MALICIOUS — repet.pdf
MALICIOUS — repet.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
c7f18bd6328f2f4f5b07bfefa9b9c8f1ba00a62d3e7fea5d2bcf470abcccc096 - SHA-1:
b1a5dde82d6a43676a00716e2dd75b4cb17bc555 - MD5:
58a296c894edda5f039da393fb8358b0 - ssdeep:
1536:TqnDNcvp3sHH63OQqqIA0Ey2dVPuyC9CU6PZFAzDmPWXPifNojZw1RBGWspOR3g1:q5stsn63OLq2E7dxO7SFAzaNfOjC1RBk - TLSH:
T17D39CFF32157CD9C738ACF0376EB1169A08AD6D96221EB5044887A2CC9BC57EBF14A11 - Submitted as: repet.pdf
- File type: pdf · Size: 91123 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://livre-d-art.com/ckfinder/userfiles/files/dedetujifixoxepob.pdf, http://shrlie.com/upload_fck/file/2021-9-6/20210906125849421820.pdf, http://indianapit.thriftstorewebsites.net/flash/indianapit.thriftstorewebsites.net/file/rugofasepezinibesov.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1xuhb7AK25c/uplcv?utm_term=practical+wpf+charts+and+graphics+pdf
- https://livre-d-art.com/ckfinder/userfiles/files/dedetujifixoxepob.pdf
- http://shrlie.com/upload_fck/file/2021-9-6/20210906125849421820.pdf
- http://indianapit.thriftstorewebsites.net/flash/indianapit.thriftstorewebsites.net/file/rugofasepezinibesov.pdf
- http://allegroescrow.com/wp-content/plugins/formcraft/file-upload/server/content/files/16141041e7929f---kidub.pdf
- https://safarekhoob.ir/basefile/safarekhoobir/files/27131153523.pdf
- https://digireg.cz/upload/zudafuxododevoriro.pdf
- https://www.sidertest.it/wp-content/plugins/formcraft/file-upload/server/content/files/1613ac2fe45a8e---86255201523.pdf
- http://szhlfz.net/upload/badawelewexiladatuxofefu.pdf
- https://bike-accessories.supersites.gr/content/ckfinder/files/51951485007.pdf
- http://ride-on-earth.com/images/blog/file/68296236301.pdf
- http://capesociety.ca/uploads/files/kujabakulomuke.pdf
- http://camara.acessoainformacao.org/uploads/ckfinder/files/41443745923.pdf
- http://www.neslihanonur.com/wp-content/plugins/super-forms/uploads/php/files/bab69df7517adc598c0c4a7c8b8fbe0e/48938504225.pdf
- http://administratieindex.nl/images/uploads/42465650303.pdf
- http://www.c-l-r-p.com/admin/ckfinder/userfiles/files/59153477834.pdf
- http://lixupeng.com/uploads/files/botodamapebapip.pdf
- http://espokebar.com/uploads/files/warurasepabaxekam.pdf
- http://beiwendq.com/data/attachment/file/86043467563.pdf
- https://xn--interpeas-r6a.es/upload/files/xatosogedinopotedidoje.pdf
- https://hightechrustremovers.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16142c96e4b8d7---88912161516.pdf
- https://ms02bet.com/contents/files/rakezutebonol.pdf
- http://sumbulefendiegitimvakfi.com/resimler/files/48507780447.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- livre-d-art.com
- shrlie.com
- indianapit.thriftstorewebsites.net
- allegroescrow.com
- safarekhoob.ir
- www.sidertest.it
- szhlfz.net
- ride-on-earth.com
- capesociety.ca
- camara.acessoainformacao.org
- www.neslihanonur.com
- administratieindex.nl
- www.c-l-r-p.com
- lixupeng.com
- espokebar.com
- beiwendq.com
- xn--interpeas-r6a.es
- hightechrustremovers.nl
- ms02bet.com
- sumbulefendiegitimvakfi.com
- www.w3.org
- purl.org
- ns.adobe.com
- digireg.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report