MALICIOUS — nijogikobugituzo.pdf
MALICIOUS — nijogikobugituzo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3cf3c0a3f3f5c16821b330ebef290e4f7bc384f8d05b4c767359614821717280 - SHA-1:
ec76ef16912c91b5b60e382449266c419db3c8a6 - MD5:
af027881ca26030fabc8c6c55521c780 - ssdeep:
1536:S6wpnM0R+zYiA+0FhVxcbwqdNW7PAzxW6pOu2Jl/H6RCuKq:jwpFbFFhVCEgFzSu2Jd6IC - TLSH:
T19037C0F31297DD8C3ECB8B43ADAA11AD244BD7882262DB90544CB57CC57C6BEAF00651 - Submitted as: nijogikobugituzo.pdf
- File type: pdf · Size: 75226 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://e2ingenieros.com/ckfinder/userfiles/files/1818874423.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://alismobile.co.uk/wp-content/plugins/super-forms/uploads/php/files/9549c0b3894f9fc77e9c9595c19eb1bd/94748267103.pdf, http://zadonskiy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160987a02bd857---nufizepipeva.pdf, https://forumhotel.by/wp-content/plugins/super-forms/uploads/php/files/pc1vepjlt0ml18u167d8ennfl7/68235618254.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/GLLx1DTH0VQ/uplcv?utm_term=dental+anatomy+and+oral+physiology+pdf
- https://alismobile.co.uk/wp-content/plugins/super-forms/uploads/php/files/9549c0b3894f9fc77e9c9595c19eb1bd/94748267103.pdf
- http://zadonskiy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160987a02bd857---nufizepipeva.pdf
- https://forumhotel.by/wp-content/plugins/super-forms/uploads/php/files/pc1vepjlt0ml18u167d8ennfl7/68235618254.pdf
- http://maristaslardero.es/userfiles/file/xukuverunujepula.pdf
- https://tucsonhomewindowtint.com/wp-content/plugins/super-forms/uploads/php/files/f2cf4bb0945df538a9cadc4f91ca4954/fofamonovifilezumozapagar.pdf
- http://e2ingenieros.com/ckfinder/userfiles/files/1818874423.pdf
- https://glass-haus.ru/wp-content/plugins/super-forms/uploads/php/files/7ecfd2d54aa2f760bc8917fef394b384/zogodojulo.pdf
- http://vitacanes.com/uploads/files/49387131008.pdf
- http://jrmhandling.nl/upload/file/38357863901.pdf
- http://ekorob.pl/userfiles/file/jigesiwojisotuvevow.pdf
- https://gabconstruction.com/ckfinder/userfiles/files/bobololije.pdf
- https://mytutr.com/wp-content/plugins/super-forms/uploads/php/files/b6c744d1798a775d8c24b47255bfa545/nivazikun.pdf
- http://grandrosso.com/js/upload/files/75636605477.pdf
- https://michaels-limo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160fba54624ff6---tebafovitivusijowosujav.pdf
- https://vegas-shop.net/uploads/files/25263524623.pdf
- http://kirche-treuen.de/UserFiles/File/92793436038.pdf
- http://www.kissdocs.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1608927151f27b---8342552800.pdf
- http://www.idenet.net/wp-content/plugins/formcraft/file-upload/server/content/files/160dbfda9c37c1---4091995091.pdf
- http://jfhcoaching.com/userfiles/files/gisilolin.pdf
- https://socialchangefactory.org/wp-content/plugins/super-forms/uploads/php/files/dcf3db6ce96d82152171eaeee21cdcfc/65012793636.pdf
- http://nuitsdartistes.eu/images/file/pixexisu.pdf
- http://anhbanglaw.com/userfiles/file/57641462003.pdf
- https://pmms-online.com/assets/file/kefuvodofusotowum.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- alismobile.co.uk
- zadonskiy.ru
- maristaslardero.es
- tucsonhomewindowtint.com
- e2ingenieros.com
- glass-haus.ru
- vitacanes.com
- jrmhandling.nl
- ekorob.pl
- gabconstruction.com
- mytutr.com
- grandrosso.com
- michaels-limo.com
- vegas-shop.net
- kirche-treuen.de
- www.kissdocs.com.au
- www.idenet.net
- jfhcoaching.com
- socialchangefactory.org
- nuitsdartistes.eu
- anhbanglaw.com
- pmms-online.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report