MALICIOUS — labulotixobakukut.pdf
MALICIOUS — labulotixobakukut.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
969cae7a46969b659718e2dc572131d619e52a7991a93130945ea8700bd11945 - SHA-1:
68e9e7ce4a3c638e11ca6fe78cd04438cf460798 - MD5:
3b02bdb7b330b8fcd9abea96b01070a1 - ssdeep:
1536:vHr3I+FOgvna+faL6SVKS/aipHaWMrcWYo9Bh2yBP2eWQpOCOt2sbn:D9Ogy+fvSVK58a9wo9BkmP2RCFO - TLSH:
T1EE39DFF322ABDD4C7B5A9F1378EA1198B0C9D38861A2D2504488772CD97C5FEBE10646 - Submitted as: labulotixobakukut.pdf
- File type: pdf · Size: 85142 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://lamekatus.ee/uploads/ckeditor/files/bijidavisoke.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://pixomot.ru/uplcv?utm_term=game+sengoku+basara+android, https://rcvizovice.cz/ckfinder/userfiles/files/safokogugisajavufibezan.pdf, http://taxplus.in/images/contentimages/files/16655538911.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pixomot.ru/uplcv?utm_term=game+sengoku+basara+android
- https://rcvizovice.cz/ckfinder/userfiles/files/safokogugisajavufibezan.pdf
- http://taxplus.in/images/contentimages/files/16655538911.pdf
- http://cyclad.org/UserFiles/file/10903636476.pdf
- https://austdoorcaocap.com/upload/files/13584952915.pdf
- https://bomando.bomsolar.com/uploadfiles/files/98052870101.pdf
- http://nitecoreromania.ro/files/file/xunexagonasasofexowa.pdf
- http://jiin-torng.com/uploadfiles/20210917233014.pdf
- http://lamekatus.ee/uploads/ckeditor/files/bijidavisoke.pdf
- http://ihdbd.org/upload/files/76961572763.pdf
- http://agavietnam.com/img/files/54079595911.pdf
- http://ambulatorioveterinariocamali.com/userfiles/files/20969211394.pdf
- http://countryclaim.cz/userfiles/file/fusali.pdf
- http://pkynfe.net/userfiles/file/8589719719.pdf
- http://yoron.net/up/files/88499217804.pdf
- http://kythuatviet.vn/uploads/userfiles/file/85033078248.pdf
- http://cn-daomeng.com/upload/userfiles/files/89191cba84c6a96e641b38a627b2a4b4.pdf
- http://asbazainville.org/userfiles/file/zulotilamiwo.pdf
- https://elitteaccesorios.com/wp-content/plugins/super-forms/uploads/php/files/kinq55bag0nrkn8h17rglh4hlc/29769656019.pdf
- http://xecuoihuyhoang.com/uploads/userfiles/file/89598576489.pdf
- https://leonardscopysystems.com/home/leonards/public_html/ckfinder/userfiles/files/lesuwatezubosekor.pdf
- http://chhattisgarhsanskritboard.in/sharpinstitute/images/files/zazuxeb.pdf
- http://abnigakgdsg.friendship-match.com/upload/files/60496235953.pdf
- https://oneremote.ru/wp-content/plugins/super-forms/uploads/php/files/8fb6939658646e190dca15b6223fc641/teromub.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- pixomot.ru
- taxplus.in
- cyclad.org
- austdoorcaocap.com
- bomando.bomsolar.com
- jiin-torng.com
- ihdbd.org
- agavietnam.com
- ambulatorioveterinariocamali.com
- pkynfe.net
- yoron.net
- cn-daomeng.com
- asbazainville.org
- elitteaccesorios.com
- xecuoihuyhoang.com
- leonardscopysystems.com
- chhattisgarhsanskritboard.in
- abnigakgdsg.friendship-match.com
- oneremote.ru
- www.w3.org
- purl.org
- ns.adobe.com
- rcvizovice.cz
- nitecoreromania.ro
- lamekatus.ee
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report