MALICIOUS — volupabewomuwu.pdf
MALICIOUS — volupabewomuwu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ab55f559db38571a71ce188c22476e0d293a6ccd8702145ed4c100805305e7d1 - SHA-1:
b8c1b73d93dc87d721736210ec8bec2f1ddecaeb - MD5:
a8258ae79d247eefc9618312745bd750 - ssdeep:
1536:NLFi1rdQ5JRc2QT/OrfgChOH2FWLMAlPmLW8pO7pQY5h9:CRQ5JRvQigChu9PmW7uY5 - TLSH:
T18238BFF361D7DE0CBA4B8F43A8EF51686086D6887122EB904048735DD4BC6BEBF14961 - Submitted as: volupabewomuwu.pdf
- File type: pdf · Size: 77404 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://mtcongnghiepxanh.com/upload/fckimagesfile/53169439122.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://www.helpfulhunks.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1613d7500e53a4---namudosorer.pdf, http://hamishehbaharcarpet.com/My_Project/Hamishe_bahar/ahar_img/files/67687002937.pdf, https://newchat.xyz/js/ckfinder/userfiles/files/melipokazikudolekotunolu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/PmAiG5ZyT-k/uplcv?utm_term=use+a+android+tablet+as+a+second+monitor
- https://www.helpfulhunks.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1613d7500e53a4---namudosorer.pdf
- http://hamishehbaharcarpet.com/My_Project/Hamishe_bahar/ahar_img/files/67687002937.pdf
- https://newchat.xyz/js/ckfinder/userfiles/files/melipokazikudolekotunolu.pdf
- http://www.movingintofreedom.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615236fc2d2bc---68120224483.pdf
- https://markaoyun.com/calisma2/files/uploads/45015609126.pdf
- http://zhengfutz.com/v15/Upload/file/202192748544042.pdf
- http://interwork.sk/userfiles/file/zadosopeniwovotapajubexo.pdf
- https://rabudiagnostic.com/userfiles/files/lomavawanas.pdf
- http://mtcongnghiepxanh.com/upload/fckimagesfile/53169439122.pdf
- http://kanomax-nsk.ru/images/95474886986.pdf
- http://cuacuonnhaxuongbinhduong.com/upload/files/39440340028.pdf
- http://pescepiana.eu/userfiles/files/dugobogum.pdf
- https://ctsgroups.asia/images/file/mamadibovakewija.pdf
- http://saiprogetti.net/userfiles/files/leluravupa.pdf
- http://otoozevran.com/resimler/files/josekazem.pdf
- https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/0c1c4a82690523b7a977a6b1f4d0a569/68969341467.pdf
- http://uat.ideadunes.com/projects/ideadunes-portfolio-site/wp-content/plugins/formcraft/file-upload/server/content/files/16143877867566---dakoxajodozupatik.pdf
- http://www.protectakoteasia.com/ckfinder/userfiles/files/voxikufumeditur.pdf
- http://pkpneu.cz/userfiles/file/fejesemojiwupip.pdf
- https://horizontire.com/userfiles/file/40504129919.pdf
- http://www.stratcareerservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/161523b37a40ba---41193056164.pdf
- http://7m-shop.com/userfiles/file/ruwaweroxuzusuguza.pdf
- https://hglobaltourb2c.com/FileData/ckfinder/files/20210914_BCBA15F0329977C0.pdf
- https://www.ebenisterie-burette.com/ckfinder/userfiles/files/43305118749.pdf
Embedded domains
- feedproxy.google.com
- www.helpfulhunks.com.au
- hamishehbaharcarpet.com
- newchat.xyz
- www.movingintofreedom.com
- markaoyun.com
- zhengfutz.com
- rabudiagnostic.com
- mtcongnghiepxanh.com
- kanomax-nsk.ru
- cuacuonnhaxuongbinhduong.com
- pescepiana.eu
- ctsgroups.asia
- saiprogetti.net
- otoozevran.com
- amezdigital.com
- uat.ideadunes.com
- www.protectakoteasia.com
- horizontire.com
- www.stratcareerservices.com
- 7m-shop.com
- hglobaltourb2c.com
- www.ebenisterie-burette.com
- free-spirit-city.eu
- amadesafar.ir
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report