MALICIOUS — jijademefejura.pdf
MALICIOUS — jijademefejura.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
05929b68c6cc050ce0e00da8c65a67e6984f4bf045f23e0fc43ba61fabe736e0 - SHA-1:
b0dc8bfd3559adac3b1217fc3504a3f747ba8c7d - MD5:
e9719785b36115d305093f9519879136 - ssdeep:
1536:nK/MrqNIL6XRSKcy9RWWvUhWrFc50mTzWrBy+pS+H:gMR6XRSC9RtUuKjTzQy+pv - TLSH:
T17A36C0FB61A7CC4C2A869B53ACEB565D518AC68C5236DA6448D87F3CC0BC1BF7E04910 - Submitted as: jijademefejura.pdf
- File type: pdf · Size: 68821 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!E9719785B361
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://simamofot.weebly.com/uploads/1/3/3/9/133997368/93afffca13ed959.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://leonvi.ru/wb?keyword=screen%20recorder%20para%20pc%20softonic, https://simamofot.weebly.com/uploads/1/3/3/9/133997368/93afffca13ed959.pdf, http://wudafozejuniv.rf.gd/blockman_go_hack_unlimited_money.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://leonvi.ru/wb?keyword=screen%20recorder%20para%20pc%20softonic
- https://simamofot.weebly.com/uploads/1/3/3/9/133997368/93afffca13ed959.pdf
- http://wudafozejuniv.rf.gd/blockman_go_hack_unlimited_money.pdf
- http://lubesugoninop.epizy.com/bandobast_telugu_songs.pdf
- http://dolasuwukino.epizy.com/python_historical_stock_data_from_yahoo.pdf
- http://vekogevev.22web.org/guide_to_wisconsin_s_child_labor_laws.pdf
- https://vokefepafox.weebly.com/uploads/1/3/4/3/134333292/1129588.pdf
- http://tufebogepamik.rf.gd/lilian_baylis_technology_school_and_6th_form.pdf
- http://nifekubipaxo.epizy.com/susurivaxixi.pdf
- https://s3.amazonaws.com/xoguwavosuje/91588623188.pdf
- https://s3.amazonaws.com/salosibejodod/anime_girl_generator.pdf
- http://kosener.epizy.com/ajax_javascript_file.pdf
- http://xafegewoweli.epizy.com/ditejizob.pdf
- https://s3.amazonaws.com/lososimap/shin_chan_comedy_video.pdf
- http://fepadegan.epizy.com/rig_veda_sanskrit_with_english_translation.pdf
- http://talagamezibupip.epizy.com/auto_dialer_software_android.pdf
- https://s3.amazonaws.com/nisoxow/99591900086.pdf
- https://jikevisanudopud.weebly.com/uploads/1/3/4/0/134017539/647936.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- leonvi.ru
- simamofot.weebly.com
- lubesugoninop.epizy.com
- dolasuwukino.epizy.com
- vekogevev.22web.org
- vokefepafox.weebly.com
- nifekubipaxo.epizy.com
- s3.amazonaws.com
- kosener.epizy.com
- xafegewoweli.epizy.com
- fepadegan.epizy.com
- talagamezibupip.epizy.com
- jikevisanudopud.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- wudafozejuniv.rf.gd
- tufebogepamik.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report