MALICIOUS — vufojos.pdf
MALICIOUS — vufojos.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
692db1ffe45a07c06325ad7821f2cc7fc8afa267e16f1603c6d75397a4a61a6f - SHA-1:
111496ce1e690a4e0d521dce07fa7c25ef660633 - MD5:
7d6ad47fcf96cc549ff094f86a084b04 - ssdeep:
1536:DzTXMtqDxskh7+bbatIihTgYWhBbPrblxoV4UWcpOmBhV:DYq18bwI4ghprblxoV4/mh - TLSH:
T1C639E0F36197ED4C77965B0779EB006C548DE348A121EA908488B77CE9BCABD6F10E01 - Submitted as: vufojos.pdf
- File type: pdf · Size: 86075 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://vrtaspol.cz/klienti/devel/sneznerolby.cz/ckfinder/userfiles/files/19496984430.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://crewmak.ru/uplcv?utm_term=cara+membuat+akun+gmail+baru+dari+hp+android, http://banghetretruc.com/media/ftp/file/22458039699.pdf, https://togeltop.net/contents/files/lefefelurife.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://crewmak.ru/uplcv?utm_term=cara+membuat+akun+gmail+baru+dari+hp+android
- http://banghetretruc.com/media/ftp/file/22458039699.pdf
- https://togeltop.net/contents/files/lefefelurife.pdf
- http://gaudi.tw/upload/files/sijolaxafotub.pdf
- https://drmiamiconnect.com/wp-content/plugins/super-forms/uploads/php/files/d89632fabd246a6c6a2c5a73d6c067e6/tolotemeni.pdf
- https://lotusmarinevn.com/upload/files/43075961086.pdf
- https://aviseco.ro/userfiles/file/36991963968.pdf
- http://vrtaspol.cz/klienti/devel/sneznerolby.cz/ckfinder/userfiles/files/19496984430.pdf
- https://mintedimages.com/ckfinder/userfiles/files/tepejorokuzavi.pdf
- https://menu2uplus.com/images/file/30328030296.pdf
- http://abwingsde.com/uploads/files/94912256671.pdf
- https://maggievanostrand.com/uploads/media/file/64404493075.pdf
- https://houstoncoinclub.org/FCKeditor/file/xipejogak.pdf
- http://xnucleus.com/members/member_images/files/tazojuvipokubelebafigarul.pdf
- http://pileshoppen.dk/userfiles/file/fujijigubukor.pdf
- http://eko-uklid.com/files/file/12751662102.pdf
- https://habrit.tw/ckfinder/userfiles/files/toloposiniwis.pdf
- https://orderpoet.com/ckfinder/userfiles/files/mepamuzumiwefabaxatexavo.pdf
- http://www.sec-ollivier-associes.fr/www/upload/file/finamutuviwimodub.pdf
- https://ymvii.com/admin/upload/files/wefipetite.pdf
- http://kesherisrael.com/uploadEditor/files/26065270685.pdf
- http://chekeeh.ir/basefile/chekeehir/files/powivum.pdf
- https://hawkseyetravels.com/assets/ckfinder/userfiles/files/48667399464.pdf
- https://paroles-vives.com/ckfinder/userfiles/files/napaw.pdf
- http://silver1979.com/upload/file/baxas.pdf
Embedded domains
- crewmak.ru
- banghetretruc.com
- togeltop.net
- gaudi.tw
- drmiamiconnect.com
- lotusmarinevn.com
- mintedimages.com
- menu2uplus.com
- abwingsde.com
- maggievanostrand.com
- houstoncoinclub.org
- xnucleus.com
- eko-uklid.com
- habrit.tw
- orderpoet.com
- www.sec-ollivier-associes.fr
- ymvii.com
- kesherisrael.com
- chekeeh.ir
- hawkseyetravels.com
- paroles-vives.com
- silver1979.com
- turinhotelcompany.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report