MALICIOUS — sukenapofuf.pdf
MALICIOUS — sukenapofuf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
b0e1c82516d4761b4eb649f270be9c4fe251e634f1a39c5457d5c5243bf19f8a - SHA-1:
32d93222c495e2813c8b9ed05261c62e7cdf5d3e - MD5:
55c885ef0f60911893bd84ec36a89033 - ssdeep:
3072:3J4akUxDxvSwS8XWCJ5CIUqiWV+Y4kV2ZlBqR8u2SGU5uNPTJ:39d5S8HJAqi5Zl7UuNPd - TLSH:
T1253CE1F310DBDCCC3246DF8369A720ACB489EB852272E7905588B1BCD5BC97DAB10951 - Submitted as: sukenapofuf.pdf
- File type: pdf · Size: 112197 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=last+year+cost+accounting+question+paper, https://puertoestereo.com/wp-content/plugins/super-forms/uploads/php/files/go3gtsirus541tlcvbmhsgtoov/1752835845.pdf, https://mmgrowersg.com/ckfinder/userfiles/files/79702928980.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=last+year+cost+accounting+question+paper
- https://puertoestereo.com/wp-content/plugins/super-forms/uploads/php/files/go3gtsirus541tlcvbmhsgtoov/1752835845.pdf
- https://mmgrowersg.com/ckfinder/userfiles/files/79702928980.pdf
- https://cashofferoregon.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a4708606953---zosutud.pdf
- http://efuegypt.org/userfiles/file/35787052469.pdf
- http://contextuae.com/resimler/files/66552479492.pdf
- https://phoenixknights.co.uk/wp-content/plugins/super-forms/uploads/php/files/320a4d1ac407645cb205b24ad9e41b8d/84318005509.pdf
- http://ttlengenharia.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16081da40a53d2---jazisigugekerimanoxeroli.pdf
- http://labonscafe.com/userfiles/kofeb.pdf
- https://amerismithenterprises.com/wp-content/plugins/super-forms/uploads/php/files/fe8b1bec0d72f653ac86959585bbd647/32969667183.pdf
- http://www.ponderosafestival.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c56f9f34911---75523829248.pdf
- http://bielwod.com/userfiles/file/mevogotinutowe.pdf
- http://xperion.hu/wp-content/plugins/super-forms/uploads/php/files/2ed8300d0404994ad3a8575f7c8e93dc/46538569482.pdf
- http://www.unidacardoso.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608473063688f---sikijigenavunad.pdf
- https://atlasautoglass.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d41defc4b5e---16181930632.pdf
- https://solarconsulting.org/wp-content/plugins/super-forms/uploads/php/files/05e35ea001ff3562b015b40392478109/lexanolupifafimilotev.pdf
- http://nsdadventist.org/FCKData/file/witij.pdf
- https://40parables.com/wp-content/plugins/super-forms/uploads/php/files/67c18951c55307e37db6e37d5d507633/ridava.pdf
- https://abofahed.com/userfiles/file/peligisasoba.pdf
- http://aldobini.it/userfiles/files/47215164415.pdf
- https://www.accidentinjuryalbuquerque.com/wp-content/plugins/super-forms/uploads/php/files/bks0kq57p3h9j8g81tn1doac21/65826209430.pdf
- https://www.alertgy.com/wp-content/plugins/super-forms/uploads/php/files/1daafba9dedaaa9253d2ba10178d3959/90051374706.pdf
- https://avenirpourtous.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1607479f2eda34---zupaxizenoguxufukuzisat.pdf
- https://unique.global/wp-content/plugins/super-forms/uploads/php/files/fe6654397ad5b33bd12b6867440e4c9f/jexotiwenojisata.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- crysiq.ru
- puertoestereo.com
- mmgrowersg.com
- cashofferoregon.com
- efuegypt.org
- contextuae.com
- phoenixknights.co.uk
- ttlengenharia.com.br
- labonscafe.com
- amerismithenterprises.com
- www.ponderosafestival.com
- bielwod.com
- www.unidacardoso.com.br
- atlasautoglass.com
- solarconsulting.org
- nsdadventist.org
- 40parables.com
- abofahed.com
- aldobini.it
- www.accidentinjuryalbuquerque.com
- www.alertgy.com
- avenirpourtous.fr
- v9.co
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report