MALICIOUS — seduvuligamezumu.pdf
MALICIOUS — seduvuligamezumu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1af1cc49192de6fc4b9f50cc3d83dd8bf2bd88abe57a9ea7a152fbb003e1931b - SHA-1:
5cf0e8c15d527826199674d1d768f881532f7d0e - MD5:
f46a9b750d8fc14b62353c708e1765ff - ssdeep:
1536:3GM5+dIdSK6PD9L/eHsaMGbnqdW6pOu26Wws0IV9pAn4/uu:mnKuxCs/Guuu2vp/b - TLSH:
T19037B0F32187DD4C778F9B0769E711A4A086D68C6562AF50404C77BCD47CA7CBB24A11 - Submitted as: seduvuligamezumu.pdf
- File type: pdf · Size: 72847 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://posaonakosovu.com/ckfinder/userfiles/files/sobot.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://velvetskin.pl/wp-content/plugins/super-forms/uploads/php/files/5a45b8ba1e09e5f38ea5f2174040bbdc/kavuzutilenakifizobutiju.pdf, http://bluecars.pl/userfiles/file/vutajunevod.pdf, https://wurstfargo.com/wp-content/plugins/super-forms/uploads/php/files/8b2ddb5e96bb2876277a9eb93f83a47f/3118168099.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/3CAf4wW3hvY/uplcv?utm_term=numerical+methods+for+scientists+and+engineers+h+m+antia+pdf
- https://velvetskin.pl/wp-content/plugins/super-forms/uploads/php/files/5a45b8ba1e09e5f38ea5f2174040bbdc/kavuzutilenakifizobutiju.pdf
- http://bluecars.pl/userfiles/file/vutajunevod.pdf
- https://wurstfargo.com/wp-content/plugins/super-forms/uploads/php/files/8b2ddb5e96bb2876277a9eb93f83a47f/3118168099.pdf
- https://posaonakosovu.com/ckfinder/userfiles/files/sobot.pdf
- https://www.andyselfstorage.co.uk/wp-content/plugins/super-forms/uploads/php/files/bn2m43j8s8tv9lg49142g4r3t9/73886549172.pdf
- https://www.dyna-tech.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160f7dbab18646---wezedudedozimosixod.pdf
- https://braviengenharia.com.br/wp-content/plugins/super-forms/uploads/php/files/2f3k6unememoifgb74hphdh6i3/47907822077.pdf
- https://www.quatainvestimentos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608a8c3498ceb---28422881707.pdf
- http://andreevmag.com/wp-content/plugins/super-forms/uploads/php/files/7b75408f675376ac25b2b53ece52cf71/giwixolafinube.pdf
- https://www.karavanlakesfet.com/wp-content/plugins/super-forms/uploads/php/files/563d353420fcab10f52b9529391d58a1/66966650932.pdf
- https://kalatranslation.co.uk/wp-content/plugins/super-forms/uploads/php/files/fvjap2co0nl06nfi1880hef7p2/63641909248.pdf
- https://victory-agency.com/wp-content/plugins/formcraft/file-upload/server/content/files/16108b6aa33707---42111885507.pdf
- http://hattrick-sports.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b2f89b843a4---11010340059.pdf
- https://tomorrowhubs.com/upload/users/files/bevupakoxutopi.pdf
- https://lotte-ppta.com/beta/assets/file/xuwivukobowovomekow.pdf
- https://webmedcentralplus.com/userfiles/file/xugetunofolujaxo.pdf
- http://bobas24.pl/Upload/file/85438274388.pdf
- https://homeaestheticsllc.com/wp-content/plugins/super-forms/uploads/php/files/a3ed086aaa6bcccc6a865e34bd2cdc4e/maluxilojo.pdf
- https://botroul.be/uploads/dexadikekorigotaxebijevi.pdf
- https://vestol.bg/files/file/30687559613.pdf
- http://pro.ovh.net/~tribuene/images/banque/file/gotap.pdf
- https://aftaplan.com/works/peepsparty/html/upload_files/file/54082519845.pdf
- https://ccskin.com/geektic/files/24051122045.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- velvetskin.pl
- bluecars.pl
- wurstfargo.com
- posaonakosovu.com
- www.andyselfstorage.co.uk
- www.dyna-tech.nl
- braviengenharia.com.br
- www.quatainvestimentos.com.br
- andreevmag.com
- www.karavanlakesfet.com
- kalatranslation.co.uk
- victory-agency.com
- hattrick-sports.com
- tomorrowhubs.com
- lotte-ppta.com
- webmedcentralplus.com
- bobas24.pl
- homeaestheticsllc.com
- botroul.be
- pro.ovh.net
- aftaplan.com
- ccskin.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report