MALICIOUS — nawukaja.pdf
MALICIOUS — nawukaja.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c6e9b5a75be2e3b7c02aa6d1e169c657190099b745bb5f431b70102145923770 - SHA-1:
90fc7c86707371b2191c6c4df67c4bcc7ab36d29 - MD5:
91137630887d47e9785ceeaa45a6d5c8 - ssdeep:
1536:G9sQSmWYZMTAsfRDPzuOT3RacPVcZBHLKvWvOoiQIVp7cWHpOvqJ1MaWj0mjrlaM:osQSmnGR7iOVaCVcZB6WGvBVpwvqJ6BV - TLSH:
T13939D0F310EBDD9C3A57DF436EDB5198D08AD3886132DA008448BA5C98BC9BE7F14991 - Submitted as: nawukaja.pdf
- File type: pdf · Size: 84795 bytes
- Verdict: malicious (97/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://popa.com.br/wp-content/plugins/super-forms/uploads/php/files/366b3273704ee887f6690964c552cabb/kudugete.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://nomylo.ru/uplcv?utm_term=best+android+weather+app+uk+2020, https://popa.com.br/wp-content/plugins/super-forms/uploads/php/files/366b3273704ee887f6690964c552cabb/kudugete.pdf, http://xn--9i1b14l32gg2dsybq3b.com/upload/fckeditor/file/dojoferuxopapepo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nomylo.ru/uplcv?utm_term=best+android+weather+app+uk+2020
- https://popa.com.br/wp-content/plugins/super-forms/uploads/php/files/366b3273704ee887f6690964c552cabb/kudugete.pdf
- http://xn--9i1b14l32gg2dsybq3b.com/upload/fckeditor/file/dojoferuxopapepo.pdf
- http://sensor4you.com/fckeditor/editor/filemanager/connectors/php/fckeditor/upload/202109/file/migubap.pdf
- https://masterok-kovka.ru/wp-content/plugins/super-forms/uploads/php/files/830df4adc9b6e8aa67860c80b177a3e3/39505327083.pdf
- http://kadh.kr/bobod/upload/file/54117510590.pdf
- http://nawooelcs.com/upload/userfiles/2021/09/files/210909165443.pdf
- http://bongoes62.dk/userfiles/file/tisupigof.pdf
- http://www.eflox.net/wp-content/plugins/formcraft/file-upload/server/content/files/1613ebcb5da9be---fosotarikenu.pdf
- http://musikpark-live.de/userfiles/file/lozudajasosazulerosadiji.pdf
- http://mcap.cz/images/uploadedimages/file/suposo.pdf
- http://vincentianssjp.com/userfiles/file/sisetafafeluroxobakivup.pdf
- http://iiiemjobs.com/FCK_Editor_Images/files/37142905495.pdf
- http://trust-law-firm.com/userfiles/file/20210910150905_1345535177.pdf
- http://savoie-outils-coupants.com/ckfinder/userfiles/files/wekit.pdf
- http://asesoriagarpe.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613bbf0747ac9---93953948263.pdf
- http://marienoellebermond.com/img/uploaded/file/kugunome.pdf
- https://termokingbt.com/ckfinder/userfiles/files/fudozu.pdf
- http://abwjefferson.com/uploads/files/tifogosixitetiralubifi.pdf
- http://pnmanagementsolutions.in/uploads/kufefuker.pdf
- http://kasintorn.com/images/upload/files/novotivubilogonovamux.pdf
- http://portalcom-b2b.es/img/user//file/_0397795001631142114.pdf
- http://wefocusdesign.com/upload/files/88535741987.pdf
- https://himalayanthailand.com/image/upload/File/77119232735.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- nomylo.ru
- popa.com.br
- xn--9i1b14l32gg2dsybq3b.com
- sensor4you.com
- masterok-kovka.ru
- kadh.kr
- nawooelcs.com
- www.eflox.net
- musikpark-live.de
- vincentianssjp.com
- iiiemjobs.com
- trust-law-firm.com
- savoie-outils-coupants.com
- asesoriagarpe.com
- marienoellebermond.com
- termokingbt.com
- abwjefferson.com
- pnmanagementsolutions.in
- kasintorn.com
- portalcom-b2b.es
- wefocusdesign.com
- himalayanthailand.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report