MALICIOUS — gupaxazaxelejelutananef.pdf
MALICIOUS — gupaxazaxelejelutananef.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d049bb392b5d359c282c0d06bbec7856440f9283e9ad285a6e719bfcd2aaa4dc - SHA-1:
1b581ea887d903ff634b78a5d96595f2886b1a5f - MD5:
497a679636fe662b7cd735226bcb091f - ssdeep:
3072:iLRZNsZlmIZ0p6rjmBOWOtBN3GoHRvf4qkOb:41HzDB/O3/n - TLSH:
T1373CDFF30097DC5C77868B4375EA14AC708AD7893221E9E04598B27CD4BC9FE7E24A61 - Submitted as: gupaxazaxelejelutananef.pdf
- File type: pdf · Size: 112236 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ambvetsanprospero.eu/userfiles/files/53934937073.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://ambvetsanprospero.eu/userfiles/files/53934937073.pdf, http://kientrucsangtrong.com/plus/files/xexaj.pdf, http://mayinmaunhat.com/upload/files/kujanafupipepig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/A3Ryygt5BCM/uplcv?utm_term=brawl+stars+36.218+download
- http://ambvetsanprospero.eu/userfiles/files/53934937073.pdf
- http://kientrucsangtrong.com/plus/files/xexaj.pdf
- http://mayinmaunhat.com/upload/files/kujanafupipepig.pdf
- https://kermoulin.com/userfiles/file/46205806136.pdf
- http://www.trimbleexpress.sk/wp-content/plugins/formcraft/file-upload/server/content/files/1613bd32c027c0---sifamif.pdf
- http://wadsoda.com/UserFiles/File/lilafajodevamuf.pdf
- http://studiofranzoni.eu/userfiles/files/83524617029.pdf
- http://studioarchterreni.it/userfiles/files/67688221164.pdf
- http://cukierniabrzezinski.pl/www/artizam/fck/file/xixovisoparazak.pdf
- http://www.deadclan.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1612f0ea46f724---48290484505.pdf
- https://global-brand.net/userfiles/files/jawifikusitelowofoxopul.pdf
- http://arndt-fahrschule.de/userfiles/file/29960464447.pdf
- http://zubrcup.by/files/files/kepulafumitafimetixej.pdf
- https://cobaltinc.org/userfiles/file/85681189926.pdf
- http://dienvietbac.com/uploads/files/99322020721.pdf
- http://color-gateway.com/userfiles/file/65652932160.pdf
- http://cityfate.com/files/files/metiloxugoni.pdf
- http://norrlandet.se/userfiles/file/mopuwibavawukuwajogibaj.pdf
- http://villabrown.it/userfiles/files/96518566857.pdf
- https://vonia.mikludava.lt/images/files/pokuvowasusip.pdf
- https://luxartparquet.com/wp-content/plugins/super-forms/uploads/php/files/a4a43c0bbff6753c5dfdac3956381521/27303653867.pdf
- http://kahsport.cz/userfiles/file/29620685387.pdf
- https://pottoka.info/files/galeria/files/9608127246.pdf
- http://csc-028.com/userfiles/file/20210907003344_37gh8b.pdf
Embedded domains
- feedproxy.google.com
- ambvetsanprospero.eu
- kientrucsangtrong.com
- mayinmaunhat.com
- kermoulin.com
- wadsoda.com
- studiofranzoni.eu
- studioarchterreni.it
- cukierniabrzezinski.pl
- www.deadclan.nl
- global-brand.net
- arndt-fahrschule.de
- cobaltinc.org
- dienvietbac.com
- color-gateway.com
- cityfate.com
- norrlandet.se
- villabrown.it
- luxartparquet.com
- pottoka.info
- csc-028.com
- harposwebdesign.nl
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report