MALICIOUS — rofovovowobapujonanuna.pdf
MALICIOUS — rofovovowobapujonanuna.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b7fd941a0ffb251a6b8611c55410d71468a474a680509e5aa6c8fc8303393615 - SHA-1:
6807b5c3cd96d564de53511fb4983723dd05d403 - MD5:
ac6057490416c37e6795a49569b5663e - ssdeep:
1536:nl+gipmpmYLcfkNh9u7k2MBmQf2j4zXmLMgPkTVcn6DIWSYX8zBh31sUoy9WwpO0:MgipmEYPvu4VmG2j4GMs3n6DCdTFSyk0 - TLSH:
T13C38C0F3609BCD5DB2CB9F17ADE60158A08AE2CD7172EF904098762C917C9FDAE10650 - Submitted as: rofovovowobapujonanuna.pdf
- File type: pdf · Size: 82847 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f7dc09983d---54857908685.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=cheat+engine+download+gta+5, http://thunderstar.cn/userfiles/file/20210906051318537392475.pdf, http://scales-center.com/shop/fck_file/file/zosojufoferapixix.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=cheat+engine+download+gta+5
- http://thunderstar.cn/userfiles/file/20210906051318537392475.pdf
- http://scales-center.com/shop/fck_file/file/zosojufoferapixix.pdf
- http://hzeiger.com/userfiles/file/20009632208.pdf
- http://geasit.it/userfiles/files/badamagobej.pdf
- http://kimsanghun.com/upload/userfiles/file/20219511115564.pdf
- http://uptindia.com/newsimages/file///28998039078.pdf
- http://innersolutions-uk.com/file/12366772263.pdf
- http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f7dc09983d---54857908685.pdf
- https://singhaniabrothersltd.com/ckeditor/ckfinder/userfiles/files/bijokefefexolunafi.pdf
- http://xn--rssx31a7tec6p.com/upload/userfiles/files/20210904094656.pdf
- http://skisun.it/userfiles/files/gelawinowefikojera.pdf
- https://kueapem.com/contents/files/webelaxesis.pdf
- https://feriaesotericadeatocha.com/wp-content/plugins/formcraft/file-upload/server/content/files/16134530eb8707---12581894945.pdf
- http://innotack.com/userfiles/file/84118443759.pdf
- http://capitaloffice.pl/fotki/file/20484076083.pdf
- https://flims.atelierleuthold.ch/userfiles/files/kuziluwamulegu.pdf
- http://interativacorretora.com/fotosempresa/files/sebozokixedaniw.pdf
- https://atlanticcompact.org/userfiles/files/jerufitebeligagominavi.pdf
- https://locktactyuma.com/ckfinder/userfiles/files/zuvukinoxujowuligamuzibub.pdf
- https://nistd.in/userfiles/file/kesoxagigisinutibewobopos.pdf
- https://eric-parnes.shortex.com/ckfinder/userfiles/files/gojut.pdf
- http://budaors.varosom.hu/userfiles/files/59292691087.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- crysiq.ru
- thunderstar.cn
- scales-center.com
- hzeiger.com
- geasit.it
- kimsanghun.com
- uptindia.com
- innersolutions-uk.com
- vtracauto.com
- singhaniabrothersltd.com
- xn--rssx31a7tec6p.com
- skisun.it
- kueapem.com
- feriaesotericadeatocha.com
- innotack.com
- capitaloffice.pl
- flims.atelierleuthold.ch
- interativacorretora.com
- atlanticcompact.org
- locktactyuma.com
- nistd.in
- eric-parnes.shortex.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report