MALICIOUS — nujadev.pdf
MALICIOUS — nujadev.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
022b348c960159c5331b7c0c8b5644c0daf23cecf2b6ca4d3429441137464ed0 - SHA-1:
1d223c118b7d1950ef623c9dfdd4851c9f8f1886 - MD5:
69673bc2a41df53f9a39c184f31bdbbe - ssdeep:
1536:RUWhWUpvg3WliJyEsm+aEr7hWWFZxgfH0LpzWGpOKCWJjJ13//LY1lOv:uWIUpvviJyEsCEXhpTggpUK99/jyY - TLSH:
T15339C0F37197DD9C72CE9B036AEA1574B048E68C2162D8A041C8766CE57C9FEEF14A40 - Submitted as: nujadev.pdf
- File type: pdf · Size: 84367 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://infoguard.ru/content/file/fevujep.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://icmasistemas.com/userfiles/files/gataroki.pdf, http://www.webtony.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16133dada871e0---14032993453.pdf, https://ontech.vn/images/ckeditor/files/94844757521.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/zMnd8XtcwSM/uplcv?utm_term=live+stream+sports+boxing
- http://icmasistemas.com/userfiles/files/gataroki.pdf
- http://www.webtony.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16133dada871e0---14032993453.pdf
- https://ontech.vn/images/ckeditor/files/94844757521.pdf
- http://infoguard.ru/content/file/fevujep.pdf
- https://mavibusiness.it/file/94208625080.pdf
- https://riwg.in/userfiles/file/57998290809.pdf
- https://elemental-ia.com/userfiles/file/pawemisizagobo.pdf
- https://073741256.com/uploads/files/202109010551079036.pdf
- http://deeringbayrealestate.com/userfiles/files/18539586699.pdf
- http://cuanhuadanang.vn/uploads/image/files/pafojexevawugo.pdf
- http://nuyewrecruitment.com/wp-content/plugins/super-forms/uploads/php/files/664ceb708bec5b05383b2893463ebc68/7634993018.pdf
- http://omni-links.com/images/blog/file/97414189202.pdf
- https://dnm.tw/uploads/files/202109111110194675.pdf
- http://ff-engineering.com/userfiles/files/nezifoputu.pdf
- http://ankaser.com/userfiles/file/milugepaxazefagosikepi.pdf
- https://beyondpins.com/calisma2/files/uploads/52048501626.pdf
- https://scalper.ir/data/files/file/89427555739.pdf
- https://bruceleevideos.org/images/file/xomamedojutitedixo.pdf
- https://www.higher-energy-trampolineclub.com/wp-content/plugins/formcraft/file-upload/server/content/files/161408d06b4bcd---59141764298.pdf
- https://commonwealthsportsawards.com/userfiles/file/17273635985.pdf
- http://uniondeautoescuelas.com/wp-content/plugins/formcraft/file-upload/server/content/files/161409145b10ac---vepunofajazasalipud.pdf
- https://iringmalaysia.com/ckfinder/userfiles/files/55577622595.pdf
- http://ivankotov.ru/img/lib/file/basubewemojigujeronuzele.pdf
- http://aktien-analyse.de/images/File/jiselu.pdf
Embedded domains
- feedproxy.google.com
- icmasistemas.com
- www.webtony.com.br
- infoguard.ru
- mavibusiness.it
- riwg.in
- elemental-ia.com
- 073741256.com
- deeringbayrealestate.com
- nuyewrecruitment.com
- omni-links.com
- dnm.tw
- ff-engineering.com
- ankaser.com
- beyondpins.com
- scalper.ir
- bruceleevideos.org
- www.higher-energy-trampolineclub.com
- commonwealthsportsawards.com
- uniondeautoescuelas.com
- iringmalaysia.com
- ivankotov.ru
- aktien-analyse.de
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report