MALICIOUS — xamowofuroravipe.pdf
MALICIOUS — xamowofuroravipe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ec5896ddcd901e5f77093ee8d71fe0dd18885143616d31afc283353ebf5fbbd2 - SHA-1:
41b9b4f9e9cdc716537888df1f08c47cf0b22861 - MD5:
81fc57db089179db81d62d0abb00a24c - ssdeep:
1536:I0+Q2rVnkOVsrf2mBzulEU5XJn7Bm65hcVrT7RWFwWyX08qiWXpO/xAkSjCo8:X2rVh2T2mu5XJnA65ovkFCIS/WkoC - TLSH:
T1F439C0F331A7CD4CB75ADB03ABBA1065608AD78C4332EAA05058BB6CD97C17E7E14941 - Submitted as: xamowofuroravipe.pdf
- File type: pdf · Size: 88132 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://www.fattyweng.com.sg/wp-content/plugins/formcraft/file-upload/server/content/files/1609e449c5af33---81155380887.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://www.fattyweng.com.sg/wp-content/plugins/formcraft/file-upload/server/content/files/1609e449c5af33---81155380887.pdf, http://ohsclassof73.com/clients/9/9a/9a21b0b253f7c4eafe662346d237c286/File/lewomujopifumasixedizibef.pdf, https://laughteronlineuniversity.com/images/upload/files/4068860546.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/zMnd8XtcwSM/uplcv?utm_term=how+do+you+tell+if+your+old+coins+are+worth+anything
- http://www.fattyweng.com.sg/wp-content/plugins/formcraft/file-upload/server/content/files/1609e449c5af33---81155380887.pdf
- http://ohsclassof73.com/clients/9/9a/9a21b0b253f7c4eafe662346d237c286/File/lewomujopifumasixedizibef.pdf
- https://laughteronlineuniversity.com/images/upload/files/4068860546.pdf
- http://mclarenquartz.in/ci/userfiles/files/84510541118.pdf
- https://bindazzled.com.au/wp-content/plugins/super-forms/uploads/php/files/a69868841dd71493dd5613fb3f76fb82/madorakazexulupupuxolib.pdf
- http://urduhadith.org/survey/userfiles/files/19770415572.pdf
- https://alcc.vn/wp-content/plugins/super-forms/uploads/php/files/ueeeiadba5vj6tt87fdr46e5mh/vizeriwowofesazogekekasus.pdf
- http://podiummoda.ru/userfiles/file/40038714836.pdf
- https://www.potterycommercials.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1606e36cb72517---39975731030.pdf
- https://www.akilciilacdernegi.com/ckfinder/userfiles/files/99362605175.pdf
- http://sumosushingrill.com/uploads/files/jinixapumejasawozuweralo.pdf
- http://domholidays.com/userfiles/file/nimopuf.pdf
- http://navakarenterprises.com/userfiles/file/jerijoparumafavif.pdf
- http://csc021.com/userfiles/file/20210629015801_bvrh73.pdf
- http://ikhmongol.mn/ckfinder/userfiles/files/4640477084.pdf
- https://www.accidentinjuryalbuquerque.com/wp-content/plugins/super-forms/uploads/php/files/uj03t0ut7ahd7d8vs60kma4q6t/mogezegefojififikimek.pdf
- http://ombs.ru/uploads/files/94237038258.pdf
- https://maloneslandscape.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607643f214fab---xovofinakofumutopoxuju.pdf
- http://alcantara.cz/data/file/67051192373.pdf
- http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cf1eac143cd---61580695819.pdf
- https://tonwen.org/userfiles/file/dalovebib.pdf
- https://asiatravel.kg/wp-content/plugins/super-forms/uploads/php/files/ba75cc56d4af0b7ec614f122166119b1/tejejakipa.pdf
- http://londonjip.com/userData/board/file/12435798602.pdf
- https://pavillonwohlen.ch/userfiles/files/punev.pdf
Embedded domains
- feedproxy.google.com
- www.fattyweng.com.sg
- ohsclassof73.com
- laughteronlineuniversity.com
- mclarenquartz.in
- bindazzled.com.au
- urduhadith.org
- podiummoda.ru
- www.potterycommercials.co.uk
- www.akilciilacdernegi.com
- sumosushingrill.com
- domholidays.com
- navakarenterprises.com
- csc021.com
- www.accidentinjuryalbuquerque.com
- ombs.ru
- maloneslandscape.com
- www.stockholmswingallstars.com
- tonwen.org
- londonjip.com
- pavillonwohlen.ch
- puertoestereo.com
- nd-58.ru
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report