MALICIOUS — fozefamikem.pdf
MALICIOUS — fozefamikem.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
0a54411a60d778f85d13aeb459d7b529b152beae16af6ae5e60be48de6f33437 - SHA-1:
1e187379c7e2d1f3056433d7e543c0624a500ad7 - MD5:
fffbde856994961a12fabf79a835dc50 - ssdeep:
1536:Gg//qiAxXjRtQU3oNeeLrVY9uDDn6SkoRYLoHe2bSAi08GlXXSy/U:5SiEzzZ3olLrV4uDDn1khZEKclXXSX - TLSH:
T14238D0F3548BEE4C7787AB835AA61159A449D6844032DB680498FB3CD1B82FDBF14F12 - Submitted as: fozefamikem.pdf
- File type: pdf · Size: 80079 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!FFFBDE856994
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=un+nombre+que+combine+con+zoe, https://webmodeli.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607f97364bda8---78608147775.pdf, https://buddingheights.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608da5d2ae895---lotijisineseketekaweno.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=un+nombre+que+combine+con+zoe
- https://webmodeli.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607f97364bda8---78608147775.pdf
- https://buddingheights.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608da5d2ae895---lotijisineseketekaweno.pdf
- https://discoverapartmentsforrent.com/wp-content/plugins/super-forms/uploads/php/files/19e0edd39ba2bfcad67b875a02f7e444/revememabavuputuvokatuf.pdf
- https://planet-for-events.de/userfiles/file/47951248447.pdf
- http://www.idenet.net/wp-content/plugins/formcraft/file-upload/server/content/files/16091dbddc2711---davafozatovat.pdf
- https://www.asahinafunnels.com/wp-content/plugins/super-forms/uploads/php/files/gtebc23eooqjfvmjt3dmd67e8b/litewasakozuzigunikiloja.pdf
- https://levin-dent.ru/wp-content/plugins/super-forms/uploads/php/files/5fb2f634072e0a52d2eeb947a780c0f0/buzete.pdf
- http://albatrossmrn.com/konadnew/userfiles/file/wugimamoguzatuzavinuxine.pdf
- http://pansophers.com/wp-content/plugins/formcraft/file-upload/server/content/files/16088193a4887d---zimabiwejenowolifa.pdf
- http://gingerwooddesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/160badbb49fafd---16950675255.pdf
- http://aarogyamedico.com/userfiles/file/sowuzipapotafaz.pdf
- https://mikepromedia.com/wp-content/plugins/super-forms/uploads/php/files/httfaj7tgncritv09ro6mkfnr7/bixebirigukafenixewe.pdf
- https://www.chartsunlimited.com.ph/wp-content/plugins/formcraft/file-upload/server/content/files/1607c89223b3b0---61575794678.pdf
- https://mattweidnerlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16096343c8d6bd---45027159673.pdf
- https://arenda1s.ru/wp-content/plugins/super-forms/uploads/php/files/1c3cbaa18907dd4b1add5039828c29c1/biduwebepefuregijun.pdf
- https://bindazzled.com.au/wp-content/plugins/super-forms/uploads/php/files/29f3d35c748dc78275270bfac93428c0/3279697580.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- huntic.ru
- webmodeli.com
- buddingheights.org
- discoverapartmentsforrent.com
- planet-for-events.de
- www.idenet.net
- www.asahinafunnels.com
- levin-dent.ru
- albatrossmrn.com
- pansophers.com
- gingerwooddesign.com
- aarogyamedico.com
- mikepromedia.com
- mattweidnerlaw.com
- arenda1s.ru
- bindazzled.com.au
- www.w3.org
- purl.org
- ns.adobe.com
- www.chartsunlimited.com.ph
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report