MALICIOUS — luxep.pdf
MALICIOUS — luxep.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4eff6982c4cfe30648bffb43be760817dfb9d9289abc0fa14591a3f2275d6297 - SHA-1:
e34112fc7edd4f96ee8113684b013e0f90052baf - MD5:
85b39a3681c7a21e701cf2f7e934e3ff - ssdeep:
1536:iOCFoSorxrXAT30dp4k8xluh2OR/j1ZdawPzp1iTWiLW6Gfpsz1WcpOmNvr:7goS+xbATEw3OR/j1ZMwPzpCWiT8pszL - TLSH:
T12D39B0F320A7ED8C7B8BDB47B95B0198A046D788A132EB6041C8B7BCC5BC5BD7A44511 - Submitted as: luxep.pdf
- File type: pdf · Size: 85212 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://lion-trading.co.uk/wp-content/plugins/super-forms/uploads/php/files/7s0jotvadnl16hu6jltf5nu4if/ravipigo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://kennyre.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e32c83e300b---wibunudavabu.pdf, https://www.bouwenaaneensterkwerkgeversmerk.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16072af160426c---23523794467.pdf, http://fundacionecla.org/resources/original/file/32229309501.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/BkSY9tpko7c/uplcv?utm_term=tercer+trimestre+del+embarazo+pdf
- http://kennyre.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e32c83e300b---wibunudavabu.pdf
- https://www.bouwenaaneensterkwerkgeversmerk.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16072af160426c---23523794467.pdf
- http://fundacionecla.org/resources/original/file/32229309501.pdf
- https://lion-trading.co.uk/wp-content/plugins/super-forms/uploads/php/files/7s0jotvadnl16hu6jltf5nu4if/ravipigo.pdf
- https://nazragame.com/calisma2/files/uploads/95379996321.pdf
- https://www.tessilgiada.it/wp-content/plugins/formcraft/file-upload/server/content/files/160cfbad4cea37---natawuxenikurerali.pdf
- http://pnmanagementsolutions.in/uploads/45933916774.pdf
- http://www.miamiairportlimo.net/wp-content/plugins/formcraft/file-upload/server/content/files/160a096a0f3a3d---14992151231.pdf
- http://mattstergamer.com/wp-content/plugins/super-forms/uploads/php/files/o9rhdbdkhju2tu9ondg9mfhu5u/voduwizexigulurowav.pdf
- https://levin-dent.ru/wp-content/plugins/super-forms/uploads/php/files/e8288b1fa447932f12a0c3c4d06c4393/14492312143.pdf
- https://maspacientes.es/wp-content/plugins/super-forms/uploads/php/files/vjln9cspu1tub3ee5n7uuf2an1/gafaxomujeguzuwenegobej.pdf
- https://ehlibeytalimleri.com/resimler/files/zagazobemuwagupofafevide.pdf
- http://anvlaw.com/userfiles/file/63700032979.pdf
- http://extracam.es/app/webroot/arxius/file/buvapano.pdf
- https://vdbergelectro.nl/wp-content/plugins/super-forms/uploads/php/files/91580ea64eef03ad99e1b5b6b5324824/75813299574.pdf
- https://evg-prague.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1607bee0727b4c---26520774615.pdf
- https://carlojans.com/cms/file/solidasagosozizexujevijom.pdf
- https://terravistahometeam.com/wp-content/plugins/super-forms/uploads/php/files/93982f93a449293b58bc7c88a6df8870/sojenejajusejiwu.pdf
- https://medok18.ru/wp-content/plugins/super-forms/uploads/php/files/fdd93c5e87ec1134929cd334b64bfcfd/sajovopoxifevo.pdf
- http://cameragiaminh.com/upload/files/forukina.pdf
- https://vasutaszeneiskola.hu/ckfinder/userfiles/files/53247359116.pdf
- https://www.grandiosa.is/wp-content/plugins/super-forms/uploads/php/files/fehlig42arti7ir99gmdk30824/83145790581.pdf
- http://bsbcarpet.com/userfiles/file/78861085810.pdf
- http://jenan.com/ckfinder/userfiles/files/powajomuwafikeb.pdf
Embedded domains
- feedproxy.google.com
- kennyre.com
- www.bouwenaaneensterkwerkgeversmerk.nl
- fundacionecla.org
- lion-trading.co.uk
- nazragame.com
- www.tessilgiada.it
- pnmanagementsolutions.in
- www.miamiairportlimo.net
- mattstergamer.com
- levin-dent.ru
- maspacientes.es
- ehlibeytalimleri.com
- anvlaw.com
- extracam.es
- vdbergelectro.nl
- evg-prague.fr
- carlojans.com
- terravistahometeam.com
- medok18.ru
- cameragiaminh.com
- bsbcarpet.com
- jenan.com
- bsl-trans.ru
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report