MALICIOUS — vuguwewiv.pdf
MALICIOUS — vuguwewiv.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7c0af553c36b2185a6a83f30b95c01bb10c0bb540c4787a8bcb38211cae98b5d - SHA-1:
004a2044221b9747e545c8f4ba182d96691eb97f - MD5:
660d240c9affc6839cb0509878dc80d0 - ssdeep:
3072:9aEouhTgVaoTQQU8yW2MLwoFuD0+O97+tJWWBrQZnuz:AENwT0W2mwoFuD0lwt0Y - TLSH:
T15A3EE1F3239BCC5CB6879F635D96116D304BC3593127E6484484B95DE1B8AEEBF20241 - Submitted as: vuguwewiv.pdf
- File type: pdf · Size: 141986 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://www.icodar.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e9fe2d7ebd---56548271392.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://vilaportugal.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f0e7192b29---95715585910.pdf, https://glosunspa.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608522a706b7a---memitefu.pdf, https://marksiegeldds.com/wp-content/plugins/super-forms/uploads/php/files/2dc5d6ae4bee689e0096e5cbc059a0c3/fazilonaseg.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/A3Ryygt5BCM/uplcv?utm_term=nh%25E1%25BB%25AFng+m%25E1%25BA%25ABu+cv+%25C4%2591%25E1%25BA%25B9p
- http://vilaportugal.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f0e7192b29---95715585910.pdf
- https://glosunspa.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608522a706b7a---memitefu.pdf
- https://marksiegeldds.com/wp-content/plugins/super-forms/uploads/php/files/2dc5d6ae4bee689e0096e5cbc059a0c3/fazilonaseg.pdf
- https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607f3b5d01814---94972224627.pdf
- https://www.hit-education.com/wp-content/plugins/super-forms/uploads/php/files/fcrlqp46cb5e92e088siubuv4g/52088028364.pdf
- http://www.icodar.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e9fe2d7ebd---56548271392.pdf
- https://sk-developers.com/wp-content/plugins/formcraft/file-upload/server/content/files/160731659f1a1a---migewagesilavoxuwenene.pdf
- https://www.web2business.pt/wp-content/plugins/formcraft/file-upload/server/content/files/1608366405ac43---83389908470.pdf
- https://intelean.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074978f7b225---24768700705.pdf
- https://californiaoptionsrealestate.com/wp-content/plugins/super-forms/uploads/php/files/a5a9826c8fbaf803ff5ec0a3dcc8ee95/32673192718.pdf
- https://fablab808.com/nbloom/fckuploads/file/95510281712.pdf
- http://a-range.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1607b7d85e8d1e---83068836665.pdf
- https://ecobox.eng.br/wp-content/plugins/super-forms/uploads/php/files/f9n7j1p959kt14dcnj5isblihd/26186035117.pdf
- https://www.aceitedeoliva.com/wp-content/plugins/super-forms/uploads/php/files/290bf9531079d0da16682494da7001ea/kutiwopajixi.pdf
- https://www.infratechgroep.nl/wp-content/plugins/super-forms/uploads/php/files/3446787d2982a3939b4482549293f699/jijumiwesariseti.pdf
- http://iamsoldierfit.com/wp-content/plugins/formcraft/file-upload/server/content/files/16072e809889eb---83948150665.pdf
- https://amatnieks.com/pictures/image/dadamu.pdf
- http://intechsol.kz/wp-content/plugins/formcraft/file-upload/server/content/files/160808911bf210---48015163858.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- vilaportugal.com
- glosunspa.com
- marksiegeldds.com
- nam.it
- www.hit-education.com
- www.icodar.com
- sk-developers.com
- intelean.com
- californiaoptionsrealestate.com
- fablab808.com
- a-range.ru
- ecobox.eng.br
- www.aceitedeoliva.com
- www.infratechgroep.nl
- iamsoldierfit.com
- amatnieks.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.web2business.pt
- intechsol.kz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report