MALICIOUS — zujisozineg.pdf
MALICIOUS — zujisozineg.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2437625aedfdf668464718ff63492be8d987a4adac70fd58970fc75cb8b3ccc2 - SHA-1:
5826fb617245f7ea873ea7eed46c1e567d036f22 - MD5:
3c9064dcb0130f407501d0534bdb0c10 - ssdeep:
1536:Sc2or4ZI6/ipeEXljRc+Nlo7ebz1NP6noUXKWIdPjbZWmpOSUj5T9a:92G4DEeoNcGo7kP6N2d/6SUj5s - TLSH:
T19338BFF3619BDE4C76879B8364FA5158A04AE3887231EBA10188777CC47C5BDBF10962 - Submitted as: zujisozineg.pdf
- File type: pdf · Size: 83669 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://scissortailfarms.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b2279a85aec---zexil.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://hotelristorantenovecento.it/wp-content/plugins/super-forms/uploads/php/files/b4a513b34b6537f5633e78e8f6198db0/60943217035.pdf, https://broadstripe.com/wp-content/plugins/super-forms/uploads/php/files/7c9b6be4c372e46d045fcb8d294df40d/xuxem.pdf, https://alphacleanwashing.com/wp-content/plugins/super-forms/uploads/php/files/e79768dfe1bfe5dd82ff093c3e1d944f/rikozabuki.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/LPIa9PGmDLg/uplcv?utm_term=holt+mcdougal+algebra+1+practice+and+problem+solving+workbook+answers
- https://hotelristorantenovecento.it/wp-content/plugins/super-forms/uploads/php/files/b4a513b34b6537f5633e78e8f6198db0/60943217035.pdf
- https://broadstripe.com/wp-content/plugins/super-forms/uploads/php/files/7c9b6be4c372e46d045fcb8d294df40d/xuxem.pdf
- https://alphacleanwashing.com/wp-content/plugins/super-forms/uploads/php/files/e79768dfe1bfe5dd82ff093c3e1d944f/rikozabuki.pdf
- http://sh8ke.com/wp-content/plugins/formcraft/file-upload/server/content/files/16082a5014c195---fugenodugidamudegere.pdf
- http://megat.pl/uploaded/fck_files/file/43712280266.pdf
- http://kashima.cc/userfiles/file/68722707439.pdf
- http://dsagco.com/Upload/file/tipimixod.pdf
- http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/5um6rmi8g7b9sq8hdftvcggvt3/zekufemasesa.pdf
- http://dmn.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160b56347d0a09---fazixepi.pdf
- http://scissortailfarms.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b2279a85aec---zexil.pdf
- http://agendatourvietnam.com/hinhanh/file/fudutojo.pdf
- https://gbagencement.fr/uploads/file/nikutamidorabepuvusofoxe.pdf
- http://www.kevinbrooks.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1607bdda6c1572---ripelozinogefalosuwes.pdf
- https://www.criteriainvest.com.br/wp-content/plugins/super-forms/uploads/php/files/n4j6t5ph5qn97k38s8n00cji76/23084996447.pdf
- http://ytbozhuo.com/upload/file/17080913665.pdf
- http://armanetti.com/images/risegoxirafuboponume.pdf
- http://gesundimjob.at/images/content/files/lubafenezujupufos.pdf
- http://totalfinance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1608acd081547d---tuxazanoj.pdf
- http://planetamama.ru/files/file/86485463461.pdf
- https://alllegaltask.com/wp-content/plugins/super-forms/uploads/php/files/s29co0mc1ja7qancbogt2729cd/63619498765.pdf
- https://law.myvzl.com/wp-content/plugins/super-forms/uploads/php/files/kic054nifk3htgcgp64pf3gh9i/guxusoxutetumibaxen.pdf
- http://okfilm.kr/userData/board/file/57556533413.pdf
- http://loadcell.vn/Images_upload/files/20645243422.pdf
- http://www.toptehnik.si/images/35952168230.pdf
Embedded domains
- feedproxy.google.com
- hotelristorantenovecento.it
- broadstripe.com
- alphacleanwashing.com
- sh8ke.com
- megat.pl
- kashima.cc
- dsagco.com
- www.sunarnuricomuisvealisverismerkezi.com
- dmn.ca
- scissortailfarms.com
- agendatourvietnam.com
- gbagencement.fr
- www.kevinbrooks.ca
- www.criteriainvest.com.br
- ytbozhuo.com
- armanetti.com
- totalfinance.ca
- planetamama.ru
- alllegaltask.com
- law.myvzl.com
- okfilm.kr
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report