MALICIOUS — lemujebufiruturix.pdf
MALICIOUS — lemujebufiruturix.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
463d6c85fe0562322029ca34c98741d007148e0d0b523e9e29c4a08c78d3fbeb - SHA-1:
b3367f2f3a7c7f01312a14a0e71e414db647f859 - MD5:
491b1e0a00ad3ec934e6041cd1a863f3 - ssdeep:
1536:qr/mSPrPL9z4RQ4Vr9ldfvfJYis96B7H0FuFr:APf1M1YBCcs - TLSH:
T17E37D0F37647DDAC7A8A9B036FB6511D914AC7C96132EA6004C4BA3CC47C5EDBE00A61 - Submitted as: lemujebufiruturix.pdf
- File type: pdf · Size: 76582 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!491B1E0A00AD
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://druttle.ru/wb?keyword=how%20to%20tell%20when%20a%20george%20foreman%20grill%20is%20ready, http://govnosiakxws.online/15529457600pntxi.pdf, http://powagurolu.rf.gd/driver_booster_6._2_with_crack.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://druttle.ru/wb?keyword=how%20to%20tell%20when%20a%20george%20foreman%20grill%20is%20ready
- http://govnosiakxws.online/15529457600pntxi.pdf
- http://powagurolu.rf.gd/driver_booster_6._2_with_crack.pdf
- http://wesofidufu.rf.gd/39925647170.pdf
- http://yazansoft.com/41527172870ijhvb.pdf
- http://sunemixawuvija.epizy.com/bypass_app_store_limit.pdf
- http://tokigarodam.22web.org/does_my_head_look_big_in_this_quotes_and_page_numbers.pdf
- http://zezutibad.iblogger.org/52353361687.pdf
- http://poguferuliwu.iblogger.org/gezunexewudiwofititokade.pdf
- http://vowubomirasupem.22web.org/nebebuvibav.pdf
- http://julepudelixi.rf.gd/xenunelene.pdf
- https://cdn-cms.f-static.net/uploads/4408601/normal_6031dc56d3fe1.pdf
- http://bowemesuzot.iblogger.org/46618131153.pdf
- https://cdn.sqhk.co/zaliroded/iv5ghvG/birthday_cake_with_name_edit_app_download.pdf
- http://kengoru.space/29800174470z3h40.pdf
- http://xiradev.rf.gd/cheerleader_song_lyrics.pdf
- http://letilemugemin.66ghz.com/brain_tumor_mri_dataset.pdf
- https://cdn.sqhk.co/gufezitaxato/gdPCjgJ/37137603256.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- druttle.ru
- govnosiakxws.online
- yazansoft.com
- sunemixawuvija.epizy.com
- tokigarodam.22web.org
- zezutibad.iblogger.org
- poguferuliwu.iblogger.org
- vowubomirasupem.22web.org
- cdn-cms.f-static.net
- bowemesuzot.iblogger.org
- cdn.sqhk.co
- kengoru.space
- letilemugemin.66ghz.com
- www.w3.org
- purl.org
- ns.adobe.com
- powagurolu.rf.gd
- wesofidufu.rf.gd
- julepudelixi.rf.gd
- xiradev.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report