MALICIOUS — wunopamurasutuxer.pdf
MALICIOUS — wunopamurasutuxer.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
68076540bfa38410f5539bce39d1235eff76bac1357ca413759aa4153476b69c - SHA-1:
6961769f6756fb1bb41ffafbebd444a9196aa06c - MD5:
c9da49464e5a18ae79f535cb58deca48 - ssdeep:
1536:XNufFka1JLLlywQqJV0lAxhrGbT7xIK7WUr9XWHhdnXW6pOu2pG8b6R:sFka7EIJKKGbTSK/9Xunsu2M8U - TLSH:
T17E38D0F32097ED5C778F8F436E9F40A96489E7841162EA9040C8B79CA5BC8BD7E10A51 - Submitted as: wunopamurasutuxer.pdf
- File type: pdf · Size: 82248 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://bringem.de/wp-content/plugins/super-forms/uploads/php/files/d7524009b6bf9095d07e99c61cb9a91f/41560902965.pdf, http://bvmnotarissen.nl/app/webroot/files/ckeditor_files/files/44741720054.pdf, http://www.infranetltd.com/wp-content/plugins/formcraft/file-upload/server/content/files/160737beb9c966---butunesawekupedafaxidika.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/3CAf4wW3hvY/uplcv?utm_term=motivational+speech+text+pdf
- https://bringem.de/wp-content/plugins/super-forms/uploads/php/files/d7524009b6bf9095d07e99c61cb9a91f/41560902965.pdf
- http://bvmnotarissen.nl/app/webroot/files/ckeditor_files/files/44741720054.pdf
- http://www.infranetltd.com/wp-content/plugins/formcraft/file-upload/server/content/files/160737beb9c966---butunesawekupedafaxidika.pdf
- http://ansonseatery.com/uploads/files/lijaden.pdf
- https://www.lightingdynamics.com/wp-content/plugins/super-forms/uploads/php/files/9f7c7bf51964013a4cc7718144186315/25598371421.pdf
- http://bhttourist.com/upload/fckimagesfile/68514062689.pdf
- https://tradegateindia.com/userfiles/file/gakusunikatovizoni.pdf
- https://gachbinhduong.com/upload/file/vebikitivikel.pdf
- https://capitalsyndic.com/userfiles/file/36909086173.pdf
- http://dooroc.com/tk/upload/file/95950045431.pdf
- http://www.patriarca-batiment.com/ressource/site-image/files/28314752988.pdf
- http://parkwestresidences.com/wp-content/plugins/formcraft/file-upload/server/content/files/160972e409ae13---semow.pdf
- https://certifiedmoversinc.com/wp-content/plugins/super-forms/uploads/php/files/05be573ce7d035bc80a50938ffa6d8e5/zezawavulemaxa.pdf
- https://unitedcardsolutions.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d8beb6e604a---luditole.pdf
- https://demetraproject.eu/ckfinder/userfiles/files/96591814745.pdf
- http://biurod9.pl/public/userfiles/file/42594115975.pdf
- http://krindustria.com.br/site/wp-content/plugins/formcraft/file-upload/server/content/files/1607c607910439---guxisukinapapi.pdf
- https://alasclub.gr/neuro/ckfinder/userfiles/files/20188592949.pdf
- http://clinicacomciencia.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16071658f40160---53749516227.pdf
- https://controlcert.se/wp-content/plugins/formcraft/file-upload/server/content/files/161129f4ca578d---66508041017.pdf
- https://kovtec.pl/eurostyl/photos/file/10179594692.pdf
- https://www.sir.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160a0d9a5a2070---98995004873.pdf
- http://se-ty.ru/uploads/userfiles/file/16632396278.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- bringem.de
- bvmnotarissen.nl
- www.infranetltd.com
- ansonseatery.com
- www.lightingdynamics.com
- bhttourist.com
- tradegateindia.com
- gachbinhduong.com
- capitalsyndic.com
- dooroc.com
- www.patriarca-batiment.com
- parkwestresidences.com
- certifiedmoversinc.com
- unitedcardsolutions.com
- demetraproject.eu
- biurod9.pl
- krindustria.com.br
- clinicacomciencia.com.br
- controlcert.se
- kovtec.pl
- www.sir.co.uk
- se-ty.ru
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report