MALICIOUS — zujekotevodet.pdf
MALICIOUS — zujekotevodet.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1c6a0d6aea0d1cb4f55483fde14e045ec40f674c1d33a39e3353caea3dd72639 - SHA-1:
d3860f7d3c097cee62fdc23f4eaaeda7245375f3 - MD5:
f29c806ace69812d10fa3358bed82a16 - ssdeep:
1536:pPVIUCd9wETvPV7BurIdjXPrvRdNHt0L9shH:pOdd9wELV4rwXbrV+k - TLSH:
T11037C0F39283DE4C6A87AB4375E5669D2449D7593132EBA00858B76CC9F82FD3F10A40 - Submitted as: zujekotevodet.pdf
- File type: pdf · Size: 70964 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F29C806ACE69
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/e1b54a28538e5c99f0ffc8603ebbf8ad/88640486643.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://timelessmebel.ru/wp-content/plugins/super-forms/uploads/php/files/87b9fcd0e8c55f7ff9390192b12dc232/80612631580.pdf, https://chicagoportablexray.com/wp-content/plugins/formcraft/file-upload/server/content/files/16098038ab402e---36344136435.pdf, http://jamoncup.es/wp-content/plugins/formcraft/file-upload/server/content/files/160708625a7f66---mavijodafal.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/ngfLrbzwjls/uplcv?utm_term=pdf+calendario+2020+mexico+para+imprimir+gratis
- http://timelessmebel.ru/wp-content/plugins/super-forms/uploads/php/files/87b9fcd0e8c55f7ff9390192b12dc232/80612631580.pdf
- https://chicagoportablexray.com/wp-content/plugins/formcraft/file-upload/server/content/files/16098038ab402e---36344136435.pdf
- http://jamoncup.es/wp-content/plugins/formcraft/file-upload/server/content/files/160708625a7f66---mavijodafal.pdf
- https://masterok-kovka.ru/wp-content/plugins/super-forms/uploads/php/files/7a680d7d4f668f7cc12bee45920bddd0/wepojebelenufuxivodop.pdf
- http://www.kmclogistics.com/wp-content/plugins/super-forms/uploads/php/files/59663e000448160006e780edc780ea17/91569895922.pdf
- https://digidatadecolombia.com/wp-content/plugins/super-forms/uploads/php/files/9e18fa6ec8b33fc9af38784e2b722b05/gibipelovisixofuzawubu.pdf
- https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/e1b54a28538e5c99f0ffc8603ebbf8ad/88640486643.pdf
- https://chicagoportablexray.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b620ec5d23---76138083784.pdf
- http://www.telsercom.com/wp-content/plugins/formcraft/file-upload/server/content/files/160829bc488a1d---kuliduta.pdf
- http://eko-inwest.eu/upload/file/72545814578.pdf
- http://neodev.space/wp-content/plugins/formcraft/file-upload/server/content/files/1608219a331a69---pirikirotozi.pdf
- https://biothiennam.com/media/ftp/file/wuforozadapopofasiwa.pdf
- https://www.sharpeningfactory.com/wp-content/plugins/formcraft/file-upload/server/content/files/160928cf4b8faa---98195478021.pdf
- http://accronline.com/userfiles/file/75700514202.pdf
- http://drinkandshrink.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160aaaff060095---47224414252.pdf
- http://www.franklinwebdesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a2ccdcad320---fagavoku.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- feedproxy.google.com
- timelessmebel.ru
- chicagoportablexray.com
- jamoncup.es
- masterok-kovka.ru
- www.kmclogistics.com
- digidatadecolombia.com
- alenakovalchuk.ru
- www.telsercom.com
- eko-inwest.eu
- neodev.space
- biothiennam.com
- www.sharpeningfactory.com
- accronline.com
- drinkandshrink.co.uk
- www.franklinwebdesign.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report