MALICIOUS — zixap.pdf
MALICIOUS — zixap.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4baa14829cac5f93c3d25e847ecf285b0dd2f04a04c30193099fcda2bff22410 - SHA-1:
101066e0afadea0be7aa6db0190a8b88cf331717 - MD5:
3039c05d810ef56e87488cd5683f4bbd - ssdeep:
1536:hecO9EmDTiLtrrx3t8XtSdBQbgwkLCiItLIzvVMJnDX4DX7WpBZue7W3OIABmUhK:JOjDTYtr5tStaibfVZmSJnDX4jSAeRkL - TLSH:
T13D3AD1F360A7DD4C7ACB9B43A9A6107C948EE78C2532EB514088B71CD4BC2BDBE14651 - Submitted as: zixap.pdf
- File type: pdf · Size: 96771 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://www.recetasyconsejos.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d5048b6a401---firad.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://afriqueitnews.com/wp-content/plugins/super-forms/uploads/php/files/693a2d896825620a2f89c5d97a6e3ea5/24844242615.pdf, https://www.cibaospalaser.com/wp-content/plugins/super-forms/uploads/php/files/e85p7m10dm4dneumm59lbmnt55/koduxazuvab.pdf, https://encouragingmath.com/wp-content/plugins/super-forms/uploads/php/files/b723aa54d30cd4d7b7de79af7730fc66/59223598692.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/cv9VXjIrmdE/uplcv?utm_term=animated+visuals+for+music
- https://afriqueitnews.com/wp-content/plugins/super-forms/uploads/php/files/693a2d896825620a2f89c5d97a6e3ea5/24844242615.pdf
- https://www.cibaospalaser.com/wp-content/plugins/super-forms/uploads/php/files/e85p7m10dm4dneumm59lbmnt55/koduxazuvab.pdf
- https://encouragingmath.com/wp-content/plugins/super-forms/uploads/php/files/b723aa54d30cd4d7b7de79af7730fc66/59223598692.pdf
- https://www.auditek.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16093e6cf3b95f---xifawivoledoxigamevigolum.pdf
- http://simonide.org/userfiles/file/41935988437.pdf
- http://netmode.net/app/webroot/uploads/files/4692320413.pdf
- https://vdbergelectro.nl/wp-content/plugins/super-forms/uploads/php/files/1da1f61f5f5cfcbcc2d068baa72a4f8a/mikerapirupunusakibuliri.pdf
- http://www.recetasyconsejos.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d5048b6a401---firad.pdf
- http://dagmar-e.de/userfiles/file/dokelebunikiruvipuw.pdf
- http://subventionsbetrug.de/wp-content/plugins/super-forms/uploads/php/files/f632iuucqngj4lme4sdids37ha/63653155134.pdf
- https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/160e0b5a9cd111---xosomalirilav.pdf
- https://gearforfree.com/wp-content/plugins/super-forms/uploads/php/files/lc882ap4cbbmtutvvnd1u59qkj/40227212096.pdf
- https://glosunspa.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ddb0bb2402d---70783473817.pdf
- https://gpagroup.in/wp-content/plugins/formcraft/file-upload/server/content/files/160a83e82ef13d---bobukegididopoje.pdf
- https://dollarplus98.com/images/upload/files/gopab.pdf
- https://toromecanicorodeo.com/files/93856159683.pdf
- https://ventana-sur.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b3fc124a026.pdf
- https://www.auditek.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1608588d519aa6---35943091577.pdf
- http://www.uvhk.com/wp-content/plugins/formcraft/file-upload/server/content/files/16084396185896---bofipedusokuki.pdf
- https://dezsredstvompx.ru/wp-content/plugins/super-forms/uploads/php/files/c22eee238ed42f27cd5bb1c98336da78/86520707905.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071e8ae7accd---33705116101.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- afriqueitnews.com
- www.cibaospalaser.com
- encouragingmath.com
- www.auditek.fr
- simonide.org
- netmode.net
- vdbergelectro.nl
- www.recetasyconsejos.com
- dagmar-e.de
- subventionsbetrug.de
- nam.it
- gearforfree.com
- glosunspa.com
- gpagroup.in
- dollarplus98.com
- toromecanicorodeo.com
- ventana-sur.com
- www.uvhk.com
- dezsredstvompx.ru
- www.1000ena.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report