MALICIOUS — guzitovovabukeje.pdf
MALICIOUS — guzitovovabukeje.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bf3e7c3353f6241ea44a81f4fbcfcae45e9394f38fd92873019987641689e8cf - SHA-1:
b78f11df0a6d308273c9896ba08e1e7c3f86ef36 - MD5:
a2dda85b6ad4a4457ec7dc8fb7c7655b - ssdeep:
1536:mv4Ms4Zy1idIGJ9hVrizJfqkGHHITQAOGDXwmK79XQFWCpOViIWdOuswI39uuqE2:43s45dnhgN3aHBAOGDXwvOSViNT9INu3 - TLSH:
T1A038D0F361CBDD4C7A8B9B476AFA11A86149E7887121FF604088B7BC80BD57DBE04191 - Submitted as: guzitovovabukeje.pdf
- File type: pdf · Size: 82967 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://midel.me/userfiles/file/lowifuvimebufazam.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://benqmusicworkshop.com/fupload/file/tugupu.pdf, https://www.colegiodesafio.net/home/wp-content/plugins/formcraft/file-upload/server/content/files/1606e474b648d6---32631143388.pdf, http://midel.me/userfiles/file/lowifuvimebufazam.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/ngfLrbzwjls/uplcv?utm_term=xhamstervideodownloader+apk+for+macbook+pro+tor+download
- https://benqmusicworkshop.com/fupload/file/tugupu.pdf
- https://www.colegiodesafio.net/home/wp-content/plugins/formcraft/file-upload/server/content/files/1606e474b648d6---32631143388.pdf
- http://midel.me/userfiles/file/lowifuvimebufazam.pdf
- http://drvision.org/wp-content/plugins/formcraft/file-upload/server/content/files/16091cc694a36b---9506673009.pdf
- https://www.frontieregypt.com/sites/all/libraries/ckfinder/userfiles/files/64385308922.pdf
- https://migger.dk/userimages/file/37294732269.pdf
- https://avigailpekelman.com/sites/default/files/file/67393433061.pdf
- http://thanhtindesign.vn/uploads/image/files/daban.pdf
- http://jnnycc.org/userfiles/file/zadaja.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/mfo4vvt7ooq0g3c4c9ncj10jg1/jugetadituveged.pdf
- https://caravanandre.it/wp-content/plugins/super-forms/uploads/php/files/0a978b3c54ef8bd4e86bc1cd7dc9e71b/jubowaralujenazimepo.pdf
- http://mamolenasnc.it/userfiles/files/rapedobi.pdf
- http://vytvarnyobchod.cz/UserFiles/File/gokemogegewodataketirop.pdf
- https://creationstationdance.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c1bddc3e632---mozebemur.pdf
- http://www.timtransportes.com/home/wp-content/plugins/formcraft/file-upload/server/content/files/16103ef105109e---nerogigosejedelofimekek.pdf
- https://www.hospedeagora.com.br/wp-content/plugins/super-forms/uploads/php/files/c66n7gcb42hd8kks70ed0m6tg1/lejodekakawukefan.pdf
- http://eduomania.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c0c747703b4---37112921679.pdf
- http://masonhn.com/d/files/vojinexapaxej.pdf
- https://pui-vital.ro/msg_media/file/gupudimadenakixifaf.pdf
- http://insfilings.com/skyzone_classic/upload/files/17290622074.pdf
- http://discarga.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608be28109492---38739268803.pdf
- https://vntdc.com/upload/fck/file/57358421908.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- benqmusicworkshop.com
- www.colegiodesafio.net
- midel.me
- drvision.org
- www.frontieregypt.com
- avigailpekelman.com
- jnnycc.org
- www.nuricomuvakfi.org
- caravanandre.it
- mamolenasnc.it
- creationstationdance.com
- www.timtransportes.com
- www.hospedeagora.com.br
- eduomania.com
- masonhn.com
- insfilings.com
- discarga.com
- vntdc.com
- www.w3.org
- purl.org
- ns.adobe.com
- migger.dk
- thanhtindesign.vn
- vytvarnyobchod.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report