MALICIOUS — kuvewumuwexokefexulevuxoj.pdf
MALICIOUS — kuvewumuwexokefexulevuxoj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7771a6b5a6a5380025d1090f6c40721bc76e8b1497e20d9dd48d9f0701535628 - SHA-1:
64971cc8d733200327bbc496bae7d0d58bb5bd0c - MD5:
ab3656f8860ddfd04d40fa9d09713d51 - ssdeep:
1536:KsKUAwE4XVr0ipYhNIDZt6uN38H23GgiWhGOrLNzrNqxLWQpOCfh0:cUAw950ipldU2WgjGOXNfNqx2CG - TLSH:
T1C637BFF3219BDCDC7A568F479A66012CA48AD78D2273AA6101CC797CD4B8DBD7F10A00 - Submitted as: kuvewumuwexokefexulevuxoj.pdf
- File type: pdf · Size: 72357 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://dongcohonda.com/userfiles/file/11129197229.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://eletroluz-al.com/_IMG/img_internas/file/kusemawusutipasozimif.pdf, http://asea-admin.com/_userfiles/file/20210901163109.pdf, http://helices-evra.com/userfiles/file/tutopopob.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/fzgW7-mxBc0/uplcv?utm_term=download+real+football+for+android+phone
- https://eletroluz-al.com/_IMG/img_internas/file/kusemawusutipasozimif.pdf
- http://asea-admin.com/_userfiles/file/20210901163109.pdf
- http://helices-evra.com/userfiles/file/tutopopob.pdf
- http://houselandia.ru/files/lusavoludukifa.pdf
- https://horizontire.com/userfiles/file/kujebiferoridowagejoleb.pdf
- http://fs-select.com/images/blog/file/11048054632.pdf
- http://officegate.biz/admin/fck_upload/file/80354031665.pdf
- http://wuchem.com/upload/files/69244808471.pdf
- https://zbmbudomont.pl/userfiles/file/76023506248.pdf
- https://dongcohonda.com/userfiles/file/11129197229.pdf
- http://www.feniuniversity.edu.bd/app/webroot/ckfinder/userfiles/files/95013285048.pdf
- https://aldurra.ly/images-editeur/img/file/dosugukaburazaponuseju.pdf
- http://viral-list-machine.com/ckfinder/userfiles/publics/files/gobigujivuginutej.pdf
- http://abwcockeysville.com/uploads/files/13123759519.pdf
- http://donovaly-ubytovanie-safran.sk/web/userfiles/file/44572560334.pdf
- http://likebarcode.com/image/files/20210923_231158.pdf
- https://hoovermaids.com/wp-content/plugins/super-forms/uploads/php/files/47ebd57fc283a2a9b81856dab848d8ff/nudojomozogelo.pdf
- https://takarasushimn.com/userfiles/files/43462951827.pdf
- https://essaidafm.com/uploads/FCK_files/file/safimedurofudi.pdf
- http://nyett.hk/uploads/news/files/25231871863.pdf
- http://bulmarconsult.com/files/pofuriwuvakipan.pdf
- http://speaklifeiamgreatness.com/files/files/6466881513.pdf
- http://kxzyjy.com/CKEdit/upload/files/98316319349.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- eletroluz-al.com
- asea-admin.com
- helices-evra.com
- houselandia.ru
- horizontire.com
- fs-select.com
- officegate.biz
- wuchem.com
- zbmbudomont.pl
- dongcohonda.com
- aldurra.ly
- viral-list-machine.com
- abwcockeysville.com
- likebarcode.com
- hoovermaids.com
- takarasushimn.com
- essaidafm.com
- nyett.hk
- bulmarconsult.com
- speaklifeiamgreatness.com
- kxzyjy.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- Z:\^K
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report