MALICIOUS — suwenu.pdf
MALICIOUS — suwenu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
a2af0eeb7e8a4123f3970d2c58a651b6d05292e2c7da97d2a93d06ef5a914858 - SHA-1:
b0a48928aa1bb90cdfa348fa7d11bb2e72a945e2 - MD5:
22206b1098534ffbf5e35c7ee85333a6 - ssdeep:
1536:dkDeNSZFigcMRPOore9GrIcCcuMjnwYx0ifQ1UZWiZ4RHxwMu6EWQpOClaireZCF:mKcZFayP3icuYxZfe0Mu6DClaiiZQ - TLSH:
T1B938D0F3225BDE5C378B8F435CEA0169B58BD3C82122CB5548C4BB6C94B85BE6F50681 - Submitted as: suwenu.pdf
- File type: pdf · Size: 84047 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://g3az.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ca234215268---dukavuwuripoj.pdf, http://flagrant-desir.com/userfiles/file/gukasitamevaxewo.pdf, http://pagyesa.org/userfiles/file/20210724140853.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/S30rS-6n6vg/uplcv?utm_term=kinds+of+sentences+according+to+use+worksheets+grade+5
- https://g3az.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ca234215268---dukavuwuripoj.pdf
- http://flagrant-desir.com/userfiles/file/gukasitamevaxewo.pdf
- http://pagyesa.org/userfiles/file/20210724140853.pdf
- https://amrapalispot.com/userfiles/file/80482097674.pdf
- https://morethancleaningservices.com/wp-content/plugins/super-forms/uploads/php/files/41e19096ac8de10c5d8b175e29c62ebb/govomiloleza.pdf
- http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b79291df6c2---daxuwa.pdf
- https://www.amiunaorchestra.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160825fb005963---gabud.pdf
- https://www.bevillelecomte.ovh/ckfinder/userfiles/files/didedepiroronaviv.pdf
- http://ziepniekkalns.lv/wp-content/plugins/formcraft/file-upload/server/content/files/1611968bd95a0a---47407814595.pdf
- https://fiscalonline.eu/app/webroot/files/userfiles/files/71565677280.pdf
- https://www.karenlovelee.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ca314156b6---45952191879.pdf
- https://luathoanghuy.com/uploads/files/97095536257.pdf
- https://eletroluz-al.com/_IMG/img_internas/file/70389532663.pdf
- https://www.entornopublicitario.com/wp-content/plugins/super-forms/uploads/php/files/761de0edd74058e790466e9b6460b1b7/96548782826.pdf
- http://sazjah.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609fdb91cf2b8---wifiz.pdf
- https://hogozaty.com/ckfinder/userfiles/files/93260040220.pdf
- https://www.rogierstoel.nl/wp-content/plugins/super-forms/uploads/php/files/b6ossetu3bo2bat3e9d4f9ctfg/wafew.pdf
- https://www.rockandroll.blog.br/wp-content/plugins/super-forms/uploads/php/files/v0ues2309cfh5aa88mto05jpaq/bunud.pdf
- https://ises.ca/phpsites/vertical_living/uploads/file/pekamarugobinexopijato.pdf
- https://sdyh.gr/wp-content/plugins/super-forms/uploads/php/files/if9fb2tn4gso68mfuek40jnet6/80322762533.pdf
- http://pokemom2.com/uploads/files/galatajutun.pdf
- http://cs-golfclub.com/ckupload/files/zadabap.pdf
- http://www.myhhsi.com/wp-content/plugins/super-forms/uploads/php/files/296c8a0b7dd50009143ed8fe49464f12/38552348600.pdf
- http://maekuangudomthara.com/ckfinder/userfiles/files/41480678340.pdf
Embedded domains
- feedproxy.google.com
- g3az.com
- flagrant-desir.com
- pagyesa.org
- amrapalispot.com
- morethancleaningservices.com
- hellnocancershow.com
- fiscalonline.eu
- www.karenlovelee.com
- luathoanghuy.com
- eletroluz-al.com
- www.entornopublicitario.com
- sazjah.com
- hogozaty.com
- www.rogierstoel.nl
- www.rockandroll.blog.br
- ises.ca
- pokemom2.com
- cs-golfclub.com
- www.myhhsi.com
- maekuangudomthara.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.amiunaorchestra.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report