MALICIOUS — pugimezolixopitas.pdf
MALICIOUS — pugimezolixopitas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b88cc17f52008803a4991990cf57da0e6b6f642c969152ce219dd3de80962e3e - SHA-1:
3783ee238083ab87bc6d992cddb9321e9324634f - MD5:
ab720c0a62537ccb7c4b360d7e0f7acc - ssdeep:
1536:/t+8kZTDmg9SkwZkiJaPYlwePlvWptaaKbqJWxApOGgTIHfbwxg:FamIt+amwEkW2O3Gg29 - TLSH:
T19F38D0E371CBED5C7A8F9B0368B612A864C9E3842166EB9048C8772DD57C5BD7F10A10 - Submitted as: pugimezolixopitas.pdf
- File type: pdf · Size: 83054 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://friluftsgruppen.se/wp-content/plugins/formcraft/file-upload/server/content/files/16133452bd60ad---zupejafakuz.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://shangrilayunnan.com/ckfinder/userfiles/files/mokuki.pdf, http://www.tenniscanberra.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1613a75388d6be---kolulajadawamesaxotomag.pdf, http://jagdrevier.hu/upload/images/file/90880879318.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/DOqCt-cVA4I/uplcv?utm_term=how+do+i+get+multimedia+messages+on+my+phone
- http://shangrilayunnan.com/ckfinder/userfiles/files/mokuki.pdf
- http://www.tenniscanberra.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1613a75388d6be---kolulajadawamesaxotomag.pdf
- http://jagdrevier.hu/upload/images/file/90880879318.pdf
- http://trans-serwis.com/userfiles/file/petefase.pdf
- http://pttaccounting.com/userfiles/files/lagezokekuxozexakubisi.pdf
- https://merohamro.com/ckfinder/userfiles/files/ludofusozubipore.pdf
- http://friluftsgruppen.se/wp-content/plugins/formcraft/file-upload/server/content/files/16133452bd60ad---zupejafakuz.pdf
- http://cualuoiskydoor.com/webroot/img/files/kogajegobixuwelofi.pdf
- https://oteaexpert.fr/cite_imgs/file/82033879294.pdf
- http://nb-magnet.com/upload/files/5135357499.pdf
- https://penal-garazh.ru/files/vanim.pdf
- https://grdr.org/paidel/ckfinder/userfiles/files/60064560750.pdf
- https://abogadosaccidentealicante.centralcms.cloud/galeria/files/47139572496.pdf
- http://criollo-cocoa.com/userfiles/file/juduj.pdf
- https://sandp-engineering.com/ckfinder/userfiles/files/7958181094.pdf
- http://turnwealthy.com/ckfinder/userfiles/files/10886108093.pdf
- https://juvelyrikoscentras.lt/Files/file/81699225584.pdf
- http://coimbrasoftware.hu/images/uploads/files/31147554037.pdf
- http://www.cheapmotorcycleinsurancepa.com/wp-content/plugins/super-forms/uploads/php/files/ab0c28749592deaf8b1a6a197e60aa71/rinaribodew.pdf
- https://s-h.cc/uploads/files/202109031817107210.pdf
- https://marblobathware.ph/app/webroot/img/files/78725444521.pdf
- http://aibasylhet.edu.bd/app/webroot/ckfinder/userfiles/files/85283768813.pdf
- https://krusomying.com/data/file/xozexep.pdf
- http://streathamtaxi.com/survey/userfiles/files/72806898554.pdf
Embedded domains
- feedproxy.google.com
- shangrilayunnan.com
- www.tenniscanberra.com.au
- trans-serwis.com
- pttaccounting.com
- merohamro.com
- friluftsgruppen.se
- cualuoiskydoor.com
- oteaexpert.fr
- nb-magnet.com
- penal-garazh.ru
- grdr.org
- abogadosaccidentealicante.centralcms.cloud
- criollo-cocoa.com
- sandp-engineering.com
- turnwealthy.com
- www.cheapmotorcycleinsurancepa.com
- s-h.cc
- krusomying.com
- streathamtaxi.com
- hmv.ir
- www.w3.org
- purl.org
- ns.adobe.com
- jagdrevier.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report