MALICIOUS — muxevi.pdf
MALICIOUS — muxevi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
0cd505984a13022336f28fbc139274aae67ed77d71b4e48da033418018049669 - SHA-1:
dcaa32f466883a6e83882ba786a28602475abe7b - MD5:
458cba0d3f4791f6cf5fd0cd45dab03f - ssdeep:
1536:qR2PNpw62mquP3a4q4jIrZqqWT1TsOKaLYi0DkSnYQrLsWQs1hSjz/MonWcupDnm:nFemrarKIg1gOPYi0D6EN+LMzcMDn3mb - TLSH:
T16D39D0F32197DD8CB7C6CF0369EA216D548AD7886171EB614488BB6CC8BCA7CBE14411 - Submitted as: muxevi.pdf
- File type: pdf · Size: 89537 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://phpirateboosters.com/clients/867602/File/87570134728.pdf, https://beautifullifeuk.com/wp-content/plugins/super-forms/uploads/php/files/6df85efb43d29be17f2b9c28bbeedb41/97984939065.pdf, https://www.lang-mayer.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609d455a3243d---gajatikexelaligobimopowub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/zMnd8XtcwSM/uplcv?utm_term=download+game+marvel+offline+mod+apk
- http://phpirateboosters.com/clients/867602/File/87570134728.pdf
- https://beautifullifeuk.com/wp-content/plugins/super-forms/uploads/php/files/6df85efb43d29be17f2b9c28bbeedb41/97984939065.pdf
- https://www.lang-mayer.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609d455a3243d---gajatikexelaligobimopowub.pdf
- https://leunamgroup.com/wp-content/plugins/super-forms/uploads/php/files/e66c3801ae094cbdb5fe004367a4e481/dereset.pdf
- http://isystemlab.com/admin/ckfinder/userfiles/files/94317600590.pdf
- https://grand-forge.ru/wp-content/plugins/super-forms/uploads/php/files/8e4ec389c8ac47fa2817ee7b554e285a/46377088739.pdf
- http://alphasigmaoverseas.com/userfiles/file/pusilemefolukurusosonuna.pdf
- https://euro-m.si/web/dokumenti/file/60420168730.pdf
- https://kalatranslation.co.uk/wp-content/plugins/super-forms/uploads/php/files/jmucnj5pk3lb6dnmkrit3kkb6s/37526556973.pdf
- http://www.gametimecatering.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c69037f291b---zotajixu.pdf
- https://markzone.az/wp-content/plugins/super-forms/uploads/php/files/qcmdn2lsd1ao4spcu1qgqtnr6t/nuguwotikutosopixulafafop.pdf
- https://www.siemers-deutschmann.de/wp-content/plugins/super-forms/uploads/php/files/cc05dg3msn4bb5vks3do20gupm/97618433779.pdf
- http://godswaynehemiahmbc.com/clients/878002/File/kuvesapojojofopa.pdf
- https://www.inkfactory.pk/wp-content/plugins/formcraft/file-upload/server/content/files/16104568b76e21---fuzizuxeminovobu.pdf
- http://hydrem.ru/images/file/volafulemisugexaxuniduf.pdf
- https://www.freshstartdigitalmarketing.com/wp-content/plugins/super-forms/uploads/php/files/e2f0d77f894acdafc2d14c38cabc1f6c/tebizizibesiboz.pdf
- https://contabil-fiscal.ro/mm/file/xuzonikub.pdf
- https://www.oneirishrover.com/wp-content/plugins/super-forms/uploads/php/files/07e1f3b9b49e4fe117c476b22c3c7674/lapewalezo.pdf
- http://webcertain.net/contentupload/fckeditorUploads/organization_/file/64673173077.pdf
- http://fsoa.cn/userfiles/file/seposonip.pdf
- http://esoftland.com/userfiles/file/52281142463.pdf
- https://www.straightmyteeth.eu/wp-content/plugins/super-forms/uploads/php/files/946c61ad66e171a1d72ead013a693c3a/mogarib.pdf
- https://gccpay.net/wp-content/plugins/super-forms/uploads/php/files/8ad84b0910be09cf9c5e34e1ede6e1d8/bukudenifarusore.pdf
- http://www.unidacardoso.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16077a496c6d54---folakavop.pdf
Embedded domains
- feedproxy.google.com
- phpirateboosters.com
- beautifullifeuk.com
- www.lang-mayer.de
- leunamgroup.com
- isystemlab.com
- grand-forge.ru
- alphasigmaoverseas.com
- kalatranslation.co.uk
- www.gametimecatering.com
- www.siemers-deutschmann.de
- godswaynehemiahmbc.com
- hydrem.ru
- www.freshstartdigitalmarketing.com
- www.oneirishrover.com
- webcertain.net
- fsoa.cn
- esoftland.com
- www.straightmyteeth.eu
- gccpay.net
- www.unidacardoso.com.br
- ecompletecontact.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report