MALICIOUS — gugaxe.pdf
MALICIOUS — gugaxe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f4a600ad395b56178f1c6154762ab7978d9cff5ce30cfb14ae82a39a1db4fb22 - SHA-1:
ee61fd950023316691cf85bd124430669a431225 - MD5:
2ae58ecb50c1f2098c87985a9f3331ec - ssdeep:
1536:pipsqWizoP+YI9IVrGS7kl2bRi9kzu5NL/GWIIYphvWvW8pO7VsdSg9BwK:8p/zoP+/Or7klO80wNL/axDvWi7Vsdnt - TLSH:
T1ED39CFE3605BDD9C3B9F9F0368FB1144A58AD6C82172EB9200C87A6C967CA7D7F20550 - Submitted as: gugaxe.pdf
- File type: pdf · Size: 91124 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://mountmedpharmacy.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1613723045fee7---tuxosegagejuvevole.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://mountmedpharmacy.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1613723045fee7---tuxosegagejuvevole.pdf, http://www.creativitaecomunicazione.it/js/lib/ckfinder/userfiles/files/sisepagamigojefan.pdf, https://vatlieutaphu.com/upload/files/17420328781.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/GLLx1DTH0VQ/uplcv?utm_term=new+messenger+2020+mod+apk
- http://mountmedpharmacy.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1613723045fee7---tuxosegagejuvevole.pdf
- http://www.creativitaecomunicazione.it/js/lib/ckfinder/userfiles/files/sisepagamigojefan.pdf
- https://vatlieutaphu.com/upload/files/17420328781.pdf
- http://topimmigrationlawyer.org/ckfinder/userfiles/files/67507253603.pdf
- http://handbook.hu/upload/page/file/69766538613.pdf
- http://m-camper.ru/ckfinder/userfiles/files/sosalijila.pdf
- https://osiindia.org/ckfinder/userfiles/files/xenoxoxuzugupud.pdf
- https://ncfouting.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613cc5e15cc4e---20690471585.pdf
- https://lordoptika.hu/files/files/63821007237.pdf
- http://sportsbettingconsultants.net/cote_dor_import/admin/ckfinder/userfiles/files/voruf.pdf
- http://gustosandvic.com/ckfinder/userfiles/files/27572093550.pdf
- https://walnutcreekguide.com/wysiwygfiles/file/munukakotuzijinin.pdf
- http://www.weilandensemble.nl/ckfinder/userfiles/files/47595273179.pdf
- http://abwpetersburg.com/uploads/files/24050056862.pdf
- http://omegapizza.net/uploads/files/9958054780.pdf
- http://siciny.pl/userfiles/file/38839130377.pdf
- https://www.bocamvigliesrooms.com/wp-content/plugins/super-forms/uploads/php/files/3471e3a3db543ca1b2595e5091dc6c5a/46851805300.pdf
- https://hanoihome.net/img_duhoc/files/11324465947.pdf
- https://bestmiamiturf.com/wp-content/plugins/super-forms/uploads/php/files/6289cbdf1c7357d77d32b55f911e6fc6/jetureg.pdf
- http://ohmytour.kr/FileData/ckfinder/files/20210913_835485CE92F2413C.pdf
- https://jdsliquorlocker.com/nbloom/fckuploads/file/88012050043.pdf
- https://tessuno.com/upload/files/6136c1b675944.pdf
- http://free-note.kr/files/fckeditor/file/1454037740613a37c2dacfa.pdf
- http://propertiesforrent.com/userfiles/file///92826710498.pdf
Embedded domains
- feedproxy.google.com
- mountmedpharmacy.co.za
- www.creativitaecomunicazione.it
- vatlieutaphu.com
- topimmigrationlawyer.org
- m-camper.ru
- osiindia.org
- ncfouting.com
- sportsbettingconsultants.net
- gustosandvic.com
- walnutcreekguide.com
- www.weilandensemble.nl
- abwpetersburg.com
- omegapizza.net
- siciny.pl
- www.bocamvigliesrooms.com
- hanoihome.net
- bestmiamiturf.com
- ohmytour.kr
- jdsliquorlocker.com
- tessuno.com
- free-note.kr
- propertiesforrent.com
- jmestateplanning.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report