/files/160a8b64813c20---toboxopuzu.pdf
- http://vilaportugal.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cf4a59cade5---ziwutoku.pdf
- https://sckprime.com/wp-content/plugins/super-forms/uploads/php/files/5c719e341c704ed8c9f5957ac5d1440c/72886819674.pdf
- https://www.nrlandscapes.co.uk/wp-content/plugins/super-forms/uploads/php/files/9f82afaea34d92a6b9ff5c259d80507d/33171468639.pdf
- http://historia-bfured.hu/userfiles/file/soberev.pdf
- https://sip7.pl/autoinstalator/sip7.online/wp-content/plugins/super-forms/uploads/php/files/a6af2ae0ffc4c56365107fd9b7147577/zegolejagebiruw.pdf
- https://aspirans.com/files/file/85603701703.pdf
- https://mattweidnerlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16086067cdc8c6---5413962100.pdf
- http://frankslawfirm.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/81845650823.pdf
- http://www.combatsim.eu/wp-content/plugins/formcraft/file-upload/server/content/files/16076321d14353---tivevexipadosimus.pdf
- http://msslink.ru/userfiles/files/kopukigosagogamaf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- crysiq.ru
- aweibel.com
- www.knickmeier.net
- www.tsssport.com
- yuktiedu.com
- bhavalaya.org
- alvasari.com
- www.themeshcowork.com
- raisemoneyonline.org
- veritiesinstitute.com
- amfmeg.org
- www.thelawchamber.com
- www.gsccn.it
- vilaportugal.com
- sckprime.com
- www.nrlandscapes.co.uk
- sip7.pl
- sip7.online
- aspirans.com
- mattweidnerlaw.com
- frankslawfirm.com
- www.combatsim.eu
- msslink.ru
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report