MALICIOUS — dujezenetanewuwugibi.pdf
MALICIOUS — dujezenetanewuwugibi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a0ebf1a57af7a704ef64f866a25a5e7aaaaa8dbd5ba80101293f65e20d211c36 - SHA-1:
01a5d01eaa5bfa88ead6e52b61a577d022d2b613 - MD5:
e3d4a402482f665f22a24dd4ecc90638 - ssdeep:
1536:J1OlIhpgOR0xTZdShfvEU4V31SgGdAr+pxsz1QEzLyAr3BvM:4IhpTRsovY3rGdAr+py5QKLyOe - TLSH:
T19338C0F31197EE8CA74E6F43AE972AB86488C3C82167DB544044B77DC87C6AD7E10A14 - Submitted as: dujezenetanewuwugibi.pdf
- File type: pdf · Size: 77727 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!E3D4A402482F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://29c5b005-6627-40e3-9da1-9f9d3dbc34dc.filesusr.com/ugd/7ad284_a66f9ded953a4484993508b78d9f49f2.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gimoguvi.ru/wb?keyword=personal%20development%20plan%20example%20nhs, https://29c5b005-6627-40e3-9da1-9f9d3dbc34dc.filesusr.com/ugd/7ad284_a66f9ded953a4484993508b78d9f49f2.pdf?index=true, http://zazonowipudu.66ghz.com/99887233776.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gimoguvi.ru/wb?keyword=personal%20development%20plan%20example%20nhs
- https://29c5b005-6627-40e3-9da1-9f9d3dbc34dc.filesusr.com/ugd/7ad284_a66f9ded953a4484993508b78d9f49f2.pdf?index=true
- http://zazonowipudu.66ghz.com/99887233776.pdf
- https://cdn.sqhk.co/zirimikuj/RW2UXWp/jumpstart_games_steam.pdf
- http://vubixegigag.rf.gd/95609295203.pdf
- http://watenuzigoxabi.rf.gd/neuropsychological_testing_boston_medical_center.pdf
- https://50bf384a-eeac-4f26-a262-e2ba1a5e00ba.filesusr.com/ugd/17159d_31b8d327f00a45458e44800dc94e3e39.pdf?index=true
- https://cdn.sqhk.co/laruxibut/jdjgYbm/estas_tomando_in_english.pdf
- https://cdn.sqhk.co/lilapanorup/Ohiggjc/string_is_wrapped_around_a_uniform_solid_cylinder.pdf
- https://7afcd0b8-98df-42a4-afe0-9544d44c9539.filesusr.com/ugd/74e9cf_eed8067635d94766861c13b4f0eb3fea.pdf?index=true
- https://uploads.strikinglycdn.com/files/16640375-67aa-4da9-9bf8-d39df4b44347/koluxetu.pdf
- https://4abf464d-34d5-4c80-8de5-e64f30e04530.filesusr.com/ugd/8b3eb5_89a91440fc1f4f1c8cf116f7436b3114.pdf?index=true
- https://2e5cbe44-7de3-4e3f-b94c-8a8567814465.filesusr.com/ugd/f96b02_c307a78802894f4e87117183255e7526.pdf?index=true
- https://uploads.strikinglycdn.com/files/e3cab81a-f9ae-4ca0-b499-594602138406/what_child_is_this_chords_am.pdf
- https://uploads.strikinglycdn.com/files/a5809d5a-a861-483d-8997-4730768590eb/how_to_be_good_public_relations.pdf
- https://uploads.strikinglycdn.com/files/ead2684f-ef9b-46fd-9fae-a24e33a11c50/how_to_connect_logitech_mouse_without_receiver.pdf
- https://c6506652-bf5e-4f52-be36-03dbfaede22c.filesusr.com/ugd/f74919_7012d20cc5124f5894154758fa43603d.pdf?index=true
- https://983c8978-ad56-435f-a988-47358aa6040c.filesusr.com/ugd/06a663_6eb36ca8477a45cd88f560907591d408.pdf?index=true
- https://f37c3615-20b0-4e70-b1e7-2acf34113780.filesusr.com/ugd/1e533a_3c4c340c8f564dc8a2b781f0e8f7bf06.pdf?index=true
- https://cdn.sqhk.co/vuveleni/5Bthip3/7965243786.pdf
- https://1f571a09-6495-4108-bd1a-9715deae29b5.filesusr.com/ugd/b0bf26_9ea67a35a70b493e9f5d34b4104baee7.pdf?index=true
- http://demumerip.rf.gd/66863639388.pdf
- https://uploads.strikinglycdn.com/files/123ad1ca-d557-462c-9807-0c45d6c5b11e/five_nights_at_freddys_survival_logbook.pdf
- https://cdn.sqhk.co/xedasuzefer/PqXijst/87928399909.pdf
- https://uploads.strikinglycdn.com/files/31a68515-6698-42c4-9380-323ed40b2fce/juvoduxun.pdf
Embedded domains
- gimoguvi.ru
- 29c5b005-6627-40e3-9da1-9f9d3dbc34dc.filesusr.com
- zazonowipudu.66ghz.com
- cdn.sqhk.co
- 50bf384a-eeac-4f26-a262-e2ba1a5e00ba.filesusr.com
- 7afcd0b8-98df-42a4-afe0-9544d44c9539.filesusr.com
- uploads.strikinglycdn.com
- 4abf464d-34d5-4c80-8de5-e64f30e04530.filesusr.com
- 2e5cbe44-7de3-4e3f-b94c-8a8567814465.filesusr.com
- c6506652-bf5e-4f52-be36-03dbfaede22c.filesusr.com
- 983c8978-ad56-435f-a988-47358aa6040c.filesusr.com
- f37c3615-20b0-4e70-b1e7-2acf34113780.filesusr.com
- 1f571a09-6495-4108-bd1a-9715deae29b5.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- vubixegigag.rf.gd
- watenuzigoxabi.rf.gd
- demumerip.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report