MALICIOUS — wiluvufapizarud.pdf
MALICIOUS — wiluvufapizarud.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
469ba633c3c301992c357247dfdcb6a546417fd3021013ac4867c088d0d07917 - SHA-1:
d087b8aab450091daf50bf39c29e5e93f14e94ba - MD5:
0a9d1c3cf8683fd5c0abd8a6d719f761 - ssdeep:
1536:w5bXRXpM1FrU2pJwHustqK/bhZBPw53Y8ecVWhUW187AAcHW8pO7sYh:U7FgNs0K/TBPw5otuWh5yAAca75 - TLSH:
T11F39D0F3209BDD4C76479F03A9E622A9A445E79971319B60018CA7BCD4BC4BDFF00661 - Submitted as: wiluvufapizarud.pdf
- File type: pdf · Size: 91585 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://renetravel.ro/images/files/54336092154.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://dbmotorbrokers.com/userfiles/file/20655317483.pdf, https://wurstfargo.com/wp-content/plugins/super-forms/uploads/php/files/72a16bd879058db5352d6aa81e5410f7/93576200254.pdf, https://renetravel.ro/images/files/54336092154.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/LPIa9PGmDLg/uplcv?utm_term=subtraction+of+binary+numbers+using+2%27s+complement
- https://dbmotorbrokers.com/userfiles/file/20655317483.pdf
- https://wurstfargo.com/wp-content/plugins/super-forms/uploads/php/files/72a16bd879058db5352d6aa81e5410f7/93576200254.pdf
- https://renetravel.ro/images/files/54336092154.pdf
- http://cowmoo.org/ckfinder/userfiles/files/gudosogogusoluwosale.pdf
- https://gradeagroup.com/wp-content/plugins/super-forms/uploads/php/files/dat6776idtiq29elbbp3qi4fsp/5968590013.pdf
- https://www.etbsupplies.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d7e450786c6---36642390899.pdf
- http://xigmatek.com/upload/files/13825792444.pdf
- https://cristalparkhotel.com/ckfinder/userfiles/files/sizeguxemexi.pdf
- https://www.etbsupplies.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bbcfd9cb951---mulefolif.pdf
- http://www.combatsim.eu/wp-content/plugins/formcraft/file-upload/server/content/files/16087f53e164bb---35977422174.pdf
- http://atomleasing.ru/media/File/63758942119.pdf
- http://hosteleriayvending.com//ckfinder/userfiles/files/tanikirivi.pdf
- https://nhaban24h.com.vn/wp-content/plugins/super-forms/uploads/php/files/ab8g7k458eufuj03bc64brnivj/xizujobobek.pdf
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1608801455f794---45451600638.pdf
- https://transpack-krumbach.de/_upload_bilder/_filemanager/file/wirivewo.pdf
- http://diclenakliyat.com/userfiles/file/nekedoxejegibuserabuxi.pdf
- https://www.ediliziaindustriale.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b80696bce99---zomurusani.pdf
- https://electrabicycles.pl/app/webroot/uploads/file/16213492869124.pdf
- https://fertilizergranulatorprice.com/d/files/44699082048.pdf
- https://hiroyoung.com/data/files/61692351650.pdf
- https://www.chartsunlimited.com.ph/wp-content/plugins/formcraft/file-upload/server/content/files/160750b15daf20---76805901301.pdf
- http://alnoorcity.com/userfiles/file/95294629263.pdf
- https://ankaratemizlikcim.com/depo/sayfaresim/file/katogisopawun.pdf
- https://adiwirawanbali.com/wp-content/plugins/super-forms/uploads/php/files/10716b44fc00f2fee82ca23a505c8d36/41384452988.pdf
Embedded domains
- feedproxy.google.com
- dbmotorbrokers.com
- wurstfargo.com
- cowmoo.org
- gradeagroup.com
- www.etbsupplies.com
- xigmatek.com
- cristalparkhotel.com
- www.combatsim.eu
- atomleasing.ru
- hosteleriayvending.com
- kaufdeinauto.de
- transpack-krumbach.de
- diclenakliyat.com
- www.ediliziaindustriale.com
- electrabicycles.pl
- fertilizergranulatorprice.com
- hiroyoung.com
- alnoorcity.com
- ankaratemizlikcim.com
- adiwirawanbali.com
- timebank.ru
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report