SUSPICIOUS — wurosukimuwurolovak.pdf
SUSPICIOUS — wurosukimuwurolovak.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
5ab33f0aab1dc1f88988d911e5a8f58499cc9bb59ba4269a8a7bce4d6063aa01 - SHA-1:
81b46ce9749c35aa3065c2265874758443dfd315 - MD5:
be84fbecd822e1822a54f89318cdee73 - ssdeep:
1536:rTYKgQ7z7f3O/F4/WUhaSsR3SUOzYfyga2Zf7EyldrtlPVrFMI:IKg63f3Ot1UhDsQwZZB4yj5rF - TLSH:
T10139D0F32297DC9C77879F5358EA256E604DDB8831628A640084B75CC8BC7BE3E24E51 - Submitted as: wurosukimuwurolovak.pdf
- File type: pdf · Size: 88749 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!BE84FBECD822
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=lookup+a+license+plate+owner+in+ontario, https://gfow.om/wp-content/plugins/super-forms/uploads/php/files/l8la8u1rhupbt3af4lakkhvc3v/17991001223.pdf, http://es-umzuege-transporte.de/wp-content/plugins/super-forms/uploads/php/files/82569dbaec4eee8aeca1f7269f08abc2/wexedisudobopalakude.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=lookup+a+license+plate+owner+in+ontario
- https://gfow.om/wp-content/plugins/super-forms/uploads/php/files/l8la8u1rhupbt3af4lakkhvc3v/17991001223.pdf
- http://es-umzuege-transporte.de/wp-content/plugins/super-forms/uploads/php/files/82569dbaec4eee8aeca1f7269f08abc2/wexedisudobopalakude.pdf
- https://hoovermaids.com/wp-content/plugins/super-forms/uploads/php/files/0a87c206af77946b0ec833712a79fcee/37636252816.pdf
- http://tort-art.ru/userfiles/file/36300145734.pdf
- http://aelma.com/sites/default/userfiles/file/rezakigezutukobimegada.pdf
- http://www.kreasoft.mx/wp-content/plugins/formcraft/file-upload/server/content/files/160a573e12ebd3---pafiwusarokeperunipipow.pdf
- http://tlxzkj.com/uploads/file/161645026899.pdf
- https://makemycake.gr/wp-content/plugins/super-forms/uploads/php/files/a4mmh29olj8pbrongc5rktfmnr/32009952819.pdf
- http://philippinesroadshow.com/wp-content/plugins/super-forms/uploads/php/files/2af9a948ae28530e61d63937ab618503/nesinufodoxediluxubaleb.pdf
- https://nscs.org/wp-content/plugins/super-forms/uploads/php/files/910d242925922c53298f980a4468aceb/lewamibu.pdf
- https://doitsolutions.co/wp-content/plugins/super-forms/uploads/php/files/0799f8ce1fa33be53b4cd7d7d6125a8e/4374599360.pdf
- http://www.iqubz.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607f864cdea4b---dinejisawuroxisekifirizi.pdf
- https://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/16075d0183fd82---56976588058.pdf
- https://fablab808.com/nbloom/fckuploads/file/sogajufilir.pdf
- http://www.onekaddy.com/wp-content/plugins/formcraft/file-upload/server/content/files/16093ccdb166ea---93654739550.pdf
- http://adoriantarla.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1609ab2c6ae871---95301375318.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- huntic.ru
- es-umzuege-transporte.de
- hoovermaids.com
- tort-art.ru
- aelma.com
- www.kreasoft.mx
- tlxzkj.com
- philippinesroadshow.com
- nscs.org
- doitsolutions.co
- www.iqubz.com
- klingende-zeder.de
- fablab808.com
- www.onekaddy.com
- www.w3.org
- purl.org
- ns.adobe.com
- gfow.om
- makemycake.gr
- adoriantarla.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report