MALICIOUS — zaginize.pdf
MALICIOUS — zaginize.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5277e30e596cab4573e59988288875e87d7c387619db31e3b25d0cd8f19e8eb9 - SHA-1:
ec427d3e9db43c2afeefe624347e5aa9e8c664cc - MD5:
0f2340f5408ffec82e6a2e955dbe9d54 - ssdeep:
1536:w8b7iYyrH9bNn7LupS/NyQ5M7B9i82bWOpOwrKWVENEbOj6ZQLM2pgFzs:j7sTn7LuA/NJM7Bk85wr3a6Oj6iM1O - TLSH:
T1AB38CFF321E7DD0C7B8A9F437A9B1269A099D2486252FB5001C8B72CC5BC6BD7F60560 - Submitted as: zaginize.pdf
- File type: pdf · Size: 78624 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://studiopetrilli.it/userfiles/files/24767665326.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://infrive.ru/uplcv?utm_term=how+to+change+the+message+center+number+in+android, http://guowangcable.com/d/files/gobokakoganenegor.pdf, https://towa-aaa.jp/userfiles/file/fepokuzusizotixadulugafub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://infrive.ru/uplcv?utm_term=how+to+change+the+message+center+number+in+android
- http://guowangcable.com/d/files/gobokakoganenegor.pdf
- https://towa-aaa.jp/userfiles/file/fepokuzusizotixadulugafub.pdf
- http://novelinternationalschool.com/ckfinder/userfiles/files/xotik.pdf
- http://cleanking.net/userData/board/file/ruvalisavanalej.pdf
- http://atanasijornet.net/uploads/ckfinder/files/91316181613.pdf
- http://nanouklid.cz/upload/file/9051735708.pdf
- http://studiopetrilli.it/userfiles/files/24767665326.pdf
- https://nurdagihaber.com/resimler/files/76257932414.pdf
- http://eg-connect.com/uploads/editorfiles/file///sedovotabetaraneki.pdf
- http://adimhukuk.com/resimler/files/kadanovobuvibuv.pdf
- http://depcip.com/app/views/panel/ckfinder/userfiles/files/rubenuselivados.pdf
- http://mawratanews.com/armedia/uploads/files/20448279459.pdf
- http://invismortgagebroker.com/images/file/72728582538.pdf
- http://concilianavarra.com/userfiles/files/pozobiworetulezib.pdf
- http://baugeraeteverleih.de/benutzerdateien/76721704588.pdf
- https://shopexpert.com/app/webroot/files/userfiles/files/wojirutebunujuxopoxanug.pdf
- http://bamboomfi.com/htdocs/cljr/data/files/leroxuxe.pdf
- http://www.prodomasa.com/ckfinder/userfiles/files/54950561808.pdf
- https://www.c2commercial.com/wp-content/plugins/super-forms/uploads/php/files/f895ae0026608d12f79e8e93a36c7c84/tumaj.pdf
- https://panificioilcavaliere.it/userfiles/files/29985904708.pdf
- http://tecksco.com/upload/files/94695714464.pdf
- http://tns-china.cn/editor_upload_image/file/77669558783.pdf
- https://sieseam.org/userfiles/files/figabowufabax.pdf
- https://paloaltospeakerseries.com/wp-content/plugins/super-forms/uploads/php/files/bcf650204ce8637e45bbaf4b520ae20d/46617185784.pdf
Embedded domains
- infrive.ru
- guowangcable.com
- towa-aaa.jp
- novelinternationalschool.com
- cleanking.net
- atanasijornet.net
- studiopetrilli.it
- nurdagihaber.com
- eg-connect.com
- adimhukuk.com
- depcip.com
- mawratanews.com
- invismortgagebroker.com
- concilianavarra.com
- baugeraeteverleih.de
- shopexpert.com
- bamboomfi.com
- www.prodomasa.com
- www.c2commercial.com
- panificioilcavaliere.it
- tecksco.com
- tns-china.cn
- sieseam.org
- paloaltospeakerseries.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report