MALICIOUS — lowifuvimebufazam.pdf
MALICIOUS — lowifuvimebufazam.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
c64edadaeb4dcca2c3b442a7f5524228cbf79d1020a65bda91fa321d0ebb139f - SHA-1:
e3b3e24b54acc57abaad2c30d6d9eb79a6b4370b - MD5:
348e5a925121b176aa7723d83f2a0e03 - ssdeep:
1536:u/7on9R6y2qhwPFcQkeejWMhkqPGKfoxFocWunWgVre84:EevUCsFcQLejWMhkqPGKkoSnWcrk - TLSH:
T1B137DFF32687ED4CBA4B7F5398BA1049218BE2443176E6A458C8B75CC97C7BD7D04A02 - Submitted as: lowifuvimebufazam.pdf
- File type: pdf · Size: 74229 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!348E5A925121
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://intechsol.kz/wp-content/plugins/formcraft/file-upload/server/content/files/1608419d943513---88520749980.pdf, https://estigotours.com/wp-content/plugins/super-forms/uploads/php/files/046f5e91cf3aaecb1580151f9e4bd268/fopukuluvegiwekosi.pdf, http://allegroescrow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e8fdcdf808---tenibenukenikojagivukezez.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=destiny+2+free+game
- http://intechsol.kz/wp-content/plugins/formcraft/file-upload/server/content/files/1608419d943513---88520749980.pdf
- https://estigotours.com/wp-content/plugins/super-forms/uploads/php/files/046f5e91cf3aaecb1580151f9e4bd268/fopukuluvegiwekosi.pdf
- http://allegroescrow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e8fdcdf808---tenibenukenikojagivukezez.pdf
- https://provisionsinternational.com/wp-content/plugins/formcraft/file-upload/server/content/files/160770908d4010---bulofirunadubogexorinof.pdf
- http://slsnn.ru/content/file/saweridupupadupinigi.pdf
- http://www.absolutecateringla.com/wp-content/plugins/formcraft/file-upload/server/content/files/16070dd3c2f75d---80391423629.pdf
- https://g-ortho.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608768a8b1594---88268883098.pdf
- https://bizdrive.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1/16074dc11799ec---26588538115.pdf
- http://www.sparkprototypes.com/wp-content/plugins/formcraft/file-upload/server/content/files/160712f7a20af6---gokatamiwefodedoputebeli.pdf
- https://alfa-clining.ru/wp-content/plugins/super-forms/uploads/php/files/483aab88488a04aa55243bc4e1883605/jatiwovubaximopax.pdf
- https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/e43b15e339e9a382575ee5b2e516eb4d/35462915282.pdf
- http://lisahyatthealth.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607dbb86ef613---dafapokozaxopelitubog.pdf
- https://akdenizokullari.k12.tr/wp-content/plugins/super-forms/uploads/php/files/ql7akp8te1u0hnlr0opv5vjp9d/xoxasexededelabido.pdf
- https://shared401k.com/wp-content/plugins/super-forms/uploads/php/files/9dc1777a2b911e4d8f4d6d68ab28fd9f/bapubisaxokizuxumorowak.pdf
- https://www.numberoneporthill.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160842834570ad---bojiregepimujem.pdf
- http://lichnyiybrand.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16094bc3c9e639---2994727812.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- estigotours.com
- allegroescrow.com
- provisionsinternational.com
- slsnn.ru
- www.absolutecateringla.com
- g-ortho.com.br
- bizdrive.nl
- www.sparkprototypes.com
- alfa-clining.ru
- ahi.com.ua
- lisahyatthealth.com
- shared401k.com
- www.numberoneporthill.co.uk
- lichnyiybrand.ru
- www.w3.org
- purl.org
- ns.adobe.com
- intechsol.kz
- akdenizokullari.k12.tr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report