MALICIOUS — gewufulewo.pdf
MALICIOUS — gewufulewo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
b4157b9161962598df0044a24c881d6d699d0413bf69e01a68982fb0ef05e65e - SHA-1:
fe100b9935dfda4f9c6fba6634b09eec40925e80 - MD5:
8c603af29f0c26b4b2311436a7e27f9d - ssdeep:
1536:1Fpv6/Hqbw7ci/tSCE23swwFbGMbBJBSWOpOaZ3mLjrE+kbyWbCceyOou:jC/8tmsvbNbBjnaZ2XrFkbcJyc - TLSH:
T12A37BEF37097DD8CB6878F0379A620AC548AD78C6225EB90408CE76D997CA7D7F11A10 - Submitted as: gewufulewo.pdf
- File type: pdf · Size: 73450 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: Trojan:PDF/Phish!atmn
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://amirafouad.com/uploaded_files/file/wogujepabixelelutalitu.pdf, https://resulgame.com/calisma2/files/uploads/joxutuvof.pdf, http://agendaalzheimer.org/files/galeria/files/wezabig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/6naE_Nh8_CY/uplcv?utm_term=gramatika+engleskog+jezika+pdf+free+download
- http://amirafouad.com/uploaded_files/file/wogujepabixelelutalitu.pdf
- https://resulgame.com/calisma2/files/uploads/joxutuvof.pdf
- http://agendaalzheimer.org/files/galeria/files/wezabig.pdf
- https://cashmeredreams.com/wp-content/plugins/super-forms/uploads/php/files/88fc7e213edf8bd2c87278335936a08e/zamisufuvodejiwofuxudip.pdf
- https://ka-base.no/images_content/file/jotabigirafekur.pdf
- http://webinaris.org/ckfinder/userfiles/publics/files/seneruxoser.pdf
- http://www.gitialiganjlko.org/ckfinder/userfiles/files/samajetonetimedobasuweki.pdf
- https://www.aserspa.net/wp-content/plugins/super-forms/uploads/php/files/dua6vool7lk9ict0jact5cr2bd/kopigofuzesudolegegin.pdf
- http://ophtalmic-overnight.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1610479b0a1fa5---38416641205.pdf
- http://pk.mo/userfiles/file/38855154476.pdf
- https://agilitynd.com/wp-content/plugins/super-forms/uploads/php/files/b11731f2b25f72681973918b561ef670/ruragixur.pdf
- http://prvugkh.ru/uploads/files/basukopawuxe.pdf
- http://srihemkuntschoolint.com/slbdavbatala/userfiles/file/fezemurinesesadupejup.pdf
- http://dailitara.lt/bites/uploads/file/visitanabovojufarakesuvaf.pdf
- http://freehajjandumrah.com/admin/admin/uploadfiles/file/37657632386.pdf
- https://csom.cz/wp-content/plugins/super-forms/uploads/php/files/0c565a0ffe3235ee29b1491697998a16/80262369846.pdf
- https://facade-metal.ch/ckfinder/userfiles/files/rarapijame.pdf
- http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/ck2f7p7bvc17hpvfrti4a3po91/20084874075.pdf
- https://www.paparazzirestaurant.com.au/wp-content/plugins/super-forms/uploads/php/files/770596beb10bf6d2ef81394074177631/bumurodizodakeda.pdf
- http://atek-ent.com/upload/file/2069520076.pdf
- https://www.hungarianassociation.com/wp-content/plugins/formcraft/file-upload/server/content/files/16124243b297fc---74678039149.pdf
- https://www.kadeavenue.com/wp-content/plugins/super-forms/uploads/php/files/b3795fc898387fe4f1f02ed0f0f5ef0c/riwijipemiji.pdf
- http://freeski.hu/freeski/file/82758605610.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- amirafouad.com
- resulgame.com
- agendaalzheimer.org
- cashmeredreams.com
- ka-base.no
- webinaris.org
- www.gitialiganjlko.org
- www.aserspa.net
- ophtalmic-overnight.fr
- agilitynd.com
- prvugkh.ru
- srihemkuntschoolint.com
- freehajjandumrah.com
- facade-metal.ch
- www.sunarnuricomuisvealisverismerkezi.com
- www.paparazzirestaurant.com.au
- atek-ent.com
- www.hungarianassociation.com
- www.kadeavenue.com
- www.w3.org
- purl.org
- ns.adobe.com
- pk.mo
- dailitara.lt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report