MALICIOUS — mumedazujizula.pdf
MALICIOUS — mumedazujizula.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5054c1e4b4d9f4d8ef07618a23fa678e56f6407678ce53c8019bc6cb2e38a7cf - SHA-1:
f17d673ed6be4caacd2e6246d09001343074062c - MD5:
f1b5a9b46057101c2b99ffaf662871fd - ssdeep:
1536:7qTKBbHpxt2Aj4QqnDrheBgpF7z0RreGW6pOu26WuVi1v9/Goao0df:2cbJKNQqnDUgpFERSDu24Vi19/GHl - TLSH:
T13937C0F361DBED4C7B8B9B4324BA116A7046D3896522EF900188BA7CC9BC5BE7F00551 - Submitted as: mumedazujizula.pdf
- File type: pdf · Size: 75907 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://prplus4u.com/ckupload/files/25720068392.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://gpszone.hu/upload/userfiles/file/tobowixeda.pdf, https://www.drserapkagan.com/wp-content/plugins/super-forms/uploads/php/files/dim7o7nfql6voi5umlk7ashgd3/dewizikunodujesal.pdf, http://prplus4u.com/ckupload/files/25720068392.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/ngfLrbzwjls/uplcv?utm_term=best+movies+torrent+magnet
- http://gpszone.hu/upload/userfiles/file/tobowixeda.pdf
- https://www.drserapkagan.com/wp-content/plugins/super-forms/uploads/php/files/dim7o7nfql6voi5umlk7ashgd3/dewizikunodujesal.pdf
- http://prplus4u.com/ckupload/files/25720068392.pdf
- http://balcimimarlik.com/resimler/files/68912659687.pdf
- http://ajitcoatings.com/uploads/51416479451.pdf
- http://agapetown.net/ckfinder/userfiles/files/dimar.pdf
- http://chiangmai-esc.net/user_img/files/xojod.pdf
- http://altronic.pl/!mag2011/userfiles/file/96328497105.pdf
- https://www.abandassociates.com/ckfinder/userfiles/files/tulemozobovulosaw.pdf
- http://cascinamana.it/userfiles/file/34545911016.pdf
- http://tieuhocsondong.hoaiduc.edu.vn/ckfinder/userfiles/files/desewakazigexud.pdf
- https://10kshot.com/customerinterview/ckfinder/userfiles/files/punibofixofib.pdf
- http://mamtaniketan.com/userfiles/file/83490088238.pdf
- http://www.goataxiservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613e18c925622---senijilegirozizegumabuwe.pdf
- http://www.liveartsaskatchewan.com/wp-content/plugins/formcraft/file-upload/server/content/files/16140ca84af624---wipudato.pdf
- http://kaplanpm.com/wp-content/plugins/formcraft/file-upload/server/content/files/16131b44669585---10627572400.pdf
- http://corse.annuaire-regional.com/ckfinder/userfiles/files/48437755905.pdf
- http://resurrection-life.net/userfiles/files/kuwesolesaden.pdf
- http://gennarimaq.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16130fadb816e1---40956205896.pdf
- https://christianbelieversmatrimony.com/web/christiansbelieversmatrimony/photos/ckeditor/files/punilototite.pdf
- http://www.verneteco.com/ckfinder/userfiles/files/kodunimov.pdf
- http://studiotecnicobonoli.com/userfiles/files/dibafemuxe.pdf
- https://flylights.pl/wp-content/plugins/super-forms/uploads/php/files/0jaln1fomom2ajmkh2tt793kvh/81256204679.pdf
- http://pck.malopolska.pl/wp-content/plugins/super-forms/uploads/php/files/79d52cb8923ea2e9a570f31320ab81e5/73276891124.pdf
Embedded domains
- feedproxy.google.com
- www.drserapkagan.com
- prplus4u.com
- balcimimarlik.com
- ajitcoatings.com
- agapetown.net
- chiangmai-esc.net
- altronic.pl
- www.abandassociates.com
- cascinamana.it
- 10kshot.com
- mamtaniketan.com
- www.goataxiservice.com
- www.liveartsaskatchewan.com
- kaplanpm.com
- corse.annuaire-regional.com
- resurrection-life.net
- gennarimaq.com.br
- christianbelieversmatrimony.com
- www.verneteco.com
- studiotecnicobonoli.com
- flylights.pl
- pck.malopolska.pl
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report