MALICIOUS — rujugalopuzi.pdf
MALICIOUS — rujugalopuzi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
757a03d6519b5727f35cfa68b8b90b6c3f63adce0832c7a8b364a1de1da611c9 - SHA-1:
05ca108d1b999136ef06de8d0e8ba2d3b247a7b7 - MD5:
208aeaeefd4c0e16c545c0372caea1bf - ssdeep:
1536:HpSYmJw8qOZZlqnSsc3eF29KlXTHCZ3kXr5/BHirWwpOS9WF0CHTGsvYD8m:cNNJnWSz3ec9KlA29/hiOShvsvs - TLSH:
T1B53AD1F7619BDE5C7A5B5B03B9BA0158A546D78930B1C3A0408D7A3CC6BC5BEBF00911 - Submitted as: rujugalopuzi.pdf
- File type: pdf · Size: 96029 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://wastran.ru/uplcv?utm_term=caption+for+friends, http://casaperferiesantamariagoretti.com/writable/public/userfiles/file/49099165152.pdf, https://honghow.com/ckfinder/userfiles/files/vonezow.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://wastran.ru/uplcv?utm_term=caption+for+friends
- http://casaperferiesantamariagoretti.com/writable/public/userfiles/file/49099165152.pdf
- https://honghow.com/ckfinder/userfiles/files/vonezow.pdf
- http://mijneigenlift.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16126ae83c239a---31048292719.pdf
- https://comobrew.com/newsite/images/user_uploads/file/88598285461.pdf
- http://aleeblog.com/wp-content/plugins/super-forms/uploads/php/files/p0vrenbq2a87n5peqnets09ta1/39424158807.pdf
- http://deeringbayrealestate.com/userfiles/files/38536513498.pdf
- http://traiteur-ribot.fr/userfiles/file/41667595577.pdf
- https://www.alpha-dynamics.gr/wp-content/plugins/formcraft/file-upload/server/content/files/1608bbc289845f---33355268928.pdf
- http://lichnyiybrand.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160a3825a98da7---80310651434.pdf
- http://aranykoronakft.hu/userfiles/file/8144073705.pdf
- https://daulte.ch/ckfinder/userfiles/files/malab.pdf
- http://www.lavalledesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a366a122de7---81924536310.pdf
- http://guinyardfamilyreunion.com/clients/62985/File/7607424335.pdf
- http://domingo.hu/ckfinder/userfiles/files/58397868782.pdf
- http://mko-yug.ru/wp-content/plugins/super-forms/uploads/php/files/81d9e92bfde7a7c13cbac47f9bdceff4/67586903281.pdf
- https://etadelloro.it/images/file/lawutudom.pdf
- http://yenidenyuzlendirme.com/ckfinder/userfiles/files/lukokemodudasem.pdf
- http://chatyzvule.cz/uploads/14522920865.pdf
- https://alismobile.co.uk/wp-content/plugins/super-forms/uploads/php/files/1873839080341c5ef7b9e51134d52c87/62424744907.pdf
- https://www.explosivo.gr/wp-content/plugins/super-forms/uploads/php/files/0c0453ba70af39ad9d1a37a2b5643d7b/22670044556.pdf
- http://artmetinc.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c22d6b3fa86---86677035815.pdf
- http://julieesteban.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609652899137e---verobijek.pdf
- https://zilalcooling.com/other_files/File/65581066080.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- wastran.ru
- casaperferiesantamariagoretti.com
- honghow.com
- mijneigenlift.nl
- comobrew.com
- aleeblog.com
- deeringbayrealestate.com
- traiteur-ribot.fr
- lichnyiybrand.ru
- daulte.ch
- www.lavalledesign.com
- guinyardfamilyreunion.com
- mko-yug.ru
- etadelloro.it
- yenidenyuzlendirme.com
- alismobile.co.uk
- artmetinc.com
- julieesteban.com
- zilalcooling.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.alpha-dynamics.gr
- aranykoronakft.hu
- domingo.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report