MALICIOUS — kisewa.pdf
MALICIOUS — kisewa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f2bfcbd007d0d1e5c095eddc900948359eaf98397c91f196c119341cf749618a - SHA-1:
3c4b0f2f497c989bb02fe6991ac2e57ce8a581a5 - MD5:
7ef37920078ed0b799d6f7a364b742d6 - ssdeep:
1536:hosX6aa7xa8kFmz94h3/hBmb9Ga4FVM4v29L+RFhTAthulaDfi3NWR1CsEo8Ylfa:dqlhkjh3m5b4FVMQ29YNlaDq30Eorlfa - TLSH:
T1533AD0F32067DD5CB65EDF03A99B116CB09AC6842133EA904888B5FDC4BCA3E7E14951 - Submitted as: kisewa.pdf
- File type: pdf · Size: 98201 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://bscsaoner.in/ckfinder/userfiles/files/5623465107.pdf - network signal, weight 0.70, confidence 0.80
- Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://makaeximworld.com/wp-content/plugins/formcraft/file-upload/server/content/files/16097088dd45d7---nesipuje.pdf, http://bscsaoner.in/ckfinder/userfiles/files/5623465107.pdf, http://abwvictory.com/uploads/files/82451854688.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/ngfLrbzwjls/uplcv?utm_term=the+famished+road+summary+and+analysis+pdf
- http://makaeximworld.com/wp-content/plugins/formcraft/file-upload/server/content/files/16097088dd45d7---nesipuje.pdf
- http://bscsaoner.in/ckfinder/userfiles/files/5623465107.pdf
- http://abwvictory.com/uploads/files/82451854688.pdf
- https://southernlightingsource.com/wp-content/plugins/super-forms/uploads/php/files/554000ad35ffa3508b3d9adc49112950/89321119172.pdf
- https://xaydungdonggia.com/app/webroot/files/images/pages/files/42142004828.pdf
- https://harpethvalleyhealth.com/wp-content/plugins/super-forms/uploads/php/files/c7c9cdd16adb0a5fc568f9c1b79240c8/foworikove.pdf
- http://chixue.com/uploadfile/file/20210522015923.pdf
- http://assessmentinsight.com/ckfinder/userfiles/files/jagexeli.pdf
- http://oneself.pro/wp-content/plugins/formcraft/file-upload/server/content/files/160d5c6512d271---99200524510.pdf
- https://laneopx.com/wp-content/plugins/formcraft/file-upload/server/content/files/160fa221195166---37193442770.pdf
- https://usssecuritate.ro/userfiles/file/fisubirexipuvum.pdf
- http://meuseguro.top/fotosempresa//files/paxisokuxaletisil.pdf
- https://sanghvicranes.com/staging/media/35355167216.pdf
- http://myexamadvisor.com/fck_uploads/files/32744524816.pdf
- https://tucsonhomewindowtint.com/wp-content/plugins/super-forms/uploads/php/files/755aed2f6b78d181fb581a604c8b020d/26810435605.pdf
- https://nicemexico.net/wp-content/plugins/formcraft/file-upload/server/content/files/160f0decb40238---sosajovobufog.pdf
- https://areshin.ru/wp-content/plugins/super-forms/uploads/php/files/dfe83574332ca0936ebb697f4d960bbb/voxizujamus.pdf
- https://autoandtruckrepair.net/nbloom/fckuploads/file/sodozabutiro.pdf
- http://ressourcengarten.de/azubi/userfiles/files/pulogukujiwarud.pdf
- https://churchosonline.com/wp-content/plugins/super-forms/uploads/php/files/9dcd95ec757504f3e308901f7129b3c4/76165643148.pdf
- http://nuestratierrapremios.com/campannas/file/durijoxajuxorapujar.pdf
- https://www.ezhealthcheck.com/wp-content/plugins/super-forms/uploads/php/files/b2nbdg11qsdij3km9so3k4jvck/reduvabuwibelupeb.pdf
- https://ethiquedevelopers.com/wp-content/plugins/super-forms/uploads/php/files/1785b6174419f811038aa80f60070164/sevituxuratikuwatunezu.pdf
- http://bridgesonthepark.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608041a7c0f67---wexogoko.pdf
Embedded domains
- feedproxy.google.com
- makaeximworld.com
- bscsaoner.in
- abwvictory.com
- southernlightingsource.com
- xaydungdonggia.com
- harpethvalleyhealth.com
- chixue.com
- assessmentinsight.com
- oneself.pro
- laneopx.com
- meuseguro.top
- sanghvicranes.com
- myexamadvisor.com
- tucsonhomewindowtint.com
- nicemexico.net
- areshin.ru
- autoandtruckrepair.net
- ressourcengarten.de
- churchosonline.com
- nuestratierrapremios.com
- www.ezhealthcheck.com
- ethiquedevelopers.com
- bridgesonthepark.com
- fobiy.net
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report