MALICIOUS — luzilifinaxanuzala.pdf
MALICIOUS — luzilifinaxanuzala.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
e18cceeab91cbf2b3713a24dd0047d97cf9209f706450a0be5e99310cbdd3274 - SHA-1:
81acec8f40b397190e7e843386bcfc6ffd47903b - MD5:
299f36461b176b15b99bf73dc36848dd - ssdeep:
1536:hO2VXgDnwVU38cazMUq9C8Fn7YIk9qw3UKO62KCIWWFj1WwpOSCAa:82Fg7wHcazezRYIFM/O5KCIjcS+ - TLSH:
T1C438CFF720E7CD5DB61ACF032AEB25AC918AE7C46661DB40448C766C953C6BE7F10980 - Submitted as: luzilifinaxanuzala.pdf
- File type: pdf · Size: 83840 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://www.tokyomagic.jp/images/library/File/58214937760.pdf, https://hiroyoung.com/data/files/jopebagesivebufif.pdf, https://tattica.byespresso.com/app/webroot/files/upload/files/71960101166.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/LPIa9PGmDLg/uplcv?utm_term=most+addictive+game+on+play+store
- http://www.tokyomagic.jp/images/library/File/58214937760.pdf
- https://hiroyoung.com/data/files/jopebagesivebufif.pdf
- https://tattica.byespresso.com/app/webroot/files/upload/files/71960101166.pdf
- http://cdmvt.cz/sites/default/files/38542068414.pdf
- https://regalcabs.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1613c47cb51958---15328516577.pdf
- https://csodamalom.hu/files/files/refanoneredomaxob.pdf
- http://swaving-stalinrichting.nl/ckfinder/userfiles/files/togogafedid.pdf
- http://fujiya-la.com/uploads/files/21737130531.pdf
- https://ispartaorganizasyon.com/ckfinder/upload/files/xakonozarafemobarat.pdf
- https://u-spot.biz/js/ckfinder/userfiles/files/zixasimorizavaf.pdf
- http://2016.letnifestiwal.pl/ckfinder/userfiles/files/subatemiwaputorobi.pdf
- http://jagodkaprzedszkole.pl/userfiles/file/jadokolilapelabifaz.pdf
- https://interstudy.net/userfiles/file/fojajipu.pdf
- http://arabic.cz/ckfinder/userfiles/files/3320689457.pdf
- http://canhtoanland.com/upload/files/nixeburekopox.pdf
- http://ggmtc.net/userfiles/files/tufegosi.pdf
- http://www.juniorcollege.cl/ckfinder/userfiles/files/98189309758.pdf
- https://pracowniatechart.pl/fckpliki/file/57505325053.pdf
- http://rotarytattoomachine.co/project-new/christianbook/upload_images/file/32199863848.pdf
- https://mvpartners.be/images/uploadedimages/file/befinejojozil.pdf
- http://simpelms.nl/userfiles/files/zadalasaxadakorurotu.pdf
- http://ziguratex.com/helpdesk/app/webroot/img/userfiles/files/pufubuguw.pdf
- https://mimzyonline.com/userfiles/file/xosojojuwezarusokeb.pdf
- http://fcraregistration.com/UploadedData/file/55172496543.pdf
Embedded domains
- feedproxy.google.com
- www.tokyomagic.jp
- hiroyoung.com
- tattica.byespresso.com
- regalcabs.co.uk
- swaving-stalinrichting.nl
- fujiya-la.com
- ispartaorganizasyon.com
- u-spot.biz
- 2016.letnifestiwal.pl
- jagodkaprzedszkole.pl
- interstudy.net
- canhtoanland.com
- ggmtc.net
- pracowniatechart.pl
- rotarytattoomachine.co
- mvpartners.be
- simpelms.nl
- ziguratex.com
- mimzyonline.com
- fcraregistration.com
- cosmikkino.ru
- kfbma.org
- anctools.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report