MALICIOUS — zemumulugifuxomekeb.pdf
MALICIOUS — zemumulugifuxomekeb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
c42586a9a0e2964e9f2c025d25ad9504e87fefac54894ff06b3be217c71265d4 - SHA-1:
e7c96a8663e0874325e71bf88f89028ae077a081 - MD5:
95a51a9ace0dad81d300af3a7e284e59 - ssdeep:
1536:IvI/7vDpZVGUPNJKEXiIvSCw34GARueR6A1MtcSOigeZMWypOlLTGNgbIeW4FcYq:EAzlC6NkERvSzARuSicbigClL6NnmF2Z - TLSH:
T1293AD1F350A7DE9CBB8B9747A99211B9F08AD3842132FB544088B72C94BC6BC7F44651 - Submitted as: zemumulugifuxomekeb.pdf
- File type: pdf · Size: 94399 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://finsura-lifedirect.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1606c6b6fcd934---jimijudilejikutidigibulu.pdf, http://e1pl2.nazwa.pl/busy/fotki/file/xonowazapifixuweminovales.pdf, http://ahkjt.com/upfile/file/fazekutukubokobunu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BkSY9tpko7c/uplcv?utm_term=the+best+way+to+clear+your+mind
- http://finsura-lifedirect.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1606c6b6fcd934---jimijudilejikutidigibulu.pdf
- http://e1pl2.nazwa.pl/busy/fotki/file/xonowazapifixuweminovales.pdf
- http://ahkjt.com/upfile/file/fazekutukubokobunu.pdf
- http://www.assignproject.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078a274015ab---23779399970.pdf
- https://aashianarealty.com/file/37255353393.pdf
- http://comicpapyrus.com/wp-content/plugins/super-forms/uploads/php/files/cbedd5708dc06c7d12d28a592838bf2f/28206583861.pdf
- http://stroynerud-sm.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160786a39acb78---61329841817.pdf
- http://www.deep2001.com/images/library/File/mubomidasitagufelizemom.pdf
- http://www.danvillern.com/wp-content/plugins/super-forms/uploads/php/files/v5j310rlrki658or665gvdrud1/retizirorofiserizesowuxif.pdf
- http://safarang.com/basefile/files/19265637861.pdf
- https://rhdplumbing.com/wp-content/plugins/super-forms/uploads/php/files/7c41b7065fe0ad1b6a6e1c9a4da3a456/14595441046.pdf
- https://regalcabs.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16081137a89783---4279594544.pdf
- https://www.infrascale.com/wp-content/plugins/super-forms/uploads/php/files/bd27fa93ca6bf8d35dee404f633862bb/galitirofiwu.pdf
- http://lalitas-thaimassage-spa.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609078cfe13f1---jitiboxotosaximaw.pdf
- http://www.expertnutritionadvisor.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607fef60483cc---83704098379.pdf
- http://maasmartcity.com/userfiles/file/92174413606.pdf
- https://gauravkankariya.com/wp-content/plugins/super-forms/uploads/php/files/btbo522dukctohpqpnov6778v7/72179534826.pdf
- https://cald-lighting.com/wp-content/plugins/super-forms/uploads/php/files/b95bd2c235bc25d5e16b0e279604ffc0/49022721231.pdf
- http://grani-tonkogo-mira.ru/wp-content/plugins/super-forms/uploads/php/files/638d22bee494f704ad40c278b2a9282d/fevetavaguselasejirodite.pdf
- http://adanateknikservis.web.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1607faf1c18c3f---janugezavuxodito.pdf
- http://www.christinemartin.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1608eef04dc9bf---64802752575.pdf
- http://www.cascinasorigherio.it/wp-content/plugins/formcraft/file-upload/server/content/files/16081cbf025ecf---maleteji.pdf
- http://festivaldeliteraturadepereira.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b6ddbcaecdb---6041438790.pdf
- http://hidra.it/ckfinder/userfiles/files/39912517100.pdf
Embedded domains
- feedproxy.google.com
- finsura-lifedirect.com.au
- e1pl2.nazwa.pl
- ahkjt.com
- www.assignproject.com
- aashianarealty.com
- comicpapyrus.com
- stroynerud-sm.ru
- www.deep2001.com
- www.danvillern.com
- safarang.com
- rhdplumbing.com
- regalcabs.co.uk
- www.infrascale.com
- lalitas-thaimassage-spa.de
- www.expertnutritionadvisor.com
- maasmartcity.com
- gauravkankariya.com
- cald-lighting.com
- grani-tonkogo-mira.ru
- www.christinemartin.co.uk
- www.cascinasorigherio.it
- festivaldeliteraturadepereira.com
- hidra.it
- www.fsnn.se
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report