MALICIOUS — pugojafawipubupizuruju.pdf
MALICIOUS — pugojafawipubupizuruju.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
76833e718d80db4367332d09b131d3adc0537841fe902477b73cbd1130de5a82 - SHA-1:
863f0a9aaccaa467d0b77466aba5360dc3cf3c98 - MD5:
e34e1b5ffd2308d844a646e1935fd96d - ssdeep:
1536:ekssanx50V1U07agbJ5T5fcdFNsWTXo7NwBUGWOpOaZRuuFFhMvko:nsLncseagJ5fIXvXqNwy7aZQ0FhMj - TLSH:
T16D37C0F33057DD9CF64A9B836AEA051D648ED6841232E980418C766CE9FC17EBF04E11 - Submitted as: pugojafawipubupizuruju.pdf
- File type: pdf · Size: 73340 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://kisikana.hr/UserFiles/files/womepepopawetu.pdf, https://motionslam.com/wp-content/plugins/super-forms/uploads/php/files/c1065dda6a0fb6971b7ae1a4e1f6b5fc/waxanibobus.pdf, https://www.americanapi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160aa824e6c0fb---wemedoliporifaguko.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BvfzZFkJO3s/uplcv?utm_term=instructions+on+how+to+make+a+paper+airplane+pdf
- https://kisikana.hr/UserFiles/files/womepepopawetu.pdf
- https://motionslam.com/wp-content/plugins/super-forms/uploads/php/files/c1065dda6a0fb6971b7ae1a4e1f6b5fc/waxanibobus.pdf
- https://www.americanapi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160aa824e6c0fb---wemedoliporifaguko.pdf
- https://carpanea.it/wp-content/plugins/super-forms/uploads/php/files/b01682d5d1f02bb0ac853c783d9d9617/xejomun.pdf
- https://personalloan2u.com/wp-content/plugins/super-forms/uploads/php/files/e792029291d11dd9d60e19610df22830/9790277633.pdf
- https://angkoronetour.com/userfiles/file/pamasukobodusizabu.pdf
- http://oasis-inwaste.asia/files/file/firevegaxojiw.pdf
- https://sarujiovalente.com/wp-content/plugins/super-forms/uploads/php/files/72sgtoa1a34ht7erp282fatvr3/41900030834.pdf
- http://korea-labels.com/ckfinder/userfiles/files/vaxojibememopoma.pdf
- http://bitite.lv/media/txt/122/file/83771538733.pdf
- https://joyfool.art/wp-content/plugins/super-forms/uploads/php/files/fdbbc9b0494180b55d82905bb8848b95/96226334425.pdf
- http://ziepniekkalns.lv/wp-content/plugins/formcraft/file-upload/server/content/files/1609556e134674---24727259956.pdf
- http://arredamenticucinesiciliane.it/userfiles/files/56481821402.pdf
- https://linhngapt.vn/upload/files/19950994161.pdf
- http://broomfield82.com/clients/4/48/489ff1710263d1ca947d92387d56c809/File/jetore.pdf
- http://doktor-okonski.pl/uploadimg/file/noredutosaxosezaxisadaru.pdf
- https://burstallconrad.com/editor_files/file/32128336836.pdf
- https://licorne-hotel-restaurant.com/userfiles/file/55026791818.pdf
- https://daluxerealty.com/wp-content/plugins/super-forms/uploads/php/files/b07jpfojqhuaiedf8e460lud37/duruvigima.pdf
- http://vervesimuhub.com/userfiles/file/nejedegivijaxoputosubovun.pdf
- https://corpusbg.com/files/fck/file/zilepufitaxemewefupinusu.pdf
- http://www.sunarozlem.com.tr/wp-content/plugins/super-forms/uploads/php/files/0db9fn751llapautrbj7rgl5f1/4078992689.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- motionslam.com
- www.americanapi.com
- carpanea.it
- personalloan2u.com
- angkoronetour.com
- oasis-inwaste.asia
- sarujiovalente.com
- korea-labels.com
- arredamenticucinesiciliane.it
- broomfield82.com
- doktor-okonski.pl
- burstallconrad.com
- licorne-hotel-restaurant.com
- daluxerealty.com
- vervesimuhub.com
- corpusbg.com
- www.w3.org
- purl.org
- ns.adobe.com
- kisikana.hr
- bitite.lv
- joyfool.art
- ziepniekkalns.lv
- linhngapt.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report