MALICIOUS — zekojoriwariwa.pdf
MALICIOUS — zekojoriwariwa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4f5d645fe493721711b61795e63e1f018f7b3201bf5720beb0e2da84a9fc7479 - SHA-1:
fae8152cba859a41d778bcd5ca81bca34a934956 - MD5:
fffeafd815422fb120cdc065d588d644 - ssdeep:
1536:lqPwqv7NM5rUbUTG2MEKS2nYXMbRK6kiZmkWYpO2tuGi8WXSWP7y/rOkBeE:wwqv7NMEUTFMEKFYqR420GixXc/rOa - TLSH:
T13239DFF361E7CC5CBB1B4B0785E601AC694DEA892172AB60444C767CD9BC9BEBF10940 - Submitted as: zekojoriwariwa.pdf
- File type: pdf · Size: 90591 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://uyaviation.com/wp-content/plugins/formcraft/file-upload/server/content/files/16090c6db03140---49938443984.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://uyaviation.com/wp-content/plugins/formcraft/file-upload/server/content/files/16090c6db03140---49938443984.pdf, https://sip7.pl/autoinstalator/sip7.online/wp-content/plugins/super-forms/uploads/php/files/2cda32a180a0db607c2b6cffb9e54785/dulakakirurajerofujaw.pdf, http://totaleclipsenv.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b999771512c---zafegojirulexeretad.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/GLLx1DTH0VQ/uplcv?utm_term=linux+pdf+to+text+converter
- http://uyaviation.com/wp-content/plugins/formcraft/file-upload/server/content/files/16090c6db03140---49938443984.pdf
- https://sip7.pl/autoinstalator/sip7.online/wp-content/plugins/super-forms/uploads/php/files/2cda32a180a0db607c2b6cffb9e54785/dulakakirurajerofujaw.pdf
- http://totaleclipsenv.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b999771512c---zafegojirulexeretad.pdf
- https://qualitylightsolutions.com/wp-content/plugins/super-forms/uploads/php/files/9fddf462c1e99b12646ab40b2b443154/87618445925.pdf
- https://rybczewice.pl/userfiles/file/fujikegosekoletulan.pdf
- http://www.sarajevo-inn-grunewald.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a36c629820d---kivadofurejupisap.pdf
- https://aartipalette.com/userfiles/file/taxerazuge.pdf
- https://www.hungarianassociation.com/wp-content/plugins/formcraft/file-upload/server/content/files/160875ee0c5358---modurifelaxoxanigi.pdf
- https://getadoc.in/ckfinder/userfiles/files/44946786394.pdf
- https://mfdesign.hu/files/file/10351162300.pdf
- https://messianic.live/wp-content/plugins/super-forms/uploads/php/files/95c13987b302f768d328ce763357508f/60322981050.pdf
- http://www.linkkorea.co.kr/wp-content/plugins/formcraft/file-upload/server/content/files/160ddd5ab02283---wipizozotuv.pdf
- https://carpanea.it/wp-content/plugins/super-forms/uploads/php/files/3e355cbcf4d127f632924e9bc81f0962/begexopen.pdf
- http://countrysquirefoods.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607929b79845d---zanopevebafatalo.pdf
- https://markeishahall.com/wp-content/plugins/super-forms/uploads/php/files/46db756c193686bc3d42daa885131743/67654041408.pdf
- https://theatresaucinema.fr/uploads/file/72896501277.pdf
- https://www.endthestigmacounselling.com/wp-content/plugins/super-forms/uploads/php/files/gr8r6lg81kesaun4l3eadrej8r/3414809487.pdf
- https://vernadoc.com/wp-content/plugins/super-forms/uploads/php/files/0e6100d2a099a84a60d1199051565bac/pogetos.pdf
- http://www.onlinetemsilci.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b056ea7421---gugekow.pdf
- https://lorenzonimmigrationlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16073e20a89df6---25291650522.pdf
- http://ilovegabal.net/fckeditor/_upload/file/97100991183.pdf
- http://progetec.org/userfiles/files/zirewes.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- uyaviation.com
- sip7.pl
- sip7.online
- totaleclipsenv.com
- qualitylightsolutions.com
- rybczewice.pl
- www.sarajevo-inn-grunewald.com
- aartipalette.com
- www.hungarianassociation.com
- getadoc.in
- messianic.live
- www.linkkorea.co.kr
- carpanea.it
- countrysquirefoods.com
- markeishahall.com
- theatresaucinema.fr
- www.endthestigmacounselling.com
- vernadoc.com
- www.onlinetemsilci.com
- lorenzonimmigrationlaw.com
- ilovegabal.net
- progetec.org
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report