MALICIOUS — jegimukeje.pdf
MALICIOUS — jegimukeje.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
0cbe3808276b2e80bcba2cd20e937a72683e9e49f973b8514a5c86fe19d2d94b - SHA-1:
e45c9b557fdad8f6235c2ea63bdee94f939f2a82 - MD5:
3e947f4450b25bcd6d00276288cb4676 - ssdeep:
1536:bptUK4U/sCbnzboBLoReeGcapjr5DthrdeL:FtOCbmLoRopjNDtZE - TLSH:
T18837D0F3504BED4CEF4A4B2369EA146CB44FD68A5435CB205488B96DC4ACFBEBD11920 - Submitted as: jegimukeje.pdf
- File type: pdf · Size: 76059 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!3E947F4450B2
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://wastran.ru/uplcv?utm_term=barry+goldwater+range+permit+form, https://www.businesswatchguardingservices.co.uk/wp-content/plugins/super-forms/uploads/php/files/5jmkn2vl14l5j935b8ns9gjjo1/zidixuk.pdf, https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/7801bd4d0ec2d3045b602dd6845ad8fc/12405146837.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://wastran.ru/uplcv?utm_term=barry+goldwater+range+permit+form
- https://www.businesswatchguardingservices.co.uk/wp-content/plugins/super-forms/uploads/php/files/5jmkn2vl14l5j935b8ns9gjjo1/zidixuk.pdf
- https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/7801bd4d0ec2d3045b602dd6845ad8fc/12405146837.pdf
- https://mandalaconfeccao.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608ea18637309---61292261167.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a3f5dd28e78---kefadolu.pdf
- https://centrosteadycam.it/wp-content/plugins/super-forms/uploads/php/files/ad10bfc96d24a3feea1b71e67eaa0a32/rovibopapetajulo.pdf
- https://benjamindreyer.com/wp-content/plugins/super-forms/uploads/php/files/60a52949fab11b4274dbb937effeb163/wigifajewunepibewuj.pdf
- https://relaxationplusmn.com/wp-content/plugins/super-forms/uploads/php/files/20a62cd66d018fcdadbf78bb5408f32a/visufekeli.pdf
- https://www.hadlowsecurityshutters.com/wp-content/plugins/super-forms/uploads/php/files/5e297f73bbb410d9ac9242cc9c17ba9d/10145875074.pdf
- http://fatamorgana.fr/uploads/assets/file/71482302607.pdf
- http://asfalon.com/__files/file/18992140132.pdf
- https://thepetrichortouch.com/wp-content/plugins/super-forms/uploads/php/files/1fk5iebkj4t9gts0r8o8qnt3hm/wivebafibezitabe.pdf
- https://trucraftsmanship.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608128f585e83---43221527427.pdf
- http://www.auditsi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160846d9982982---zogetowonajemivonaxozevom.pdf
- https://gz-topstar.com/wp-content/plugins/super-forms/uploads/php/files/6b32ed6eae9c1f01748d420b1755e5b7/17111192425.pdf
- https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/16077c08f36bd0---guwupiposebebaxefa.pdf
- http://scro.ru/pic/file/fekodop.pdf
- https://ecoinkworld.com/wp-content/plugins/super-forms/uploads/php/files/07b8448ed86690d0d56b0e3ac0424d72/vivojag.pdf
- http://redwoodpwr.com/wp-content/plugins/super-forms/uploads/php/files/5m38bprdcr9qefgt3dsdtnilt4/30214210651.pdf
- http://www.orhancoskun.com/wp-content/plugins/formcraft/file-upload/server/content/files/160866c5daa061---9543283109.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- wastran.ru
- www.businesswatchguardingservices.co.uk
- adbadog.com
- mandalaconfeccao.com.br
- www.1000ena.com
- centrosteadycam.it
- benjamindreyer.com
- relaxationplusmn.com
- www.hadlowsecurityshutters.com
- fatamorgana.fr
- asfalon.com
- thepetrichortouch.com
- trucraftsmanship.com
- www.auditsi.com
- gz-topstar.com
- scro.ru
- ecoinkworld.com
- redwoodpwr.com
- www.orhancoskun.com
- www.w3.org
- purl.org
- ns.adobe.com
- webmodels.studio
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report