MALICIOUS — kuvol.pdf
MALICIOUS — kuvol.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
db3468e650f3f9993e677fe5d644d0fa674154059b7b14384a34508b2310722d - SHA-1:
f8a811fa18063edd489a0b4db513ce35edc7f208 - MD5:
f37ef757ef93805d490a22cc96bef043 - ssdeep:
1536:0vp/1h7j9ME+B802fV34dxGRemAOECkaDNJjKEkAuiQQBHw0LHg3WOpOwrKWYv0J:G1TMENHfV32okmXka5JjYLiQ+Dg0wrgU - TLSH:
T15D37BFF321D7CC8CB74BDF076AD211ADA046E7882132EB445188B96C91BC5BD7F28612 - Submitted as: kuvol.pdf
- File type: pdf · Size: 75399 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://drzwiukryte.pl/userfiles/file/vusuwafakoteg.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080cb01ac27e---powizafemejezuvo.pdf, http://gpshardorawal.com/hemkunt/userfiles/file/pejafib.pdf, http://al-bandak.com/userfiles/file/33265749660.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/3vuEKuznOb8/uplcv?utm_term=pradhan+mantri+awas+yojana+2019+list+pdf+download
- http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080cb01ac27e---powizafemejezuvo.pdf
- http://gpshardorawal.com/hemkunt/userfiles/file/pejafib.pdf
- http://al-bandak.com/userfiles/file/33265749660.pdf
- https://esteticarcare.com/wp-content/plugins/super-forms/uploads/php/files/af812b784d8c7f590283d6f82aead03c/vusojelen.pdf
- http://alicekhenrylawoffice.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/figowovozajedido.pdf
- http://drzwiukryte.pl/userfiles/file/vusuwafakoteg.pdf
- http://iideree.org/wp-content/plugins/formcraft/file-upload/server/content/files/160ca1cfd5b57d---gevonetodakegolibuxojovi.pdf
- http://www.dramayaramendes.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160757edd19dfa---99493801261.pdf
- https://www.hdontheroadnapoli.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607991aa53321---20676386005.pdf
- http://sevoir.hu/uploads/file/65792254293.pdf
- http://bertrandetgastineaudesigners.com/userfiles/file/rosujuruvirojiba.pdf
- http://werder-ritter.de/UserFiles/File/galugalavu.pdf
- http://www.onegelha.com/wp-content/plugins/super-forms/uploads/php/files/afbeff2094b013992d1ac86a331dbe77/74913016312.pdf
- http://aiswaryamatrimonials.com/fck_uploads/file/20347475137.pdf
- http://thefutureofgolf.eu/wp-content/plugins/formcraft/file-upload/server/content/files/160a4955dd5f27---josemiwitetiboxuruvuvit.pdf
- https://arenda1s.ru/wp-content/plugins/super-forms/uploads/php/files/758c53e44337f9e6fb98fa9f725b4a9a/1131232458.pdf
- https://aryaayur.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a01ba4ddfb9---618219901.pdf
- https://calldidocta.com/wp-content/plugins/super-forms/uploads/php/files/4008f836d4d9796a904e85b15b3360a2/19610525418.pdf
- http://komputerzagrosze.pl/userfiles/file/16818811589.pdf
- http://www.chiringuitomediterraneo.com/ckfinder/userfiles/files/tavapijorajudizozufofegeb.pdf
- http://stellar-toys.com/ckfinder/userfiles/files/88570379919.pdf
- https://ccveg.org/wp-content/plugins/super-forms/uploads/php/files/ohffvvhml1qc2727j2j9m1su2g/lereratuno.pdf
- https://www.hauptsache.cc/wp-content/plugins/formcraft/file-upload/server/content/files/160d5ee350afef---fadukiwolekopudofaduw.pdf
- http://ingmontagna.com/userfiles/files/razanafudugaganasijoj.pdf
Embedded domains
- feedproxy.google.com
- vtracauto.com
- gpshardorawal.com
- al-bandak.com
- esteticarcare.com
- alicekhenrylawoffice.com
- drzwiukryte.pl
- iideree.org
- www.dramayaramendes.com.br
- www.hdontheroadnapoli.it
- bertrandetgastineaudesigners.com
- werder-ritter.de
- www.onegelha.com
- aiswaryamatrimonials.com
- thefutureofgolf.eu
- arenda1s.ru
- aryaayur.com
- calldidocta.com
- komputerzagrosze.pl
- www.chiringuitomediterraneo.com
- stellar-toys.com
- ccveg.org
- www.hauptsache.cc
- ingmontagna.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report