MALICIOUS — pefegaxafulezemufe.pdf
MALICIOUS — pefegaxafulezemufe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ab2529cd888f9b208b0d218ae4c2714b583f7d6afc09381deb93f354c7c6626b - SHA-1:
63dc3e6cb2345d1b5776af67f286455751c9a1c1 - MD5:
1782b7559920daae1cabd1355d99644f - ssdeep:
1536:+8sT2RR56yCZNL2mk7Hn8d2yHkdytOsuEqxOI:qTuRnCCgAyHlgEqf - TLSH:
T1BE37D0F7B147DD8C7B8B6F13D9E6043CA405D3583166EA588588B65CDC683BC6D20E82 - Submitted as: pefegaxafulezemufe.pdf
- File type: pdf · Size: 72215 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!1782B7559920
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://www.molinoag.com/wp-content/plugins/formcraft/file-upload/server/content/files/16096eae9a692f---31444251482.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=eagle+claw+kung+fu+book, https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/ebeabb004ab82cb978280ca9b31178c3/popoberiramobekuweg.pdf, https://www.advids.io/wp-content/plugins/formcraft/file-upload/server/content/files/1606e91e51e615---34062931054.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/uplcv?utm_term=eagle+claw+kung+fu+book
- https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/ebeabb004ab82cb978280ca9b31178c3/popoberiramobekuweg.pdf
- https://www.advids.io/wp-content/plugins/formcraft/file-upload/server/content/files/1606e91e51e615---34062931054.pdf
- http://www.molinoag.com/wp-content/plugins/formcraft/file-upload/server/content/files/16096eae9a692f---31444251482.pdf
- http://inlikeflintlogistics.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a24cbf30483---zuwuvapamozavizulobuxisur.pdf
- https://amalighting.com/wp-content/plugins/super-forms/uploads/php/files/764f67f36402cfb791c6bfb6fd7cb72f/17807890496.pdf
- http://www.shipsupply.co.mz/wp-content/plugins/formcraft/file-upload/server/content/files/160758fdd9b6df---20426365767.pdf
- https://nikken-engineer.jp/export/sd205/www/jp/r/e/gmoserver/8/6/sd0748886/nikken-engineer.jp/fckeditor/upload/file/84440742520.pdf
- http://www.dramayaramendes.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16078bbd7b0ea5---radiwebidi.pdf
- http://aeronautike.com/userfiles/file/81134845225.pdf
- https://www.mercedesbenzofaustinservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606da7cf0c996---77871724059.pdf
- http://ecbpolska.pl/wp-content/plugins/super-forms/uploads/php/files/e0c1c994a29508dc8db2db789cf36f58/3727745653.pdf
- https://www.varishastalari.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608493d9dadca---56200700094.pdf
- https://miamivanservice.net/wp-content/plugins/formcraft/file-upload/server/content/files/1607fd487913f6---28999735047.pdf
- https://apoc.com.au/wp-content/plugins/super-forms/uploads/php/files/18a3648b6043092816b96cbfe21cddd4/nolumir.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- medvor.ru
- amartzon.store
- www.advids.io
- www.molinoag.com
- inlikeflintlogistics.com
- amalighting.com
- nikken-engineer.jp
- www.dramayaramendes.com.br
- aeronautike.com
- www.mercedesbenzofaustinservice.com
- ecbpolska.pl
- www.varishastalari.com
- miamivanservice.net
- apoc.com.au
- www.w3.org
- purl.org
- ns.adobe.com
- www.shipsupply.co.mz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report