MALICIOUS — jafuwoselerezufizafivaset.pdf
MALICIOUS — jafuwoselerezufizafivaset.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
da74bb5eae76264e1044bb99730c94f7b5b848816f1adfbdc1dd8d8ee5244f95 - SHA-1:
e35e963dc29bee9a765916a01a408181086ef526 - MD5:
bf725ee3308bf81103e5817f49dca542 - ssdeep:
1536:Ii9PTWVEEiCyuk93uOGYH97w3SRgu23KYwLYKa+ixy6DhJlWZVS7WkpjW8pO7rN0:Di1jo9eOX7w8x1YwLYt+iMmOHkpO7qxH - TLSH:
T18B39D0F711A3DE4C7BCB97432AAB1158744EE7852232DA500049F7BCD6BC97CAE04A51 - Submitted as: jafuwoselerezufizafivaset.pdf
- File type: pdf · Size: 89271 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://kwik-it.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1606fc18cbfc04---pumure.pdf, http://kraljicabih.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612aaa33d9895---govopalunasibopividiwaxor.pdf, https://stayatrosetta.com/wp-content/plugins/super-forms/uploads/php/files/ba32eb8a5h476eimq5j47nggvl/46404460052.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/YTWXjIUwRh0/uplcv?utm_term=edible+mushrooms+list+pdf
- http://kwik-it.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1606fc18cbfc04---pumure.pdf
- http://kraljicabih.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612aaa33d9895---govopalunasibopividiwaxor.pdf
- https://stayatrosetta.com/wp-content/plugins/super-forms/uploads/php/files/ba32eb8a5h476eimq5j47nggvl/46404460052.pdf
- https://247hvac.ca/fabulous1/uploads/files/87478035232.pdf
- http://swaptoys.org/ckeditor/uploads/files/25069477601.pdf
- http://bilcafe.it/userfiles/file/xapigibipevoluxuwori.pdf
- https://www.vibrationmonitoring.asia/wp-content/plugins/formcraft/file-upload/server/content/files/1608a89300d02f---93321730988.pdf
- http://totalfinance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16083bc13d0c7b---92943999858.pdf
- https://admonks.ru/wp-content/plugins/super-forms/uploads/php/files/08e4e65201ecd57999cdd11caa7efb57/21294593729.pdf
- http://www.megasaludips.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ade3e8d4151---sitomapemadijidovol.pdf
- http://architettogherardi.eu/userfiles/files/wuteku.pdf
- https://clubforeducation.com/FCKeditor/userfiles/file/65903596841.pdf
- http://cheers-gifts.com/userfiles/7804424262.pdf
- https://www.ideaklinik.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1609db0e233d81---84075996822.pdf
- https://www.harasportcenter.com/wp-content/plugins/super-forms/uploads/php/files/a08316hvk7jfe7ss1qgbkmn1v3/66132272138.pdf
- https://orderpoet.com/ckfinder/userfiles/files/kipofenakipekozirofumis.pdf
- http://palazzodiaz.com/userfiles/files/93057889293.pdf
- http://shriadinathbank.com/uploads/77952559217.pdf
- http://www.hj-bouwt.be/wp-content/plugins/formcraft/file-upload/server/content/files/160a6d6c995d6b---vomol.pdf
- http://bjhtdszdh.com/v15/Upload/file/2021626727539496.pdf
- http://milcontabil.com.br/wp-content/plugins/super-forms/uploads/php/files/kkmjfkid8bv7ght21u6tdcrs75/wovafuxaxexizafezapo.pdf
- http://burelomdo.com/ckfinder/userfiles/files/medegesedewat.pdf
- http://tcurryproperties.com/konadnew/userfiles/file/begegikakakaralavudaj.pdf
- http://www.radiopopiatej.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a9862ddba9---20846269302.pdf
Embedded domains
- feedproxy.google.com
- kwik-it.ru
- kraljicabih.com
- stayatrosetta.com
- 247hvac.ca
- swaptoys.org
- bilcafe.it
- www.vibrationmonitoring.asia
- totalfinance.ca
- admonks.ru
- www.megasaludips.com
- architettogherardi.eu
- clubforeducation.com
- cheers-gifts.com
- www.harasportcenter.com
- orderpoet.com
- palazzodiaz.com
- shriadinathbank.com
- www.hj-bouwt.be
- bjhtdszdh.com
- milcontabil.com.br
- burelomdo.com
- tcurryproperties.com
- www.radiopopiatej.com
- townsendrogersfamilyreunion.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report