MALICIOUS — likaganokaxaduge.pdf
MALICIOUS — likaganokaxaduge.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c03ec0b97f9cf4fe61fa4ff7b2e9b1dfeb1b55007e8fadfa0e1ea8a09ad14716 - SHA-1:
1e6de62a823111f71d4c20fe3649aa723ba3d891 - MD5:
5c84fa3b27c0dde0f8de4d9d19523a6b - ssdeep:
1536:SkpATM5sUDKVHaiBakJSL9HTRmV9Eg2pYivhkfFjZKEb7PWiUCUlegTm9b+5WApC:fANk0VaksU9EVv6fhgEbRsegTGb+g6q - TLSH:
T1BA39DFF3A19BCC9C7B07DF1369B950AC6089E38C2476EB409548736CD47C9BDA960A31 - Submitted as: likaganokaxaduge.pdf
- File type: pdf · Size: 85905 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://bluetact.com/locktactyuma/userfiles/file/degubegajeneruvedukafo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cructi.ru/uplcv?utm_term=rooted+virtual+machine+for+android, https://kildevangen.dk/files/mabajodamovarawuge.pdf, https://www.simplythebestevents.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1613f936236279---19191777764.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cructi.ru/uplcv?utm_term=rooted+virtual+machine+for+android
- https://kildevangen.dk/files/mabajodamovarawuge.pdf
- https://www.simplythebestevents.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1613f936236279---19191777764.pdf
- http://htk2.altrodesign.eu/ckfinder/userfiles/files/fesuxiwonagitefateba.pdf
- http://sandsflooring.co.uk/ckfinder/userfiles/files/27756818663.pdf
- http://cw-cut.com/uploads/file/87841980404.pdf
- http://dyccpharma.com/upload/files/kavakewojoloxew.pdf
- http://klaaswester.nl/img/file/69843024205.pdf
- https://bluetact.com/locktactyuma/userfiles/file/degubegajeneruvedukafo.pdf
- https://hmv.ir/wp-content/plugins/formcraft/file-upload/server/content/files/161390524d8549---kirotodidipefarijisulupaj.pdf
- http://thanhnienxp.com/vietkiendo/upload/file/77432805202.pdf
- https://kp-bs.ru/upload/files/ruzovatusadoliruxatusa.pdf
- http://vongtaygiay.net/media/ftp/file/50688728334.pdf
- https://bonekarusa.com/contents/files/kafixa.pdf
- https://agmatbaa.com/upload/files/40246607059.pdf
- https://happycustomerservice.com/wp-content/plugins/super-forms/uploads/php/files/5c0bc968fe4fe8809a662a4352fb15b0/19161290899.pdf
- http://datacomsystems.cz/userfiles/file/tozuzepiwiwuw.pdf
- http://files.ibiza-ferien.de/file/77997402862.pdf
- https://eventpro-kontraktorpameran.com/uploaded/files/43665970910.pdf
- https://aartipalette.com/userfiles/file/19080924770.pdf
- http://worldplastsolution.com/ckfinder/userfiles/files/21130006920.pdf
- https://arte-salon.ru/upload_picture/sirudapedol.pdf
- http://closehorses.com/userfiles/file/96492846129.pdf
- http://tks-forever.com/upload/2021/09/09/file/tixapebamifajuvoworewuges.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cructi.ru
- www.simplythebestevents.ca
- htk2.altrodesign.eu
- sandsflooring.co.uk
- cw-cut.com
- dyccpharma.com
- klaaswester.nl
- bluetact.com
- hmv.ir
- thanhnienxp.com
- kp-bs.ru
- vongtaygiay.net
- bonekarusa.com
- agmatbaa.com
- happycustomerservice.com
- files.ibiza-ferien.de
- eventpro-kontraktorpameran.com
- aartipalette.com
- worldplastsolution.com
- arte-salon.ru
- closehorses.com
- tks-forever.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report