MALICIOUS — lefuponoxexilokukesawuw.pdf
MALICIOUS — lefuponoxexilokukesawuw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5cafe098ac6184e1fd6b56f723be952287e30bbeaea2e1f8a926c437b700c9e7 - SHA-1:
41527b1358468e0190e5a6de23ea8b6e524b826a - MD5:
58b230c9bfde070daee7a9bbfcbd71ce - ssdeep:
1536:HwXukumywe9KM11tUYVRDN8gk7oc+JgHd2RxD/S05Wxa98v60W8pO+u60sY61e0:YumyweX11tUYVDXkp+JgHd2R8AI6P+uO - TLSH:
T11138CFF761C7CD9C369BAB1365EB11695449E7882162EA9040CCBB3CD0BC5FCBE20952 - Submitted as: lefuponoxexilokukesawuw.pdf
- File type: pdf · Size: 83292 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://chamdure.com/DATA/files/21145167526.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://allytemp.ru/uplcv?utm_term=naruto+moba+games+download, https://reparationmobile.net/userfiles/file/jatumepolelutupewez.pdf, http://vuason.vn/upload/files/sevuzakesodod.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://allytemp.ru/uplcv?utm_term=naruto+moba+games+download
- https://reparationmobile.net/userfiles/file/jatumepolelutupewez.pdf
- http://vuason.vn/upload/files/sevuzakesodod.pdf
- https://yourdentist.ro/app/webroot/files/userfiles/files/novebajovelululivowatet.pdf
- https://salvamontbihor.ro/app/webroot/files/userfiles/files/88885053293.pdf
- http://filipdegreef.be/uploads/files/96025766817.pdf
- https://drinkpoint.com/uploads/files/dasirekawi.pdf
- https://ww150005.linebot.net/upfile/files/20210908154910.pdf
- http://club-integra.ru/userfiles/file/vujamiwavinine.pdf
- http://chamdure.com/DATA/files/21145167526.pdf
- https://ehbo-oostkapelle.nl/userfiles/file/jikavenutetodib.pdf
- https://apoc.com.au/wp-content/plugins/super-forms/uploads/php/files/02096be25d29723ab907123cffbb5090/30691663003.pdf
- https://skl.deindrukdemo.nl/upload/files/49294448023.pdf
- http://antwerp-rentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/16140ccce68232---61240153390.pdf
- https://capital-publishing.com/ckfinder/userfiles/files/60263198045.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/161490b2f9b249---gigifivepiziroseb.pdf
- http://eugensa.lt/app/webroot/uploads/userfiles/files/42104176111.pdf
- http://npk-bypassdrr2.com/file_media/file_image/file/kokufodivuvoxipafapeti.pdf
- http://park-seversk.ru/other/js/ckfinder/userfiles/files/202571551.pdf
- http://uni-soar.com/userfiles/file/tevuwalebedugap.pdf
- http://jongauger.com/ckfinder/userfiles/files/pobumidunikaxasepow.pdf
- http://dkkarsin.pl/img/upload/files/sinego.pdf
- https://sharzh-ufa.ru/wp-content/plugins/super-forms/uploads/php/files/89d0bfe3d613270bd38d00fc0f44a748/fezotusumufetikagulij.pdf
- http://chernogolovka.inhome360.ru/admin/ckfinder/userfiles/files/samizunizazaderubiga.pdf
- http://mt-filtration.com/uploaded/file/2143025591613a7b1657417.pdf
Embedded domains
- allytemp.ru
- reparationmobile.net
- filipdegreef.be
- drinkpoint.com
- ww150005.linebot.net
- club-integra.ru
- chamdure.com
- ehbo-oostkapelle.nl
- apoc.com.au
- skl.deindrukdemo.nl
- antwerp-rentals.com
- capital-publishing.com
- www.1000ena.com
- npk-bypassdrr2.com
- park-seversk.ru
- uni-soar.com
- jongauger.com
- dkkarsin.pl
- sharzh-ufa.ru
- chernogolovka.inhome360.ru
- mt-filtration.com
- mamadona.ru
- adidravidar.com
- harpethvalleyhealth.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report