MALICIOUS — raxesuxumexezav.pdf
MALICIOUS — raxesuxumexezav.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b46e809c71d92a6d02af7cb33999c9936363fba6a379b9221eb15d656e53309f - SHA-1:
0ed9fcb2316b02c754627f8e2770e349615e0f7f - MD5:
31e0489d9dee84544e99e57ebe62d67b - ssdeep:
1536:77c96bxUDpWEFbsTJOcdYwjTbRvjmmbH/CRb4WvdI6wFJG5V6WepOZcIIc:MEb2tWEFbsTscdYwjRvjmO6PdIr87Z3 - TLSH:
T14A38CFF3309BCC1C7B5A9F0769B720695085E788A236EB91408CBA3CD9BC97DAF00551 - Submitted as: raxesuxumexezav.pdf
- File type: pdf · Size: 83462 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://remont-elektro.eu/archiv/file/mapura.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://sakitonus.ru/wp-content/plugins/super-forms/uploads/php/files/7656d7779c885d7062bdf29a692dd7d3/77030794025.pdf, http://remont-elektro.eu/archiv/file/mapura.pdf, https://ngoctraithaibinhduong.com/uploads/news_file/garukemidex.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/Om9ozkHLxGw/uplcv?utm_term=software+requirements+by+karl+wiegers+pdf
- https://sakitonus.ru/wp-content/plugins/super-forms/uploads/php/files/7656d7779c885d7062bdf29a692dd7d3/77030794025.pdf
- http://remont-elektro.eu/archiv/file/mapura.pdf
- https://ngoctraithaibinhduong.com/uploads/news_file/garukemidex.pdf
- http://www.insurancedirectcanada.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160a0e13fea89f---58587426895.pdf
- https://www.kadeavenue.com/wp-content/plugins/super-forms/uploads/php/files/a80ff7728d872cc04d5efae62047052b/zoreziwosiwu.pdf
- https://webhostmurah.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ce6ed8153c---punaxiguvavubonakizine.pdf
- http://toitureetfacade.fr/data/Files/bonigozasepukefomu.pdf
- https://wacee.net/wp-content/plugins/formcraft/file-upload/server/content/files/1606d9c2320096---zetonupazepezokedexerato.pdf
- https://aslimitada.com/userfiles/file/biwawixulibiburikoli.pdf
- http://www.bluewhaleline.com/image/upload/File/93351296347.pdf
- https://artenika.pl/fck/file/66157028756.pdf
- https://southernlightingsource.com/wp-content/plugins/super-forms/uploads/php/files/5faa55105d9f00405906e9c10fcf6e70/niworaxobedifelejadugebi.pdf
- https://asiatravel.kg/wp-content/plugins/super-forms/uploads/php/files/f123778c4529a76bab87a99786bbccc5/78827511007.pdf
- http://boulderdivorcelaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cb605534a5c---zisamafizegonoginawer.pdf
- https://kassa-evotor.ru/wp-content/plugins/super-forms/uploads/php/files/k6fe37nn67073rnt2u5p1mrhro/guzexogiripa.pdf
- https://btegypt.com/file/67643477194.pdf
- http://hotelbelleepoque.bg/userfiles/file/656948165.pdf
- http://mobilesamara.com/img/files/file/49632191205.pdf
- http://suachuabaoduongmaynenkhi.com/img_quanganh/files/78392565890.pdf
- http://sonnenheizungen.ch/fckeditor/editor/images/file/26566510804.pdf
- https://jaunimodienos.lt/wp-content/plugins/super-forms/uploads/php/files/be7rejmet52av3m8mbml3cha11/diver.pdf
- https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/be5ebcbeb19ce6a6b2a76f7379321953/fejivobawifujunebibesoge.pdf
- http://pferdefreunde-brueckenhof.de/sites/default/files/userfiles/file/tunesutalarurebi.pdf
- http://centonze-vini.com/userfiles/files/xenumesusagasiriwuresik.pdf
Embedded domains
- 7l.uk
- feedproxy.google.com
- sakitonus.ru
- remont-elektro.eu
- ngoctraithaibinhduong.com
- www.insurancedirectcanada.ca
- www.kadeavenue.com
- webhostmurah.com
- toitureetfacade.fr
- wacee.net
- aslimitada.com
- www.bluewhaleline.com
- artenika.pl
- southernlightingsource.com
- boulderdivorcelaw.com
- kassa-evotor.ru
- btegypt.com
- mobilesamara.com
- suachuabaoduongmaynenkhi.com
- sonnenheizungen.ch
- otdelkamos.ru
- pferdefreunde-brueckenhof.de
- centonze-vini.com
- deniz-sogutma.org
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report