MALICIOUS — vovoguzezix.pdf
MALICIOUS — vovoguzezix.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
63c909260525a144d9a4851c6a4feafff13e9e5c6d03e5bef808d626ef2b3a25 - SHA-1:
e53912cfa62ca263e7ba07fe4bb55f094e5699b4 - MD5:
35b759b27b43e1bf867212b16bdf7bcd - ssdeep:
1536:faYuxGNyg0JSRSSRl+hCC2ypRVkzRjSbCI75iQ3GeerJ:THChR1RS9Qfiq0 - TLSH:
T1AA36BFF7A19BDC8C7D475B43BEBA2128744AD7486676E7580088BAACD47C6FC6D10E00 - Submitted as: vovoguzezix.pdf
- File type: pdf · Size: 66418 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!35B759B27B43
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://famcareconnect.org/wp-content/plugins/formcraft/file-upload/server/content/files/160841562de926---39210679374.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://laborke.ru/uplcv?utm_term=kulwinder+billa+new+song+download+djpunjab, https://jclifeschools.org/wp-content/plugins/super-forms/uploads/php/files/ff43c9e6a738b5d286bf1ed2cee84fc5/87494364274.pdf, https://www.caesarstravel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b658d35125e---legufuxenojixafiku.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://laborke.ru/uplcv?utm_term=kulwinder+billa+new+song+download+djpunjab
- https://jclifeschools.org/wp-content/plugins/super-forms/uploads/php/files/ff43c9e6a738b5d286bf1ed2cee84fc5/87494364274.pdf
- https://www.caesarstravel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b658d35125e---legufuxenojixafiku.pdf
- http://famcareconnect.org/wp-content/plugins/formcraft/file-upload/server/content/files/160841562de926---39210679374.pdf
- https://deedpoll.sg/wp-content/plugins/super-forms/uploads/php/files/79ec5d6506f3a56416d0c6ae437a08e9/pixiwir.pdf
- https://infravoip.com/wp-content/plugins/super-forms/uploads/php/files/23ba54a1dd11823b435bca3b138b030c/wugujegisakekopavasuse.pdf
- http://jockmurray.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608e4448bdfac---51447517858.pdf
- https://cms.blauraum.com/wp-content/plugins/super-forms/uploads/php/files/a3d89e0c2c69f942852e95f64e7daffa/pajawakegegora.pdf
- https://pinotcar.com/wp-content/plugins/super-forms/uploads/php/files/a29613d6115543ec7b866556d7e88a6e/dunubatuxo.pdf
- http://cateringkieuan.com/uploads/userfiles/file/fuvinagewilanabegudit.pdf
- https://wavemed.it/wp-content/plugins/super-forms/uploads/php/files/231ad25d124016d4ca0792a5ec62927c/pifubinumodifurokugexo.pdf
- https://pypconsultores.mx/userfiles/file/97750686162.pdf
- http://ats-dz.com/userfiles/file/62002267523.pdf
- https://mebelpozakazu.ru/wp-content/plugins/super-forms/uploads/php/files/9aa5a050ab986db6686626acb4732fe3/53424241960.pdf
- https://ddriu.hu/wp-content/plugins/super-forms/uploads/php/files/b88cda91feca36f50a977618528bcab8/puvadofed.pdf
- https://ascinfratech.com/clientprojects/trading/file/84161545263.pdf
- http://beloezoloto.ru/userfiles/file/53572708464.pdf
- https://agrotehholding.ru/wp-content/plugins/super-forms/uploads/php/files/5d863ec6f5d498786e88324df45431ec/97107139678.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- laborke.ru
- jclifeschools.org
- www.caesarstravel.com
- famcareconnect.org
- deedpoll.sg
- infravoip.com
- jockmurray.com
- cms.blauraum.com
- pinotcar.com
- cateringkieuan.com
- wavemed.it
- pypconsultores.mx
- ats-dz.com
- mebelpozakazu.ru
- ascinfratech.com
- beloezoloto.ru
- agrotehholding.ru
- www.w3.org
- purl.org
- ns.adobe.com
- ddriu.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report