MALICIOUS — xowowivoper.pdf
MALICIOUS — xowowivoper.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e6e15c550c63e3376e5a240b99f82efd43363e6aa17988620887aad9b652177f - SHA-1:
feb82d10b3018b979521f7e6753e80dd34e497cf - MD5:
ab4e26b1e621facece62c7da9a926676 - ssdeep:
1536:DswFvQuRY0CXOoAxM1vYXuwgBARnnMOLSuWOpOwrqIdMW0WFcNAf0EgDkv:LFUjXOLOQXQsnSDwrq4QWX0Egk - TLSH:
T1C438C0F751EBEC4C76AB5B0325FB217C908ADB845163EBA0408CB6AC957C77DAE10940 - Submitted as: xowowivoper.pdf
- File type: pdf · Size: 78293 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://salman-is.com/userfiles/file/tevalowebigoxomosuzexax.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://crewmak.ru/uplcv?utm_term=o2jam+u+mod, https://bibliotheque-des-arts.ch/ckfinder/userfiles/files/55523932296.pdf, http://sjar-tech.com/uploadfile/file///2021090519550114.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crewmak.ru/uplcv?utm_term=o2jam+u+mod
- https://bibliotheque-des-arts.ch/ckfinder/userfiles/files/55523932296.pdf
- http://sjar-tech.com/uploadfile/file///2021090519550114.pdf
- http://salman-is.com/userfiles/file/tevalowebigoxomosuzexax.pdf
- http://bsp-oblspl.org/ckfinder/userfiles/files/jijadotuziwib.pdf
- http://rtm-plus.ru/ckfinder/userfiles/files/93571031240.pdf
- http://podhoru.cz/userfiles/file/16220713117.pdf
- http://santamariamikado.com/uploads/files/vabivakawile.pdf
- http://spzpoz-zdunskawola.pl/upload/file/wojimito.pdf
- https://limpjet.com.br/wp-content/plugins/super-forms/uploads/php/files/848c1296c4e10f672691f3088130edb8/15309869007.pdf
- https://rt9.rspo.org/ckfinder/userfiles/files/davak.pdf
- http://namadagaskare.ru/ckfinder/userfiles/files/40460745329.pdf
- http://barrybusiness-crm.com/ressource/devis-photo/files/49198430834.pdf
- https://unitjaya.com/contents/files/tunafogobupujufelumu.pdf
- http://halmar.info/userfiles/file/talikidilagulukik.pdf
- https://parisnordmedical.fr/docs/file/viduwowafutabagat.pdf
- http://ptaki.info/imgekoprojekty/files/46673969504.pdf
- http://healthywithhart.com/res/file/6022985805.pdf
- https://milsagliksen.org/upload/ckfinder/files/kajixoponevirakezofag.pdf
- http://brezov-gaj.si/uporabnik/file/46271630769.pdf
- http://nhahanghienminh68.com/upload/files/72638768902.pdf
- http://thephinhmienbac.com/upload/files/nipuwuxa.pdf
- http://cobe-ing.it/userfiles/files/famoxegakedoko.pdf
- https://mttrasportisrl.it/dati/upload/file/vujodiginabebibufakaki.pdf
- https://dazzlin.co.uk/wp-content/plugins/super-forms/uploads/php/files/89a5ef4b984ce12c7a111971dac9b3a8/26920590603.pdf
Embedded domains
- crewmak.ru
- bibliotheque-des-arts.ch
- sjar-tech.com
- salman-is.com
- bsp-oblspl.org
- rtm-plus.ru
- santamariamikado.com
- spzpoz-zdunskawola.pl
- limpjet.com.br
- rt9.rspo.org
- namadagaskare.ru
- barrybusiness-crm.com
- unitjaya.com
- halmar.info
- parisnordmedical.fr
- ptaki.info
- healthywithhart.com
- milsagliksen.org
- nhahanghienminh68.com
- thephinhmienbac.com
- cobe-ing.it
- mttrasportisrl.it
- dazzlin.co.uk
- v-rshine.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report