MALICIOUS — 160b3b8e8d222b---bobufixagewegakixa.pdf
MALICIOUS — 160b3b8e8d222b---bobufixagewegakixa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
eff80e01a9e3537543ee6c3faca3b0ed150cab3e1b8a97826e520b7a19255db0 - SHA-1:
f7d385089496172f89f4e3c271c19d05bfa1e103 - MD5:
244b06fdbe4c4301e601d70dc131c06a - ssdeep:
1536:yRWdbxj86nDjceOcdkIHwh/+yQKCdsoKuPuVfL9/4HJjNm1IYFe:k+84XDBOGwh/+ACOIHJj81ID - TLSH:
T1E237C0F3618BDE9C7E4BAB83AEA5152D109AC78D5232CBA44484B66CC5FC37DAE04510 - Submitted as: 160b3b8e8d222b---bobufixagewegakixa.pdf
- File type: pdf · Size: 72985 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!244B06FDBE4C
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://freemansphotography.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a3498cd1925---84904337216.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://bezpieczna-strefa.pl/wp-content/plugins/super-forms/uploads/php/files/a171b512d6c288e310dcd4bd840d389b/moguvila.pdf, https://bowenpainter.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a19a5138b6a---40371354511.pdf, http://freemansphotography.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a3498cd1925---84904337216.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/LPIa9PGmDLg/uplcv?utm_term=jio+rockers+2021+telugu+movies+download+2020
- http://bezpieczna-strefa.pl/wp-content/plugins/super-forms/uploads/php/files/a171b512d6c288e310dcd4bd840d389b/moguvila.pdf
- https://bowenpainter.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a19a5138b6a---40371354511.pdf
- http://freemansphotography.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a3498cd1925---84904337216.pdf
- https://bokseinstituttet.dk/wp-content/plugins/formcraft/file-upload/server/content/files/1608f3f3ccc115---84646985367.pdf
- https://kvartira-zalog.ru/wp-content/plugins/super-forms/uploads/php/files/3cb48467b1cca1d992e5eef62b1ad6cc/xoxifavatatozi.pdf
- https://www.dekleinewerf.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160a04032f0bd4---rakokakosuxufupeximaxoj.pdf
- http://nek.ua/wp-content/plugins/formcraft/file-upload/server/content/files/1607725047c938---wofuxinekawo.pdf
- https://arihantgranites.in/wp-content/plugins/super-forms/uploads/php/files/5bdmjgf17hi6nv9e8m69fgnl85/xesen.pdf
- http://sugarfree-gelato.com/upload/file/gimarokifefiverar.pdf
- https://cananalimdar.com/wp-content/plugins/super-forms/uploads/php/files/v9ljvdqj2frlt9ee5hp5o6bpro/12043253476.pdf
- https://sweetestspaparty.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075133fc6f18---gapalip.pdf
- https://x-software.cz/data/file/70395395720.pdf
- https://arizonalightingsales.com/wp-content/plugins/super-forms/uploads/php/files/1bbacdbefc52bb6dd6bd1248060e17df/96679429458.pdf
- http://recruiters-zone.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609cc826ede04---tizumapiruguli.pdf
- https://halobysciton.com/wp-content/plugins/formcraft/file-upload/server/content/files/16094b181397fe---92088755952.pdf
- https://edukiya.com/wp-content/plugins/super-forms/uploads/php/files/ec2f9526da54e73fe337d85c9bed8016/danazulizexedi.pdf
- http://dirabrealtors.com/wp-content/plugins/formcraft/file-upload/server/content/files/160706d049b71a---71315343429.pdf
- https://hmv.ir/wp-content/plugins/formcraft/file-upload/server/content/files/1608d9aaf07c98---kodaloj.pdf
- https://drainscovers.com/wp-content/plugins/super-forms/uploads/php/files/3fdd455508410f3258fa9b06d059f717/rokipajifawopedig.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- feedproxy.google.com
- bezpieczna-strefa.pl
- bowenpainter.com
- freemansphotography.com
- kvartira-zalog.ru
- www.dekleinewerf.nl
- nek.ua
- arihantgranites.in
- sugarfree-gelato.com
- cananalimdar.com
- sweetestspaparty.com
- arizonalightingsales.com
- recruiters-zone.com
- halobysciton.com
- edukiya.com
- dirabrealtors.com
- hmv.ir
- drainscovers.com
- www.w3.org
- purl.org
- ns.adobe.com
- bokseinstituttet.dk
- x-software.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report