MALICIOUS — zojewamamesabofa.pdf
MALICIOUS — zojewamamesabofa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0d168260fd684e7c9f6a30189c12e2e8db7624b373d7b018d5d5b74f389edc42 - SHA-1:
38d5f3f01d52122c5dc0b5a2c54b3366509f3310 - MD5:
942645a4596faa650aabcd30cbbfa8bc - ssdeep:
1536:R/ZvmK7SkhrP+rMCmZX3NJ5GDTHdqRr7Zxxne4WHpOvsoXpOAWgVZBBvbNyzPhWm:vvmYsICm59zGnArZNvPXpOonbNyzPhT - TLSH:
T1D639D0F3115BCD8C769AAB4329BF11AC709B96C86121EBA044C87A7C897C5FDBE04911 - Submitted as: zojewamamesabofa.pdf
- File type: pdf · Size: 87085 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://alexanderkanevskyartgallery.com/clientMedia/file/rapabilapaxositerupelepov.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cructi.ru/uplcv?utm_term=our+discovery+island+2+student+book+pdf+download, https://www.karenlovelee.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c27ea1d246f---30723964079.pdf, https://muahohangnhat.com/app/webroot/uploads/files/wesozolawubewazoxisanoto.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cructi.ru/uplcv?utm_term=our+discovery+island+2+student+book+pdf+download
- https://www.karenlovelee.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c27ea1d246f---30723964079.pdf
- https://muahohangnhat.com/app/webroot/uploads/files/wesozolawubewazoxisanoto.pdf
- http://alexanderkanevskyartgallery.com/clientMedia/file/rapabilapaxositerupelepov.pdf
- https://funbugs.ie/userfiles/file/22013784985.pdf
- http://climacom.eu/userfiles/files/30757661007.pdf
- http://arcomproltd.com/userfiles/file/wawanosuzuse.pdf
- http://www.chinahkcarplate.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a313995adf3---nonixe.pdf
- http://animationcoach.com/userfiles/file/soriwumisowame.pdf
- https://expeditions-travel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607019deb71b5---kixafiwok.pdf
- http://vladjurnalist.ru/archive/file/noxozafo.pdf
- https://maxflowfans.com/userfiles/file/71289419138.pdf
- http://www.acefence.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f6af1c26a5---9419397542.pdf
- http://techscreening.com/userfiles/files/49779977573.pdf
- http://maroba-zirndorf.de/file/63092754983.pdf
- https://samarthanamparisara.org/apadmin/uploads/userfiles/files/27716183217.pdf
- https://aashianarealty.com/file/wilirutera.pdf
- http://carrozzeriardue.it/userfiles/files/45768259498.pdf
- https://universal4shipping.net/userfiles/file/gunonusebazude.pdf
- https://www.tamilsaga.com/ckfinder/userfiles/files/jezutu.pdf
- https://www.propertyfilevault.com/wp-content/plugins/super-forms/uploads/php/files/5b6304358907ecb064a390cdd910e3ba/38552926228.pdf
- https://globalclassic.org/wp-content/plugins/super-forms/uploads/php/files/nglngkhiu27mkbb0kj2vnt0ho8/gawegokizatopefera.pdf
- http://langeline.com/ckeditor/upload/files/zamixol.pdf
- http://fantasypartyentertainment.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ab793f8c516---44207735050.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cructi.ru
- www.karenlovelee.com
- muahohangnhat.com
- alexanderkanevskyartgallery.com
- climacom.eu
- arcomproltd.com
- www.chinahkcarplate.com
- animationcoach.com
- expeditions-travel.com
- vladjurnalist.ru
- maxflowfans.com
- www.acefence.com
- techscreening.com
- maroba-zirndorf.de
- samarthanamparisara.org
- aashianarealty.com
- carrozzeriardue.it
- universal4shipping.net
- www.tamilsaga.com
- www.propertyfilevault.com
- globalclassic.org
- langeline.com
- fantasypartyentertainment.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report