MALICIOUS — bijupidipatazidab.pdf
MALICIOUS — bijupidipatazidab.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e99e904ee00b475d49d5b5ab80c59018fe0ae92bec3f8a9568c227616026faf4 - SHA-1:
961cc04f4665221b0f056d33d36ecda0e4b7c7d1 - MD5:
d099941c7d15c198a06d24298b3ab82a - ssdeep:
1536:7TPp8Dq4dg0t7x2bkOWURnxsPRVgmTQAUjO+WOpOaZEWYyUVvyWTuTHAMzHIc265:3p0q4qE7A9RRnxsZbxU4aZkyWKx7MA - TLSH:
T19639C0F321ABFD9C738EAB0364AF515EB097D7886571AA6001887B2DC53C9BD7E00911 - Submitted as: bijupidipatazidab.pdf
- File type: pdf · Size: 85581 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://nutronicltd.com/userfiles/file/sogikudabowosokajusab.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://apexsafetyproducts.com/ckfinder/userfiles/files/89693193888.pdf, https://tecsal.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/161306638f0a54---50119588390.pdf, http://aotwresort.info/ckfinder/userfiles/files/kozifi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/DOqCt-cVA4I/uplcv?utm_term=best+bluetooth+gamepad+app+for+android
- https://apexsafetyproducts.com/ckfinder/userfiles/files/89693193888.pdf
- https://tecsal.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/161306638f0a54---50119588390.pdf
- http://aotwresort.info/ckfinder/userfiles/files/kozifi.pdf
- https://treasurehunterdetectors.solar-ovens.net/ckfinder/userfiles/files/33728346724.pdf
- http://nutronicltd.com/userfiles/file/sogikudabowosokajusab.pdf
- https://euinsuti.ro/app/webroot/files/userfiles/files/gesujenosa.pdf
- http://darec.sk/files/files/56110308972.pdf
- http://opersan.com/file/68576123962.pdf
- http://rosniyom.com/userfiles/files/gowoku.pdf
- http://gyermekhaz.hu/Content/site_images/files/12374583107.pdf
- http://profil-metall.de/content/uploads/file/77953668139.pdf
- https://mimpiindah168.com/contents/files/67261534388.pdf
- http://boek.se/bilder_umeny/File/82684679800.pdf
- http://hc6999.com/userfiles/files/63548622283.pdf
- http://pastadimatteo.com/ckfinder/userfiles/files/18058342346.pdf
- http://inlovehuahin.com/file_media/file_image/file/37426656780.pdf
- https://chocoinmobiliario.com/wp-content/plugins/super-forms/uploads/php/files/14b8d956a89d075b2028d65bea55d251/66372006962.pdf
- https://www.horisunmauritius.com/wp-content/plugins/super-forms/uploads/php/files/a41fdb468696f0921d91ec27ebd3479f/zomidevotebomo.pdf
- http://www.jindatunnel.com/up_files/file/lelexaviwidozowimix.pdf
- http://jca-t.com/fck_image/file/86372489334.pdf
- http://chokysitohang.com/Uploads/userfiles/files/32427667473.pdf
- http://www.guus.edu.mn/ckfinder/userfiles/files/fikesa.pdf
- http://qataminational.com/uploaded_files/userfiles/files/gawesilafulowukepinuz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- apexsafetyproducts.com
- tecsal.com.br
- aotwresort.info
- treasurehunterdetectors.solar-ovens.net
- nutronicltd.com
- opersan.com
- rosniyom.com
- profil-metall.de
- mimpiindah168.com
- boek.se
- hc6999.com
- pastadimatteo.com
- inlovehuahin.com
- chocoinmobiliario.com
- www.horisunmauritius.com
- www.jindatunnel.com
- jca-t.com
- chokysitohang.com
- qataminational.com
- www.w3.org
- purl.org
- ns.adobe.com
- euinsuti.ro
- darec.sk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report