MALICIOUS — bemuga.pdf
MALICIOUS — bemuga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0a396f1fc0b9ec4dc06774f1ee71cd99a898df9896d81cf2fd9f282805612aaa - SHA-1:
02fb274929cacd5febbbc437431e9037a930e7f7 - MD5:
7538f3fb1381e744d05e3331f4f11460 - ssdeep:
1536:+bD/30aLayKd9g3Lieb3sJgmMrW4Uocj3yGmIWwpOS9WJRHO2DEcQ/C1dXfO:QD/ka5Ky2asJg5rW4/nZXSGHPQclK - TLSH:
T19439C0E3229BDD4C765B8B03E6EA0169654ED7896231FB90508CB27CC07CA7DBF11A11 - Submitted as: bemuga.pdf
- File type: pdf · Size: 84909 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://vigova.vn/Images_upload/files/nidirikagazutulosod.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://www.totspotdaynursery.co.uk/ckfinder/userfiles/files/wilog.pdf, https://www.freshstartdigitalmarketing.com/wp-content/plugins/super-forms/uploads/php/files/4260b4618125240a1d29d01f933b0559/soxodipamawitir.pdf, http://vigova.vn/Images_upload/files/nidirikagazutulosod.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BvfzZFkJO3s/uplcv?utm_term=women%27s+shoe+conversion+chart+to+youth
- https://www.totspotdaynursery.co.uk/ckfinder/userfiles/files/wilog.pdf
- https://www.freshstartdigitalmarketing.com/wp-content/plugins/super-forms/uploads/php/files/4260b4618125240a1d29d01f933b0559/soxodipamawitir.pdf
- http://vigova.vn/Images_upload/files/nidirikagazutulosod.pdf
- http://tele-video.ru/upload/files/4667699637.pdf
- http://eldmsh1.ru/js/ckfinder/userfiles/files/mopobevomu.pdf
- https://planet-for-events.de/userfiles/file/92213750240.pdf
- https://restavracia02.com/userfiles/file/50420592835.pdf
- http://maremio.ru/admin/ckfinder/userfiles/files/13836017180.pdf
- http://adams-gold.ru/archive/image/file/pumofimunoperafe.pdf
- https://mission4recruitment.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b2958b7216e---zizuzamewepemudezukega.pdf
- https://agroadvanced.com/app/webroot/newsletters/editor/files/nobobudofimijebuwotu.pdf
- https://alianzatours.com/imagenes/file/desorararopidekap.pdf
- http://wonikquartz.com/upload/editor/file/1628856797.pdf
- http://burrburroughsfamily.com/clients/55468/File/66385018484.pdf
- https://bibliotheque-des-arts.com/ckfinder/userfiles/files/41175732239.pdf
- http://qianxish.com/ckfind_image/files/dexizidulupabuvimun.pdf
- http://tropo-design.com/ckfinder/userfiles/files/24993965684.pdf
- http://st-ark.it/userfiles/files/60724931883.pdf
- http://e-sportis.com/images/upload/60880493770.pdf
- https://ewms.vn/wp-content/plugins/super-forms/uploads/php/files/ufr2q2o4i1an87m6jdmk8cjc0i/45352511771.pdf
- https://parisautotravel.com/wp-content/plugins/super-forms/uploads/php/files/0jae05msg3l3qr5smf55rlc7o0/95552141432.pdf
- http://www.maoles.com/wp-content/plugins/formcraft/file-upload/server/content/files/160fb55439f741---lamemomivagemuremaziloma.pdf
- https://christembassybarking.org/wp-content/plugins/super-forms/uploads/php/files/539c7372dbc5fe8d94c81716cdb6bc11/zesopexabiwusiwexela.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- www.totspotdaynursery.co.uk
- www.freshstartdigitalmarketing.com
- tele-video.ru
- eldmsh1.ru
- planet-for-events.de
- restavracia02.com
- maremio.ru
- adams-gold.ru
- mission4recruitment.com
- agroadvanced.com
- alianzatours.com
- wonikquartz.com
- burrburroughsfamily.com
- bibliotheque-des-arts.com
- qianxish.com
- tropo-design.com
- st-ark.it
- e-sportis.com
- parisautotravel.com
- www.maoles.com
- christembassybarking.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report