MALICIOUS — fagarija.pdf
MALICIOUS — fagarija.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9958eff569e6ac0cfacc701e7dceccdda483e65bbb5719072c9afd82551a12ab - SHA-1:
b0f424830bc06e4b234e57e0d305c72cfcdb7da4 - MD5:
9adcec8d2aca1b70fa452970814ec898 - ssdeep:
3072:k1N8CfolMD79xnUo/zevax62oVgbJrfwfuMUD+RT8ehr:blMDpxnUo7eyxhogtwHRt - TLSH:
T1AC3BC0F3218FED4CBB4BCB8356A612A8748DD6C86131EB244498B76C807D5BE7F10961 - Submitted as: fagarija.pdf
- File type: pdf · Size: 107218 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://argekaucuk.com/nbg/upload/files/79236455021.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://anthonyvienna.com/sites/default/files/file/xumosozedeferamewepibepot.pdf, https://aquaticlandscape.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b7d2930c5fb---61246829947.pdf, https://airflow-skateboards.com/userfiles/files/rilolukomij.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/cv9VXjIrmdE/uplcv?utm_term=manual+de+funciones+de+un+vendedor+interno
- http://anthonyvienna.com/sites/default/files/file/xumosozedeferamewepibepot.pdf
- https://aquaticlandscape.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b7d2930c5fb---61246829947.pdf
- https://airflow-skateboards.com/userfiles/files/rilolukomij.pdf
- http://geteffective.biz/uploadfiles/file/95962333615.pdf
- https://tuabogadoangel.com/wp-content/plugins/super-forms/uploads/php/files/9b3420896031af89d503fdb296997ec4/11835589550.pdf
- https://anfauglir.com/images/file/jilojuzikukipe.pdf
- https://krimgranit.ru/wp-content/plugins/super-forms/uploads/php/files/7bd14974a7d19f8f1b780dba7a33b93f/sidinoxite.pdf
- http://dabaizhongxue.com/upload_fck/file/2021-9-7/20210907220011691053.pdf
- https://rhdplumbing.com/wp-content/plugins/super-forms/uploads/php/files/c479468719a9a554ff76424f77222963/tumotozatolavitoge.pdf
- https://argekaucuk.com/nbg/upload/files/79236455021.pdf
- http://zpb-maciejewski.pl/upload/fck/file/71477981061.pdf
- https://specialbrands.gr/wp-content/plugins/super-forms/uploads/php/files/64157ebfa6fd9b0b71adad1a26ff5221/beduladolabodiniwe.pdf
- http://www.urbanwaterways.info/files/gokowubedaduzedutoraj.pdf
- http://brownewingfamily.com/clients/a/a4/a4d7a48ed280e719b438ae57db99af5e/File/sijexajufedomozure.pdf
- https://inprovitvenezuela.com/ckfinder/userfiles/files/73083690978.pdf
- https://mygamedaysports.com/wp-content/plugins/super-forms/uploads/php/files/668f9e761b588f265739bbadf7d3433e/jejixibonifomebositatomo.pdf
- https://jyapa.com/jhuoyue/uploadfiles/59956035640.pdf
- http://bukharajohnscreek.com/sites/default/files/file/dokoxipajujilez.pdf
- https://pielinks.com/UserFiles/file/lajefowewe.pdf
- https://ruxthai-guesthouse-chiangmai.com/ckfinder/userfiles/files/zedijubenol.pdf
- http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a0895f8c8b5---nifizikedukawufeni.pdf
- http://yokosohk.com/files/fckfiles/file/50823058156.pdf
- https://airshow-bg.com/file/84875842490.pdf
- http://www.mezmat.ru/ckfinder/userfiles/files/lewum.pdf
Embedded domains
- feedproxy.google.com
- anthonyvienna.com
- aquaticlandscape.com
- airflow-skateboards.com
- geteffective.biz
- tuabogadoangel.com
- anfauglir.com
- krimgranit.ru
- dabaizhongxue.com
- rhdplumbing.com
- argekaucuk.com
- zpb-maciejewski.pl
- www.urbanwaterways.info
- brownewingfamily.com
- inprovitvenezuela.com
- mygamedaysports.com
- jyapa.com
- bukharajohnscreek.com
- pielinks.com
- ruxthai-guesthouse-chiangmai.com
- www.marsagri.com
- yokosohk.com
- airshow-bg.com
- www.mezmat.ru
- flemingdecal.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report