MALICIOUS — kogin.pdf
MALICIOUS — kogin.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c6eb22a1cfe4aacd5b5093b620e8efa0fac50f63d26b6250a9a33cc42808ca80 - SHA-1:
b7ba5b8675a6b14d0acc87cec3f5392a4e8894db - MD5:
0bff19981e2547fda4423d08a66e6148 - ssdeep:
1536:BU1CemxHE1QCVilQbftm6r59+bSa4OtqPApr2NstYeA8LxpZOWvsAJYFFRFWspOX:CDmxkulaf1gOa1tqPA8EYevL16DRMRN - TLSH:
T1A738C0F321AFDD1CB7865F0365B72494B58BD78C2121EAA4408CBA6CC5BC6BDBE50811 - Submitted as: kogin.pdf
- File type: pdf · Size: 81521 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://kaxtongroup.com/home5/maxconne/public_html/kaxtongroup/assets/images/newspostimages/files/fiwigikataxobuvapes.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://egf.tw/test2/images/file/bimurel.pdf, https://www.pietri-automobiles.com/wp-content/plugins/super-forms/uploads/php/files/beb292coij5s0pnunib18a0ljc/retenetemenosotezokunuw.pdf, http://parkhigh65.com/clients/4970/File/82628630748.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/DOqCt-cVA4I/uplcv?utm_term=phone+number+for+lee+county+utilities
- https://egf.tw/test2/images/file/bimurel.pdf
- https://www.pietri-automobiles.com/wp-content/plugins/super-forms/uploads/php/files/beb292coij5s0pnunib18a0ljc/retenetemenosotezokunuw.pdf
- http://parkhigh65.com/clients/4970/File/82628630748.pdf
- http://www.ecvbrass.ch/user/web/file/gosivotevovenajobofokoxow.pdf
- https://jiptv.nl/wp-content/plugins/super-forms/uploads/php/files/e1i9iqmlh9pk376t5tdktthv2f/venitu.pdf
- https://action-roofing.com/wp-content/plugins/super-forms/uploads/php/files/52266ce7aec5e426aed75a3307082817/48351674816.pdf
- http://profisystem.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160a44ff128e7f---tixuzukemas.pdf
- https://kaxtongroup.com/home5/maxconne/public_html/kaxtongroup/assets/images/newspostimages/files/fiwigikataxobuvapes.pdf
- http://bahtiyardishekimi.com/fckfiles/file/nesaloziwoxapegaf.pdf
- http://toeicspeaking.net/_UploadFile/Images/file/54167746421.pdf
- http://telekommarketing.com/firme_data/files/vofodox.pdf
- http://www.sunarmisir.com.tr/wp-content/plugins/super-forms/uploads/php/files/em216q93v3in3vt19q387j7si4/87958691678.pdf
- http://ladue62.com/clients/2/2d/2d0487a90c18d3a1b3df44839405a665/File/84310426863.pdf
- https://noithatkuongthinh.com/uploads/files/63044655676.pdf
- https://www.baptistenhardenberg.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160c42e730121f---13682863364.pdf
- http://yuha.be/_files/file/debepojen.pdf
- http://morard-mcf.fr/data/Files/5011987672.pdf
- http://www.lavalledesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c5a01e77c75---15418653977.pdf
- https://genesisbehaviorcenter.com/wp-content/plugins/super-forms/uploads/php/files/5921ff79d14a2660431e9b4ee676190f/29101646400.pdf
- https://thai-airpark.com/ckfinder/userfiles/files/43244324600.pdf
- https://strechybenesov.cz/content/45726774172.pdf
- http://www.sunarsurdurulebilir.com/wp-content/plugins/super-forms/uploads/php/files/0vq9a11nte350dqir4bp4lf442/79234087094.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- egf.tw
- www.pietri-automobiles.com
- parkhigh65.com
- www.ecvbrass.ch
- jiptv.nl
- action-roofing.com
- kaxtongroup.com
- bahtiyardishekimi.com
- toeicspeaking.net
- telekommarketing.com
- ladue62.com
- noithatkuongthinh.com
- www.baptistenhardenberg.nl
- yuha.be
- morard-mcf.fr
- www.lavalledesign.com
- genesisbehaviorcenter.com
- thai-airpark.com
- www.sunarsurdurulebilir.com
- www.w3.org
- purl.org
- ns.adobe.com
- profisystem.ro
- www.sunarmisir.com.tr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report