MALICIOUS — kezuruz.pdf
MALICIOUS — kezuruz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
58ba4fc5df90e84f20157e0912b4d0b9d5931494349d92a91cf75dad2ce475b0 - SHA-1:
3baf802e09bad0e257ddfa9ca248885ad1d7f323 - MD5:
a01d4e91d0e75a08c752f3cd4c379c1e - ssdeep:
1536:btuayOBUOjXkg6u3l9UXDFW6WGugYIRL2WOpOaZEWCGnUZsN75HX9U:UUUOISoXwBGu3IRLraZuMIw7Ju - TLSH:
T13538CFF77147DD4C7A9A8F0769AB156E6085C3886222EFA085CCF77C813C5BDAB00A51 - Submitted as: kezuruz.pdf
- File type: pdf · Size: 77222 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://dmn.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1613ada158a34b---41038472737.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://ayurveda-shiatsu-qigong-nice.com/upload/files/tewesobasij.pdf, http://dmn.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1613ada158a34b---41038472737.pdf, http://zpkprzemysl.pl/ckfinder/userfiles/files/56752683476.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BkSY9tpko7c/uplcv?utm_term=gta+mobile+torrent+magnet
- http://ayurveda-shiatsu-qigong-nice.com/upload/files/tewesobasij.pdf
- http://dmn.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1613ada158a34b---41038472737.pdf
- http://zpkprzemysl.pl/ckfinder/userfiles/files/56752683476.pdf
- http://beta-rc.com/upload/files/37765248317.pdf
- http://dtjxbpzx.com/filespath/files/20210919051033.pdf
- http://capriololaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/17255981314.pdf
- https://www.adcgrain.com/wp-content/plugins/super-forms/uploads/php/files/52567b853777ce78b04ab5ee2bed230d/gigawelubavazekixoseru.pdf
- https://slavica.ru/wp-content/plugins/super-forms/uploads/php/files/87cdfced3c5df119adf6ede1f148c0b8/xikavisukojovixaxakuseto.pdf
- https://responsible-tourism-alliance.com/content_file/files/gefosejasoxokawi.pdf
- https://dollarplus98.com/images/upload/files/44035604301.pdf
- http://www.synagoge-stommeln.de/ckfinder/userfiles/files/bevumu.pdf
- https://minlinart.com/archive/upload/files/fopevefenogubuwoxejorama.pdf
- https://k9-warrior.com/wp-content/plugins/super-forms/uploads/php/files/8lts8o37904i3ou64a262f711t/64742825960.pdf
- http://garderoba.sk/images/_file/wodamuxamajo.pdf
- http://marathon-gexin.com/Uploadfiles/files/96824164977.pdf
- http://datong-travel.tw/upload/ckeditor/files/20210904005403.pdf
- https://mobilaide.com/upload/editor/file/pakasefiv.pdf
- https://apartmani-mestrovic-krk.hr/files/vonorun.pdf
- http://ues-rb.ru/themes/ues-rb.ru/files/53516628141.pdf
- http://physocare.com/Images_upload/files/7719178828.pdf
- http://stalmont.eu/userfiles/file/31571155649.pdf
- https://cutletsmeat.com/wp-content/plugins/formcraft/file-upload/server/content/files/16134db2f5a2a9---togiruxibinavarujid.pdf
- https://tattica.byespresso.com/app/webroot/files/upload/files/49783209390.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- ayurveda-shiatsu-qigong-nice.com
- dmn.ca
- zpkprzemysl.pl
- beta-rc.com
- dtjxbpzx.com
- capriololaw.com
- www.adcgrain.com
- slavica.ru
- responsible-tourism-alliance.com
- dollarplus98.com
- www.synagoge-stommeln.de
- minlinart.com
- k9-warrior.com
- marathon-gexin.com
- datong-travel.tw
- mobilaide.com
- ues-rb.ru
- physocare.com
- stalmont.eu
- cutletsmeat.com
- tattica.byespresso.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report