MALICIOUS — vomuwa.pdf
MALICIOUS — vomuwa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
414f436aaafc02882d06e7b200a97d1e50b70d0cc0ce9302bc0219f1a60ea9a9 - SHA-1:
d08386099020e1bb8e1e77e6fbf343af555d5809 - MD5:
3488bc5b2148778bae9626a3b7eb15e1 - ssdeep:
1536:GuSyFIV+Ue/ohXnMEIUqUJYCciN1Mp7soq6fpNec54UHdLHQPWb+uoqkJ/ySl3WV:03+nw5IZOdZHMJvuKZwW+uoq4nlq7F - TLSH:
T12238D0F32073ED8C7A4A8F4766FF12AD554AE79822239A404088776CC17C5BDBF24652 - Submitted as: vomuwa.pdf
- File type: pdf · Size: 83618 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://rmdschoolandcollege.com/wp-content/plugins/super-forms/uploads/php/files/c5b0790226a31de74788cfa449860bea/79467124519.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://infrive.ru/uplcv?utm_term=free+fire+mega+mod, http://nikolalepojevic5.com/multimedia/file/79988637727.pdf, https://sca-eagleegg5k.com/ckfinder/triplebuserfiles/file/30418984308.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://infrive.ru/uplcv?utm_term=free+fire+mega+mod
- http://nikolalepojevic5.com/multimedia/file/79988637727.pdf
- https://sca-eagleegg5k.com/ckfinder/triplebuserfiles/file/30418984308.pdf
- http://gimhaejazz.com/fckeditor/userfiles/image/6345242914.pdf
- http://wwsm-us.com/files/file/27598198073.pdf
- http://bluecreator.biz/ckfinder/userfiles/files/89470658638.pdf
- https://rmdschoolandcollege.com/wp-content/plugins/super-forms/uploads/php/files/c5b0790226a31de74788cfa449860bea/79467124519.pdf
- http://grgct.com/ckfinder/userfiles/files/betepewelixe.pdf
- https://www.myjamaicais.com/wp-content/plugins/super-forms/uploads/php/files/7cdd937cf2436e3d4678403e8de8c281/pukijupuzajomobesagefid.pdf
- https://congnghieptauthuyvietnam.vn/upload/files/miwipivivadavitov.pdf
- http://www.multigacos.com/admin/uploaded/fck/file/69886531440.pdf
- http://abwcockeysville.com/uploads/files/4654938684.pdf
- http://glamour-nsk.ru/ckfinder/userfiles/files/48978051793.pdf
- http://josquin-capella.de/download/97715914391.pdf
- https://2acontractor.it/images/file/rixelewexamifupexagenelim.pdf
- https://rubyyadav.com/nbloom/fckuploads/file/88576471937.pdf
- http://autoset66.ru/admin/ckfinder/userfiles/files/87340799616.pdf
- http://www.sarajevo-inn-grunewald.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612fe642ec057---7315669549.pdf
- https://heyratacademy.ir/file/fakelugatusagidenariwuv.pdf
- http://esistore.de/userfiles/file/mizakefevu.pdf
- https://partnermind.cz/images/files/feduwawarukuveril.pdf
- http://tranhdaquydep.vn/upload/files/sokojuvixokokadi.pdf
- https://wcdt.co.th/wp-content/plugins/super-forms/uploads/php/files/u24qq5sin8lvpaohr4ijgmmhcl/suxid.pdf
- https://thehideawayresortpattaya.com/userfiles/files/rizejakegidebo.pdf
- https://www.campacinter.com/image/upload/File/lupofewikomivogexuga.pdf
Embedded domains
- infrive.ru
- nikolalepojevic5.com
- sca-eagleegg5k.com
- gimhaejazz.com
- wwsm-us.com
- bluecreator.biz
- rmdschoolandcollege.com
- grgct.com
- www.myjamaicais.com
- www.multigacos.com
- abwcockeysville.com
- glamour-nsk.ru
- josquin-capella.de
- 2acontractor.it
- rubyyadav.com
- autoset66.ru
- www.sarajevo-inn-grunewald.com
- heyratacademy.ir
- esistore.de
- thehideawayresortpattaya.com
- www.campacinter.com
- www.w3.org
- purl.org
- ns.adobe.com
- congnghieptauthuyvietnam.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report