MALICIOUS — gagufutejidazomaxojofuf.pdf
MALICIOUS — gagufutejidazomaxojofuf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
fb6af4bbc6b1c01c25981853979623dc87a8416c9cfd24471f4dfbdb5d457d85 - SHA-1:
5f68d9c7ab98424faf839fa0ab7b94dc285597bb - MD5:
61dc019681494902b1906fbb08293fb7 - ssdeep:
1536:3IupImasOwwAdv4wPwEds6cLkPDPmf3W90W+nEnW5364r+UStjKyrWUpO7Xw3:FemasuW4wVVcLgTmeSW+nE/XKy+7U - TLSH:
T1D739D0F350A7DD8C774BCB4369A921ECB48BC7847161F69001887A2C897C5BE7F14A91 - Submitted as: gagufutejidazomaxojofuf.pdf
- File type: pdf · Size: 87530 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://archism.ru/uplcv?utm_term=melhores+livros+de+direito+constitucional+2020, https://vdbergelectro.nl/wp-content/plugins/super-forms/uploads/php/files/ac6abb17ec98352d14f97545e9fdec35/wetadubek.pdf, http://kadernictvo-svetlana.sk/editor_uploads/system/files/tinufosugixexu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://archism.ru/uplcv?utm_term=melhores+livros+de+direito+constitucional+2020
- https://vdbergelectro.nl/wp-content/plugins/super-forms/uploads/php/files/ac6abb17ec98352d14f97545e9fdec35/wetadubek.pdf
- http://kadernictvo-svetlana.sk/editor_uploads/system/files/tinufosugixexu.pdf
- http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160c888d2c9a52---wawivopudib.pdf
- http://workprohealth.com/wp-content/plugins/formcraft/file-upload/server/content/files/160740a86d390a---latuxidetupenutaj.pdf
- http://juha.be/_files/file/24940624915.pdf
- http://usmleworkout.com/files/file/9156618853.pdf
- http://www.hkqi.com/wp-content/plugins/formcraft/file-upload/server/content/files/16089cc140b890---82359707392.pdf
- https://weddingitaly.jp/images/file/ridaraxijak.pdf
- https://spencershaulageltd.co.uk/wp-content/plugins/super-forms/uploads/php/files/45a738a2f3a45019ea5e311e0627cee3/87791548377.pdf
- http://www.medical-psychology.gr/wp-content/plugins/formcraft/file-upload/server/content/files/160e4ce9a960d2---53913553176.pdf
- http://studiotecnicopinto.it/userfiles/files/49346832109.pdf
- https://acrgruppe.de/userfiles/file/52285624973.pdf
- http://chaodontuonglai.vn/uploads/ck_upload/files/mojonufefomivapireb.pdf
- http://sva-jeanroze.com/xmedia/file/46201190605.pdf
- https://useoneconvo.com/wp-content/plugins/super-forms/uploads/php/files/c590df76f6519a8fb7a1c86aaac133d5/59626231043.pdf
- https://big-cash.de/wp-content/plugins/super-forms/uploads/php/files/dr3103u8ps2ou441v8f4eqb0uu/gasutiruzuna.pdf
- https://volgogradexpo.ru/ckfinder/userfiles/files/sebipifuvi.pdf
- http://www.chinahkcarplate.com/wp-content/plugins/formcraft/file-upload/server/content/files/160878aee03664---fupofivur.pdf
- https://bilegt.mn/userfiles/files/palorikozumob.pdf
- https://tbsva.org/Upload/files/20210704011252.pdf
- http://skup-laptopow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b4fe43d293---juxivuxigukegutuziwofemu.pdf
- https://braviengenharia.com.br/wp-content/plugins/super-forms/uploads/php/files/6kn03d7j88jt38jr2tlsoonj6s/tijazuxizepuzu.pdf
- https://sitebyside.ru/wp-content/plugins/super-forms/uploads/php/files/d6876f9b70b005bc07055b187492042b/84633120786.pdf
- http://www.ncstarim.com.tr/wp-content/plugins/super-forms/uploads/php/files/1q05k661l3iecokdepstqc43p2/93069031542.pdf
Embedded domains
- archism.ru
- vdbergelectro.nl
- prodesign31.ru
- workprohealth.com
- juha.be
- usmleworkout.com
- www.hkqi.com
- weddingitaly.jp
- spencershaulageltd.co.uk
- studiotecnicopinto.it
- acrgruppe.de
- sva-jeanroze.com
- useoneconvo.com
- big-cash.de
- volgogradexpo.ru
- www.chinahkcarplate.com
- tbsva.org
- skup-laptopow.com
- braviengenharia.com.br
- sitebyside.ru
- www.w3.org
- purl.org
- ns.adobe.com
- kadernictvo-svetlana.sk
- www.medical-psychology.gr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report