MALICIOUS — lunumazuwefer.pdf
MALICIOUS — lunumazuwefer.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9cdf495258098f4a0b7e5be4833d14d5fef56c9b1ac5014cc0f60356ef9d2ca6 - SHA-1:
4e020c17d289b3acb2764f6c29a018867a1217f3 - MD5:
e76d9f21907f0fddcf9ff9c0c76ca9df - ssdeep:
1536:ARVIxCcrxDixW7kWsD1CZ3ixaXkEqoweP4vtlWmJ/vWApO6DF6:EVIxCfW7kjDswxykEqowqKtHO6A - TLSH:
T1F537CFF32097DC8C3B979B0379AA1588B019D7986162DB90408CBB6CC5BC67DFF14652 - Submitted as: lunumazuwefer.pdf
- File type: pdf · Size: 72177 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://www.carnesvarejo.com.br/assets/ckfinder/core/connector/php/uploads/files/taredawijapobim.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://softtox.com/new/userfiles/file/47335961480.pdf, http://boschvietnam.com/files/usersfiles/files/musarepofevejo.pdf, https://vietnam-pump.com/userfiles/file/pixupoza.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/GLLx1DTH0VQ/uplcv?utm_term=face+makeup+camera+beauty+makeover+photo+editor
- http://softtox.com/new/userfiles/file/47335961480.pdf
- http://boschvietnam.com/files/usersfiles/files/musarepofevejo.pdf
- https://vietnam-pump.com/userfiles/file/pixupoza.pdf
- https://www.carnesvarejo.com.br/assets/ckfinder/core/connector/php/uploads/files/taredawijapobim.pdf
- https://plantbiochem.com/ckfinder/userfiles/files/9015910035.pdf
- http://4998horo.gmmwireless.com/contents/files/vesizokoxetufomagojeg.pdf
- http://tantos.jp/js/upload/files/49007819445.pdf
- http://gptools.net/userfiles/file/gubefufeli.pdf
- http://billagelaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/91868973673.pdf
- https://pcparts.fr/ckfinder/userfiles/files/91385091882.pdf
- http://www.psoealora.es/ckfinder/userfiles/files/sakivazeb.pdf
- https://e-room.co/userfiles/file/jomenisagusuxowup.pdf
- http://bantinnhadat.com/users/files/4835553768.pdf
- http://www.sunarpazarlama.com/wp-content/plugins/super-forms/uploads/php/files/os03bqamsseo3i0d8t6s7tk8b5/54004076843.pdf
- http://0048.pl/48files/file/pazajodabe.pdf
- https://prestinireedcorp.com/userfiles/files/fadativosapegora.pdf
- http://jl-vacuum.com/upload/files/93657821417.pdf
- http://computer-rudolstadt.de/upload/file/mikiraliwuxok.pdf
- http://7serve.org/userfiles/file/20210917114144.pdf
- http://streathamtaxi.com/survey/userfiles/files/12415389669.pdf
- https://gulamanis.com/contents/files/kasejulifuzelupuvililu.pdf
- http://petraifevronii.ru/ckfinder/userfiles/files/bisiruvorepafumojaweniwip.pdf
- http://xinshifm.com/userfiles/file/bibasa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- softtox.com
- boschvietnam.com
- vietnam-pump.com
- www.carnesvarejo.com.br
- plantbiochem.com
- 4998horo.gmmwireless.com
- tantos.jp
- gptools.net
- billagelaw.com
- pcparts.fr
- www.psoealora.es
- e-room.co
- bantinnhadat.com
- www.sunarpazarlama.com
- 0048.pl
- prestinireedcorp.com
- jl-vacuum.com
- computer-rudolstadt.de
- 7serve.org
- streathamtaxi.com
- gulamanis.com
- petraifevronii.ru
- xinshifm.com
- www.w3.org
File paths
- S:\)vm
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report