MALICIOUS — volizamibapukolugom.pdf
MALICIOUS — volizamibapukolugom.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
ada2e53879da937bf341f0a65518014bf60f558a811590d170a94fa090e6b480 - SHA-1:
c7d4971c72c54fe3bb7984bfc83a1dea19e247a4 - MD5:
d80351bc2f70dcd8f96850dde32b68fc - ssdeep:
1536:yz/EAGJ0DyXyB+o/pV7p8W3tTj9CqXhgFWGICxWI/6q3Cz1Is/zV:w8fSRB+qtp8WtVqFxwCCJIQV - TLSH:
T1B137E1F7B07BCD5CB8CA9B1325D52468284AE2847172D7AD0088B76DECBC67E7E14411 - Submitted as: volizamibapukolugom.pdf
- File type: pdf · Size: 70260 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D80351BC2F70
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://alismobile.co.uk/wp-content/plugins/super-forms/uploads/php/files/6f0e33bab04d595d0f4db34edc9b29d5/gejixigelavitatudotonoko.pdf, https://www.marbelitesa.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/16086b03577907---62837310935.pdf, https://www.teppiche-waschen-hamburg.de/wp-content/plugins/formcraft/file-upload/server/content/files/16072e95a72d00---13394975114.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/A3Ryygt5BCM/uplcv?utm_term=party+invitation+template+psd+free
- https://alismobile.co.uk/wp-content/plugins/super-forms/uploads/php/files/6f0e33bab04d595d0f4db34edc9b29d5/gejixigelavitatudotonoko.pdf
- https://www.marbelitesa.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/16086b03577907---62837310935.pdf
- https://www.teppiche-waschen-hamburg.de/wp-content/plugins/formcraft/file-upload/server/content/files/16072e95a72d00---13394975114.pdf
- https://wamsconference.com/wp-content/plugins/super-forms/uploads/php/files/f6153d87c2bc06bb268d4d5820b91251/72221184483.pdf
- https://rosemonttherapy.health/wp-content/plugins/super-forms/uploads/php/files/466ofk1fnrcurpvu8urj988v1j/96870915173.pdf
- https://sygimportaciones.com/wp-content/plugins/super-forms/uploads/php/files/ing1bh15l48l2u7gb8su3fc1ug/fufexipekaturalipapaxezop.pdf
- https://bestmiamiturf.com/wp-content/plugins/super-forms/uploads/php/files/bc596831211b3dad04b30c11f83c07d2/96142151118.pdf
- https://www.alignerco.ca/wp-content/plugins/super-forms/uploads/php/files/01b7d8e96587e37be97cfbab4cddc5c8/11477050951.pdf
- https://vetranhtuongmamnon.vn/wp-content/plugins/super-forms/uploads/php/files/jenejlo97i7dsl95diei2otnca/79214604839.pdf
- https://bodwellassociates.com/wp-content/plugins/super-forms/uploads/php/files/05c83a6b8833b186e4d0e50a218d6b82/1326600410.pdf
- http://bellezaeimagen.com.mx/wp-content/plugins/formcraft/file-upload/server/content/files/160860b70004b9---jidarinomoli.pdf
- http://lookupagency.es/wp-content/plugins/formcraft/file-upload/server/content/files/160733406641a8---xafikusu.pdf
- https://christianboudreau.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075e9bc16ac8---wumopawisokuvujitonis.pdf
- https://www.emma-solutions.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607d5dbf06f35---xumepiturulej.pdf
- https://www.federatedlighting.com/wp-content/plugins/super-forms/uploads/php/files/74c5ff538f748f2b6a0e80f067f6ac12/wokibek.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- alismobile.co.uk
- www.marbelitesa.co.za
- www.teppiche-waschen-hamburg.de
- wamsconference.com
- sygimportaciones.com
- bestmiamiturf.com
- www.alignerco.ca
- bodwellassociates.com
- bellezaeimagen.com.mx
- lookupagency.es
- christianboudreau.com
- www.emma-solutions.de
- www.federatedlighting.com
- www.w3.org
- purl.org
- ns.adobe.com
- rosemonttherapy.health
- vetranhtuongmamnon.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report