MALICIOUS — vezadifovajafum.pdf
MALICIOUS — vezadifovajafum.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
16e8e8f8e1529abe20225b55529517f238c04b71ae50ca0d372236d47fb63f09 - SHA-1:
7ffb4bf0992798ebbf3e3159d587bb9307c76e04 - MD5:
82374b1ef0612b9f97b6d71836db8512 - ssdeep:
1536:iEomWa/dHgv+0/NHiGzSqHePHCAiaACG9W0Iz1KceWUpO7Car:E4gv9fSqreGXIzEcJ79 - TLSH:
T1C639D0F35193CC6CBB4BCF0766AB015D604ED78C5266EE508088BB9C98FC8BDB951A44 - Submitted as: vezadifovajafum.pdf
- File type: pdf · Size: 85517 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://hattrick-sports.com/wp-content/plugins/formcraft/file-upload/server/content/files/160dd60f8a7048---26842175356.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://www.cedicar.com/wp-content/plugins/formcraft/file-upload/server/content/files/16091c337a7acf---36257413276.pdf, http://rotang.net/userfiles/file/3003936743.pdf, https://readxyz.org/wp-content/plugins/super-forms/uploads/php/files/b2858b7173de447a9ae44e183f38e009/63780781700.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1xuhb7AK25c/uplcv?utm_term=english+writing+styles+pdf+download
- https://www.cedicar.com/wp-content/plugins/formcraft/file-upload/server/content/files/16091c337a7acf---36257413276.pdf
- http://rotang.net/userfiles/file/3003936743.pdf
- https://readxyz.org/wp-content/plugins/super-forms/uploads/php/files/b2858b7173de447a9ae44e183f38e009/63780781700.pdf
- https://advantagelic.com/singhania/downloads/file/22818204836.pdf
- https://neoville.ru/wp-content/plugins/super-forms/uploads/php/files/18adddab1639e1c36997e9a36ed45ae3/rifanukipovomiluba.pdf
- http://hattrick-sports.com/wp-content/plugins/formcraft/file-upload/server/content/files/160dd60f8a7048---26842175356.pdf
- https://tavio.ru/files/file/31145643014.pdf
- https://www.okcfarmersmarket.com/wp-content/plugins/super-forms/uploads/php/files/598bf0d933f38404da18734a23547212/tojizatemogu.pdf
- http://stellamaris.cz/userfiles/gasojesudem.pdf
- http://aotwresort.net/ckfinder/userfiles/files/xeruvobevolesixuxewigu.pdf
- https://kaisar168.com/contents//files/rosowenupajalofasoja.pdf
- http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16079eabf45bc7---71398258087.pdf
- https://larustt.com/upload/ckfinder/files/midabezopuvon.pdf
- https://psychologgia.pl/Upload/file/sisavizeporeroviruj.pdf
- https://bursaceviritercume.com/wp-content/plugins/formcraft/file-upload/server/content/files/16083e11c06dfa---33428460367.pdf
- https://webtraffic.ch/wp-content/plugins/super-forms/uploads/php/files/lucs626h7ednv9jg710hfgdvg2/gibofiguremidusijurezad.pdf
- https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a6cc10373b9---donur.pdf
- https://www.mybizwebsites.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b8b082ce7de---vizoturinojizaviwob.pdf
- https://brokenspoke.com/wp-content/plugins/super-forms/uploads/php/files/cc4c3bb2affaf21a4c162b27baf2d69b/6997000743.pdf
- https://zemiigori.com/uploads/file/85515517039.pdf
- http://mexvp.com/ckfinder/userfiles/files/piwijemunuxewegolojaz.pdf
- http://bike-aholic.com/UserFiles/file/kikanagi.pdf
- http://a-kamen.com/userfiles/file/lerizorulovusam.pdf
- https://ventana-sur.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d406baad79b.pdf
Embedded domains
- feedproxy.google.com
- www.cedicar.com
- rotang.net
- readxyz.org
- advantagelic.com
- neoville.ru
- hattrick-sports.com
- tavio.ru
- www.okcfarmersmarket.com
- aotwresort.net
- kaisar168.com
- prodesign31.ru
- larustt.com
- psychologgia.pl
- bursaceviritercume.com
- webtraffic.ch
- www.northamericatalk.com
- www.mybizwebsites.com
- brokenspoke.com
- zemiigori.com
- mexvp.com
- bike-aholic.com
- a-kamen.com
- ventana-sur.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report