MALICIOUS — gezizajunodeveda.pdf
MALICIOUS — gezizajunodeveda.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1b2ce62edb7b90ad792dbf2cd252058fe5f25683f6ead21169a1627ec9acd71e - SHA-1:
062a5827c9cc8ebd09262d10d85042ed0606d1a2 - MD5:
ad47d3e62792f6112c0c9c73eb3c23e4 - ssdeep:
1536:h+sXZo0+SqhfVNhUZfXk8qLbb4HLzT6Zw+s4T543gCDfo2aWfHjMFrM43WspO2ni:rSRhdNhOfXk86b4HLyZw+s/gCjo2NjME - TLSH:
T11F39E0F3259BED9C76479B03BABB0258519ED7882262DF50448CBB7D863C2BDAF04141 - Submitted as: gezizajunodeveda.pdf
- File type: pdf · Size: 86191 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://leaguengn.com/userfiles/file///22348273326.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ksboutlet.com/file/files/23134414650.pdf, http://leaguengn.com/userfiles/file///22348273326.pdf, http://getsolarnj.com/userfiles/file/miketibupuxekevizop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/6naE_Nh8_CY/uplcv?utm_term=how+to+send+app+from+mobile+to+pc
- https://ksboutlet.com/file/files/23134414650.pdf
- http://leaguengn.com/userfiles/file///22348273326.pdf
- http://getsolarnj.com/userfiles/file/miketibupuxekevizop.pdf
- http://k9careclinic.in/ckeditor/ckfinder/userfiles/files/vonenozuzapenefuba.pdf
- http://marketingnews.fr/images/file/rawisikupobavonel.pdf
- https://hongdung.vn/ckeditor/images/files/kolozawemar.pdf
- https://pametnidom.hr/pametne_kuce/userfiles/file/demewubexukomo.pdf
- http://gianniarnaudo.com/userfiles/files/80577066910.pdf
- http://sumisaedu.com/FileData/ckfinder/files/20210909_BFC97581440707F8.pdf
- https://luxm.pl/userfiles/file/77665388604.pdf
- http://np-laser.com/upload_fck/file/2021-9-8/20210908100445821674.pdf
- http://lecieldesandes.fr/ckfinder/userfiles/files/3432773546.pdf
- https://jmcoverseaspvtltd.com/uploads/files/girenijesilelid.pdf
- http://www.hausman.eu/images/wyswig_images/file/danad.pdf
- http://zenithmetals.com/files/nifososubufo.pdf
- http://chinajessie.com/seadata/data/uploads/img/file/16311078878.pdf
- http://coinproject.com/userfiles/image/file/57525272004.pdf
- http://letnipohar.cz/upload/file/20458420142.pdf
- http://www.infranetltd.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613070880cf30---22861079966.pdf
- http://gima.ge/admin/ckeditor/ckfinder/userfiles/files/sonajuzebazevokazibek.pdf
- http://emekyesiltepe.net/images_upload/files/peluvedo.pdf
- http://cnsgafgl.netsociality.com/upload/files/wokobuxurom.pdf
- http://dichvubaove.online/upload/files/repejogosavotevelalatafu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- ksboutlet.com
- leaguengn.com
- getsolarnj.com
- k9careclinic.in
- marketingnews.fr
- gianniarnaudo.com
- sumisaedu.com
- luxm.pl
- np-laser.com
- lecieldesandes.fr
- jmcoverseaspvtltd.com
- www.hausman.eu
- zenithmetals.com
- chinajessie.com
- coinproject.com
- www.infranetltd.com
- emekyesiltepe.net
- cnsgafgl.netsociality.com
- dichvubaove.online
- www.w3.org
- purl.org
- ns.adobe.com
- hongdung.vn
- pametnidom.hr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report