MALICIOUS — vebuvijenifewovev.pdf
MALICIOUS — vebuvijenifewovev.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ce3ddbb2ef8366f80dd97bcb49c471490f324ea1963ee475ab09189bd7ab3ddb - SHA-1:
a9b8c6aeb2580a649f8aa93b804be39edcc50a5b - MD5:
f4e107206739ef6130476036874fb5ed - ssdeep:
1536:aLPHSyiDQrSzaO0iGeGvqGRvLip9mwVxLfkwD6U44EohW8pO73WyzmCbbfEieBp0:0PHDhO7Ae67RvWppxQwD/41oY7CkfE5g - TLSH:
T12139CFF311A3CD4C77978F4329AB1258A089D7C42662E66095C8B77CD8FC9BDBE04621 - Submitted as: vebuvijenifewovev.pdf
- File type: pdf · Size: 85301 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://drzwiukryte.pl/userfiles/file/demas.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://bedandbreakfastchia.it/userfiles/file/59180345536.pdf, http://ephtour.com/FileData/ckfinder/files/20210911_9A9B9EA38B170E2E.pdf, http://drzwiukryte.pl/userfiles/file/demas.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/PmAiG5ZyT-k/uplcv?utm_term=watch+high+maintenance+online+free
- https://bedandbreakfastchia.it/userfiles/file/59180345536.pdf
- http://ephtour.com/FileData/ckfinder/files/20210911_9A9B9EA38B170E2E.pdf
- http://drzwiukryte.pl/userfiles/file/demas.pdf
- http://cathyknightwaite.com/ckfinder/userfiles/files/95506153464.pdf
- http://phayaotechno.com/UserFiles/File/13040444443.pdf
- https://millersexpress.com/userfiles/file/45178832643.pdf
- http://wasserentkalkung.at/ckfinder/userfiles/files/64397995109.pdf
- http://balletpanov.com/uploads/files/58426342148.pdf
- https://riverasphotovideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613947c6560b8---gatixevenajarunupepiwi.pdf
- https://ksmt.edu.np/assets/ckfinder/userfiles/files/nafivevagexol.pdf
- http://steffis-strassladen.de/userfiles/file/42274107905.pdf
- https://ooobelkom.ru/ckfinder/userfiles/files/dumoruwazud.pdf
- https://varida-tech.com/ckfinder/userfiles/files/gujov.pdf
- http://rexant.by/upload/editor/files/jugitinuroraz.pdf
- https://www.reliancecareuk.com/wp-content/plugins/super-forms/uploads/php/files/acdf66dffc9079cab3e3e36212db9253/5549204245.pdf
- http://feldbach-tourismus.at/files/sisuw.pdf
- https://rsvforum.com/userfiles/file/59524086149.pdf
- https://riosemarescentrodemergulho.com/ckfinder/files/13352576327.pdf
- http://propack-th.com/image/upload/File/6549245921.pdf
- http://phrabat.net/UserFiles/File/24053241761.pdf
- http://delannahotel.com/user_img/file/wadimibelon.pdf
- https://rjiminfra.com/wp-content/plugins/super-forms/uploads/php/files/77ad0b3419716e1edae38525c65c3d1a/vikojebumajijuzugizaxemir.pdf
- http://tentauto23.ru/ckfinder/userfiles/files/47134083485.pdf
- https://www.yoursurveysurveyors.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1613b02f8b3ada---21215192290.pdf
Embedded domains
- feedproxy.google.com
- bedandbreakfastchia.it
- ephtour.com
- drzwiukryte.pl
- cathyknightwaite.com
- phayaotechno.com
- millersexpress.com
- balletpanov.com
- riverasphotovideo.com
- steffis-strassladen.de
- ooobelkom.ru
- varida-tech.com
- www.reliancecareuk.com
- rsvforum.com
- riosemarescentrodemergulho.com
- propack-th.com
- phrabat.net
- delannahotel.com
- rjiminfra.com
- tentauto23.ru
- www.yoursurveysurveyors.co.uk
- structurecreative.com
- fatimaartwork.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report