MALICIOUS — fewigilitabuwilopegol.pdf
MALICIOUS — fewigilitabuwilopegol.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
baf5a81b14e2b1ee4b748930135e78a55f21072dc432bc86dc6b4cc4464156e4 - SHA-1:
7c7b460f4d1ef0d83c995f1790f80e355ac52fb1 - MD5:
95de2e663271b1e3cd94b6fa57637e18 - ssdeep:
1536:K0t27zptQORMVdk43cYOGwOXsM69hSYKZyfp9HC7f4WRZGxoBYcwW8pO72IG:rOQ9k43hqxpSyfPibjEoecb7Y - TLSH:
T1C937BFF3219BED4CB647CF0369AF1258A08EE2546066FA64908CB73CE87C47DAB14951 - Submitted as: fewigilitabuwilopegol.pdf
- File type: pdf · Size: 76233 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://nano-vip.com/ckfinder/userfiles/files/30961792901.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://www.hzkontejnery.cz/ckfinder/userfiles/files/supolerumorimufetejane.pdf, https://hpx.com.ua/wp-content/plugins/super-forms/uploads/php/files/4255eb70534a302ec94c3527bcb0e57a/77128759878.pdf, https://hogozaty.com/ckfinder/userfiles/files/zimifutaximiregobuxo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BkSY9tpko7c/uplcv?utm_term=command+prompt+tricks+windows+10+pdf
- http://www.hzkontejnery.cz/ckfinder/userfiles/files/supolerumorimufetejane.pdf
- https://hpx.com.ua/wp-content/plugins/super-forms/uploads/php/files/4255eb70534a302ec94c3527bcb0e57a/77128759878.pdf
- https://hogozaty.com/ckfinder/userfiles/files/zimifutaximiregobuxo.pdf
- https://webgirls-studio.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ee227ad2898---96286703580.pdf
- https://polnische-zaune.de/userfiles/file/daginejutigix.pdf
- https://makenie.com/upload/files/jawawexasipevibufovumedaj.pdf
- http://nano-vip.com/ckfinder/userfiles/files/30961792901.pdf
- https://promocionesnma.com/wp-content/plugins/super-forms/uploads/php/files/56c2526ce44c7b7de6ceb5367cdbf2f0/moxitiwo.pdf
- http://teerosy.com/ipp/images/uploads/files/15092076239.pdf
- http://www.leesii.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608773e88ae73---86602302917.pdf
- https://ldoris.com/upfile/files/20210822085944.pdf
- http://www.cuerpomenteyespiritu.es/wp-content/plugins/formcraft/file-upload/server/content/files/160d3c2ad75179---15623367312.pdf
- https://stalbeckers.nl/userfiles/image/file/61309154562.pdf
- http://www.melodypods.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a7b381985d7---webesiputozutovutadu.pdf
- http://pajurioverslas.lt/ckfinder/userfiles/files/42774847683.pdf
- http://lmleadmanagement.com/userfiles/files/zetiwes.pdf
- http://gandolfiarchitetti.com/userfiles/files/runaponovigow.pdf
- https://snoman.mb.ca/ckfinder/userfiles/files/satobexumuba.pdf
- http://nineslash.com/user_file/file/80582025432.pdf
- http://unternehmensberatung-hegenbarth.de/userfiles/file/58019018771.pdf
- https://maryamghiasi.com/images/upload/files/baxixinoj.pdf
- http://www.zopfitravel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c56d3e548d0---kakezojomo.pdf
- http://www.studiolegalefusimorelli.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b18325ddd89---62532209982.pdf
- http://lilit-realty.com/wp-content/plugins/super-forms/uploads/php/files/8n38lggntu93s13g5bg0va4603/2715580758.pdf
Embedded domains
- feedproxy.google.com
- hpx.com.ua
- hogozaty.com
- webgirls-studio.com
- polnische-zaune.de
- makenie.com
- nano-vip.com
- promocionesnma.com
- teerosy.com
- www.leesii.com
- ldoris.com
- www.cuerpomenteyespiritu.es
- stalbeckers.nl
- www.melodypods.com
- lmleadmanagement.com
- gandolfiarchitetti.com
- snoman.mb.ca
- nineslash.com
- unternehmensberatung-hegenbarth.de
- maryamghiasi.com
- www.zopfitravel.com
- www.studiolegalefusimorelli.com
- lilit-realty.com
- aweibel.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report