MALICIOUS — zebinagokoru.pdf
MALICIOUS — zebinagokoru.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
168c22fe6d3f793ba7f18d2a41a6b44be610b28d5710e01abd0829ba17abec86 - SHA-1:
bca7e5b2d24abe2c0cf47d881bd8782f99cbe39e - MD5:
f5d48b094d68449fa8f291df3029efef - ssdeep:
1536:J0SIXNc9QIWO+r5xNfoRyTtKxNIGAmhevDLXXKW7tLZT5Tc6vKg6hCvWPjoo:UonWO+xfoRyTtKrKDp7tLZ1txwP - TLSH:
T1593AE1F31246DD9C5B876B436AA6066C208DC78C3133E099444CB97DD4B8BBDBF24926 - Submitted as: zebinagokoru.pdf
- File type: pdf · Size: 98952 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.uppld.org/wp-content/plugins/formcraft/file-upload/server/content/files/16076a1d9a6d73---guvazowowilivatifofo.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://pixomot.ru/uplcv?utm_term=manual+de+instrucciones+maquina+de+coser+lervia+kh+4000, https://ventana-sur.com/wp-content/plugins/formcraft/file-upload/server/content/files/16084df3e23b45.pdf, https://www.skyline-recruiting.com/wp-content/plugins/super-forms/uploads/php/files/f71c405b0206404bfbc11d9bcd0a7476/lulixerisixazukerazemazu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pixomot.ru/uplcv?utm_term=manual+de+instrucciones+maquina+de+coser+lervia+kh+4000
- https://ventana-sur.com/wp-content/plugins/formcraft/file-upload/server/content/files/16084df3e23b45.pdf
- https://www.skyline-recruiting.com/wp-content/plugins/super-forms/uploads/php/files/f71c405b0206404bfbc11d9bcd0a7476/lulixerisixazukerazemazu.pdf
- http://caribsplash.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607bc45ad142a---kudimitivuweden.pdf
- https://amitadevnani.com/userfiles/file/jazusaxemogikilimoropokuz.pdf
- http://www.uppld.org/wp-content/plugins/formcraft/file-upload/server/content/files/16076a1d9a6d73---guvazowowilivatifofo.pdf
- http://refta-bg.com/userfiles/file/63217036701.pdf
- http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/16094b961a9086---zotovakilujadukorugov.pdf
- https://www.colegiodesafio.net/home/wp-content/plugins/formcraft/file-upload/server/content/files/160886e9e485e8---15218662950.pdf
- https://www.medicalart.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160a30a324b91c---dexolilodit.pdf
- https://activepymes.com/pub/file/katubusuburutusokatapezob.pdf
- https://cremeconferences.com/wp-content/plugins/super-forms/uploads/php/files/785f22813c5eb6e8835edf8310d5e251/65778101777.pdf
- https://x-software.cz/data/file/39644734205.pdf
- https://maloneslandscape.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d9e17df015---61897276125.pdf
- https://jaunimodienos.lt/wp-content/plugins/super-forms/uploads/php/files/5eu9e40oj8rgo0e2kruev270qk/tizovujujuvexag.pdf
- https://socialacademy.gr/wp-content/plugins/super-forms/uploads/php/files/11276aed6f536966e0d753c7f16be4d7/11586884070.pdf
- https://oneremote.ru/wp-content/plugins/super-forms/uploads/php/files/8884501f755d29b9cd4a44d923c844e7/88482490846.pdf
- https://www.ediliziaindustriale.com/wp-content/plugins/formcraft/file-upload/server/content/files/160705eeb76029---99767701689.pdf
- http://ildiko-szepsegszalon.hu/userfiles/file/54965910846.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- pixomot.ru
- ventana-sur.com
- www.skyline-recruiting.com
- caribsplash.org
- amitadevnani.com
- www.uppld.org
- refta-bg.com
- www.marsagri.com
- www.colegiodesafio.net
- activepymes.com
- cremeconferences.com
- maloneslandscape.com
- oneremote.ru
- www.ediliziaindustriale.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.medicalart.com.tr
- x-software.cz
- jaunimodienos.lt
- socialacademy.gr
- ildiko-szepsegszalon.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report