MALICIOUS — lugufejoderepemuwi.pdf
MALICIOUS — lugufejoderepemuwi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6b880d0ae82ddc1049b56888bbc35a9dd5fe26d82ede2d55ef12a88b59c4543e - SHA-1:
be3dba2a479054f53fc1ff4ec292ca4b798ea2e7 - MD5:
2d9e18049b038b573a1b83a3cee427a8 - ssdeep:
1536:Pk4g0rnsSxkFzHQ1r59VCJObvYyCy+lLW6pOu2lWJncY/mwWHqWlsyD1ELz:84ZrsNFzydC4bQu+mu28c4owyxg - TLSH:
T13639D0F361EBDC5C779B8F8375A6119CB08AD7886132996040C8BA7C84BC67EBF00651 - Submitted as: lugufejoderepemuwi.pdf
- File type: pdf · Size: 86570 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://www.webhisto.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160a27b2698fc9---nulilaveruluzuzako.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://fermuar.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607fc83dc0880---49907488617.pdf, http://www.suffaheducation.com/wp-content/plugins/formcraft/file-upload/server/content/files/160968a09817b4---8276668587.pdf, http://iehyun.com/editorupload/file/70727707866.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/YTWXjIUwRh0/uplcv?utm_term=what+times+what+is+115
- https://fermuar.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607fc83dc0880---49907488617.pdf
- http://www.suffaheducation.com/wp-content/plugins/formcraft/file-upload/server/content/files/160968a09817b4---8276668587.pdf
- http://iehyun.com/editorupload/file/70727707866.pdf
- https://www.ideakliniksisli.com/wp-content/plugins/formcraft/file-upload/server/content/files/160de62232b5a6---56980356800.pdf
- http://mijneigenlift.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1608a3259c7475---zitefuxeki.pdf
- http://charivne.info/images/file/99574119608.pdf
- https://pinpointfeedtech.com/ckfinder/userfiles/files/nawobutufo.pdf
- https://www.webhisto.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160a27b2698fc9---nulilaveruluzuzako.pdf
- http://jjkxmy.com/upload/files/202108051432204661.pdf
- http://www.opencalgary.org/wp-content/plugins/formcraft/file-upload/server/content/files/160710e4d4c14a---tepewoxikemipojete.pdf
- http://catherine-massage.com/ckfinder/userfiles/files/97516031441.pdf
- http://frederickfollows.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160c73bfd2d662---pitupaxitipirivugefijoz.pdf
- http://launensia.cz/ckfinder/userfiles/files/27060147131.pdf
- http://brunsfamilyreunion.org/clients/e/e7/e70b0594429ddd28dfd4dd2f61c76e80/File/tixujonafagor.pdf
- http://vilaportugal.com/wp-content/plugins/formcraft/file-upload/server/content/files/16093da83ef4eb---nelegajunafanumimu.pdf
- https://www.hungarianassociation.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a8db8f1fbbb---83693507810.pdf
- https://daleel.global/wp-content/plugins/super-forms/uploads/php/files/2c2o7otns3k3mpngqimuot66er/46869759510.pdf
- https://daleel.global/wp-content/plugins/super-forms/uploads/php/files/ngef5dupk5is9a4p4k58ov2sl5/wapobizifusedarajojum.pdf
- http://elitvorota.ru/f/file/zenurafijijire.pdf
- https://www.alongsideasia.com/wp-content/plugins/super-forms/uploads/php/files/d11f47a670e4e16218844a10f9b1cccb/20276161240.pdf
- http://billsky.ee/files/file/tonilibulidanubafa.pdf
- http://www.playerclub.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160ce9a2e44aa9---4636526825.pdf
- https://forumhrdbekasi.com/webroot/userfiles/files/sirabikodewomokuponumo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- fermuar.com
- www.suffaheducation.com
- iehyun.com
- www.ideakliniksisli.com
- mijneigenlift.nl
- charivne.info
- pinpointfeedtech.com
- jjkxmy.com
- www.opencalgary.org
- catherine-massage.com
- frederickfollows.co.uk
- brunsfamilyreunion.org
- vilaportugal.com
- www.hungarianassociation.com
- elitvorota.ru
- www.alongsideasia.com
- forumhrdbekasi.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.webhisto.com.tr
- launensia.cz
- daleel.global
- billsky.ee
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report