MALICIOUS — xinesufeleb.pdf
MALICIOUS — xinesufeleb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c41c37b92d496eaccbc6b1b9ff3814bfa1b391c83dbd6b61f3139ab658420c26 - SHA-1:
5a4ce38e8b8358405fa4831003445d2c4d8b5f34 - MD5:
81751464cee76cf3e26eadd1a30ddf3d - ssdeep:
1536:feZLFwkw5R8JueS/hNnODrcr3LbwbpX91TWOpOZyW/eeeCqM0b:qLFwlkJjS/hQDrc7basZAjP - TLSH:
T17839C0F36157DE8C66979F43BAFA01A8908EE7885132DB544188B77C84BC57C6F00B52 - Submitted as: xinesufeleb.pdf
- File type: pdf · Size: 87541 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://pavaniautismschools.com/wp-content/plugins/super-forms/uploads/php/files/u65d3h9iodrmcrnotu3nrharjj/nutagefulifesu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://pavaniautismschools.com/wp-content/plugins/super-forms/uploads/php/files/u65d3h9iodrmcrnotu3nrharjj/nutagefulifesu.pdf, https://phoenixknights.co.uk/wp-content/plugins/super-forms/uploads/php/files/f4952b5aa83e5718501deab0ac72b811/depepijaboxewawofofax.pdf, http://malbreil.com/userfiles/file/runoridedanibun.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/6naE_Nh8_CY/uplcv?utm_term=callers+can%27t+hear+me+on+iphone+10
- https://pavaniautismschools.com/wp-content/plugins/super-forms/uploads/php/files/u65d3h9iodrmcrnotu3nrharjj/nutagefulifesu.pdf
- https://phoenixknights.co.uk/wp-content/plugins/super-forms/uploads/php/files/f4952b5aa83e5718501deab0ac72b811/depepijaboxewawofofax.pdf
- http://malbreil.com/userfiles/file/runoridedanibun.pdf
- http://baohanhranghm.com/upload/img/files/58412323258.pdf
- http://odessahighschool1970.com/clients/7/70/70263b1be1b93b62200e198143f59f20/File/denugawubofij.pdf
- https://billionbosses.com/ckfinder/userfiles/files/63683251834.pdf
- http://www.kidnuri.com/wp-content/plugins/formcraft/file-upload/server/content/files/16088afd60aa9c---70259301230.pdf
- http://shsclassof1959.com/clients/a/a7/a7a82b2a6025f7fafce5d77be70bf845/File/datut.pdf
- https://fallsplat.se/file/zinojowixazara.pdf
- https://purpleleafestatebuyers.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bd5fc65c51d---60002834414.pdf
- http://tourbusan.net/FileData/ckfinder/files/20210605_5668C992E1A75B57.pdf
- https://avis-medical.ma/wp-content/plugins/super-forms/uploads/php/files/d7191208e7bac24da004d1e3909f156b/simazawimivuriluditeka.pdf
- https://betenenergy.com/sites/default/files/file/fubusisefe.pdf
- https://www.prowallpanama.com/wp-content/plugins/super-forms/uploads/php/files/8a8d37205df0781e8271ad0ac72d3876/nakuga.pdf
- http://www.lbf-cosmetics.com/website/wp-content/plugins/formcraft/file-upload/server/content/files/1611a8be8609d1---62612744519.pdf
- http://cbcom.fr/ressource/site-image/files/tewupewelesadolamef.pdf
- https://provisionsinternational.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cbe5f3f73a---23624967531.pdf
- https://frasertechno.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c72502129dd---23359679329.pdf
- https://www.gml.de/wp-content/plugins/formcraft/file-upload/server/content/files/160e05020299d2---10499316969.pdf
- http://www.akutrans.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609860b3d3e37---fojijegirizonufosex.pdf
- http://asu.com.vn/wp-content/plugins/super-forms/uploads/php/files/ulmjh0lfrk8tl2m09rh4v854ff/bisitipafinovepatuv.pdf
- https://www.die-umzugsfabrik.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609b972569c6d---7146093411.pdf
- https://www.novet.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607d9c79838dd---75344903116.pdf
- https://kuzeyilac.com/resimler/files/11567421047.pdf
Embedded domains
- feedproxy.google.com
- pavaniautismschools.com
- phoenixknights.co.uk
- malbreil.com
- baohanhranghm.com
- odessahighschool1970.com
- billionbosses.com
- www.kidnuri.com
- shsclassof1959.com
- fallsplat.se
- purpleleafestatebuyers.com
- tourbusan.net
- betenenergy.com
- www.prowallpanama.com
- www.lbf-cosmetics.com
- cbcom.fr
- provisionsinternational.com
- frasertechno.com
- www.gml.de
- www.akutrans.com
- www.die-umzugsfabrik.com
- www.novet.de
- kuzeyilac.com
- 123kozijnofferte.nl
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report