MALICIOUS — vowalaxin.pdf
MALICIOUS — vowalaxin.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6c2091a07a39deaff8b2bf963401257c21d26e4a003b6810416e9c5afbf2656b - SHA-1:
8ae500b9ff24eb91916d6af87adb60fb261618ce - MD5:
bb242bbc95a8b5cef2fe07fe8b2bbebb - ssdeep:
6144:nUOU8PmvIq07KugLxAvdNRxUJbsKDgLVI+k3V+jLPXNc0kX:UOnPmQ7uLxAlzS2KDgLmz+3VuX - TLSH:
T1254512F7227FCE8876CD6B03A8F6505D1585CB8C50319B5285CDBB1C9A6C4FE78A4A20 - Submitted as: vowalaxin.pdf
- File type: pdf · Size: 268260 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://cameragiaminh.com/upload/files/ramitoforuzapa.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://nomylo.ru/uplcv?utm_term=comprehension+questions+pdf, http://zkojicin.cz/userfiles/file/74556919562.pdf, https://52fantasies.com/home/holly/public_html/ckfinder/userfiles/files/26969143104.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nomylo.ru/uplcv?utm_term=comprehension+questions+pdf
- http://zkojicin.cz/userfiles/file/74556919562.pdf
- https://52fantasies.com/home/holly/public_html/ckfinder/userfiles/files/26969143104.pdf
- http://snnet.kr/board_pds/fckeditor/2021/09/file/31321147014.pdf
- http://cameragiaminh.com/upload/files/ramitoforuzapa.pdf
- http://www.melodypods.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614aece9e8cce---69172739482.pdf
- https://www.phoenixdentalacademy.co.uk/wp-content/plugins/super-forms/uploads/php/files/5e1cc9f075f2b0875b3c6299be0f7cec/sunidesogilopoba.pdf
- http://malir-naterac.info/UserFiles/File/45876292451.pdf
- https://comesa.com.pe/wp-content/plugins/super-forms/uploads/php/files/fe42a890deceaf9fd0969682660c5917/23461479855.pdf
- http://nhasachconggiao.com/luutru/files/pufagexesumusesixezu.pdf
- http://antik-cafe-bergen.de/wp-content/plugins/formcraft/file-upload/server/content/files/161321a7946371---mitojiruvimabu.pdf
- https://nirkongrp.com/ckfinder/userfiles/files/71623682229.pdf
- http://informerfitness.com/wp-content/plugins/super-forms/uploads/php/files/f3c06d308639fe74aadfd876dbe86f04/vujulibefefejigegipoz.pdf
- http://tutaylamhet.com/storage/ckfinder/files/tilibixofi.pdf
- http://logo4you.dk/userfiles/file/wefolekojesedomabakaduboj.pdf
- https://global-product.org/CKEdit/upload/files/gogig.pdf
- http://zzps.pl/userfiles/file/82707869210.pdf
- https://valkexclusief.reviewz.eu/app/webroot/files/userfiles/files/46705899673.pdf
- https://auf.vn/wp-content/plugins/super-forms/uploads/php/files/g1fvjj3len2ofc4coiqvsibuc2/40814201005.pdf
- https://www.web2business.pt/wp-content/plugins/formcraft/file-upload/server/content/files/1613eec38de2e3---goxiwiv.pdf
- http://www.nachtruhe.info/up/files/koneseruwinufepukukoz.pdf
- http://186086.com/upload/files/ruzamaxivenalofupejinex.pdf
- https://heureka-cz.eu/files/49443523502.pdf
- https://snowcat.pl/admin/ckfinder/userfiles/files/71103348243.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- nomylo.ru
- 52fantasies.com
- snnet.kr
- cameragiaminh.com
- www.melodypods.com
- www.phoenixdentalacademy.co.uk
- malir-naterac.info
- nhasachconggiao.com
- antik-cafe-bergen.de
- nirkongrp.com
- informerfitness.com
- tutaylamhet.com
- global-product.org
- zzps.pl
- valkexclusief.reviewz.eu
- www.nachtruhe.info
- 186086.com
- heureka-cz.eu
- snowcat.pl
- www.w3.org
- purl.org
- ns.adobe.com
- zkojicin.cz
- comesa.com.pe
- logo4you.dk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report