MALICIOUS — mukenupelire.pdf
MALICIOUS — mukenupelire.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
eebb4bcb9ef876c88dc01465de60379db2a0261e0c635d3b8cc2426b8d2308e7 - SHA-1:
224d19b9fc4b2e6d401f0b963d4c2b2547b2aff1 - MD5:
94e610950d7a62d378d67da26b165ac8 - ssdeep:
1536:ju1JBPvt2hd9lQEADmBM31kOaU3aq3mcecivX0irCqV5Am/tsq:6BN2hd9l7Wr37aU3x3mcWrV5d/P - TLSH:
T1EE36D0F3B19BCC9E7A4AEB43A8E55828144AE2896031F7685884F31CD9BC5FD3D25C11 - Submitted as: mukenupelire.pdf
- File type: pdf · Size: 67923 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://retentionstudentexperience.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071655a2e454---25773279360.pdf, http://mgocsm.in/userfiles/file/97744511988.pdf, http://opalsolar.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1606f01618ac0e---29371686171.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/GLLx1DTH0VQ/uplcv?utm_term=worksheet+on+single+and+double+displacement+reactions+answer+key
- https://retentionstudentexperience.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071655a2e454---25773279360.pdf
- http://mgocsm.in/userfiles/file/97744511988.pdf
- http://opalsolar.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1606f01618ac0e---29371686171.pdf
- http://mijneigenlift.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1609e903231b78---kovejibakusi.pdf
- https://aldea.work/wp-content/plugins/super-forms/uploads/php/files/e163149db2b0851352445b0963ac0b9e/valojejixoz.pdf
- http://www.luminicaambiental.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a1bc5db4749---98527272429.pdf
- https://sitebyside.ru/wp-content/plugins/super-forms/uploads/php/files/93a30092290819a2df4247201219cb10/4740483852.pdf
- https://atlasautoglass.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b58e54594b3---rapupisalenok.pdf
- https://comesa.com.pe/wp-content/plugins/super-forms/uploads/php/files/jn9c8r0a6bmr9i4v8mpn2aqfa4/58462247504.pdf
- https://susta.vn/userfiles/file/jupotuj.pdf
- http://www.cddfct.com/up_files/file/zuwugupijudologufiwisit.pdf
- https://ailani.org/wp-content/plugins/super-forms/uploads/php/files/6c020c5f00b8bb34b5ef439c8d092c8e/60791980155.pdf
- https://www.baileysmilk.com/wp-content/plugins/super-forms/uploads/php/files/114acb232562756b8f35b23c8f981566/40368913253.pdf
- https://donnasalon.ru/wp-content/plugins/super-forms/uploads/php/files/9dfdb4c8b7aca11f43a38cb98080cd48/35296437501.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- retentionstudentexperience.com
- mgocsm.in
- opalsolar.com.au
- mijneigenlift.nl
- aldea.work
- www.luminicaambiental.com
- sitebyside.ru
- atlasautoglass.com
- www.cddfct.com
- ailani.org
- www.baileysmilk.com
- donnasalon.ru
- www.w3.org
- purl.org
- ns.adobe.com
- comesa.com.pe
- susta.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report