MALICIOUS — zamufas.pdf
MALICIOUS — zamufas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6dbf475ace709dc06dd3420d51d9403afb45e4d051bfc8d4bd802e7a15ad1817 - SHA-1:
e8c19c423b5ad2daf33663301381fe0f46fda43e - MD5:
9bbf592b80a264b1470b3f45588068a2 - ssdeep:
1536:APwZxrHE+xuSUpaARcFBRpzDIFnIoy6qUYcWsiBI5Q2CvHWx/WIlzWVWapOnkEC:mgxzECSpvCBRpzDIpIoRtvo2Cvy/flz8 - TLSH:
T1A039B0F321A7CD8C739B9B0359AB1168608AF78D6173EA61048C76BCC9AC5BD7F10542 - Submitted as: zamufas.pdf
- File type: pdf · Size: 85224 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://artistalexanderkanevskywinnerinternationalaward.com/clientMedia/file/12835069328.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://garglob.ru/uplcv?utm_term=lego+flatbed+tow+truck+instructions, https://kes-stv.ru/wp-content/plugins/super-forms/uploads/php/files/f6ef5b8ca7bd022343aa0d083d39805f/lubipaxolugepoxekipas.pdf, http://eastendmediation.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/5473422604.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://garglob.ru/uplcv?utm_term=lego+flatbed+tow+truck+instructions
- https://kes-stv.ru/wp-content/plugins/super-forms/uploads/php/files/f6ef5b8ca7bd022343aa0d083d39805f/lubipaxolugepoxekipas.pdf
- http://eastendmediation.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/5473422604.pdf
- http://sntaviator.ru/ckfinder/userfiles/files/6581876919.pdf
- http://petswithlove.com/cvsprojects/SSK/Source/2.0.0/images/files/44717623062.pdf
- http://casaperferiesantamariagoretti.com/writable/public/userfiles/file/91455191047.pdf
- http://artistalexanderkanevskywinnerinternationalaward.com/clientMedia/file/12835069328.pdf
- http://iccj.jp/images/uploads/fckeditor/file/ligexavu.pdf
- http://southportrubbish.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608f5a512398c---72273928111.pdf
- http://ylgems.com/file_media/file_image/file/63622279467.pdf
- https://minervatech.work/js/ckfinder/userfiles/files/1538026483.pdf
- http://computerdoki.hu/user/file/xugiberegasuvuzurit.pdf
- http://julieesteban.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b3bcf9ab60f---sumalenal.pdf
- https://www.digitalsofts.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608663f8a5d2c---malugubunasotupoz.pdf
- https://mecaniquekd.ca/upload/file/karoxomigota.pdf
- http://www.cargeacrew.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160b41d379b4ee---10406684579.pdf
- http://skup-laptopow.com/wp-content/plugins/formcraft/file-upload/server/content/files/16079d3c82a72c---6994333060.pdf
- http://toyteepee.com/uploadfiles/file/210522171254793999h1230c.pdf
- http://koreabulk.net/userData/board/file/nadaruzirutaluzop.pdf
- https://torbay.ru/images/uploads/file/kojotesimiked.pdf
- https://audreyheselmans.com/_files/file/10651102347.pdf
- http://www.cheapmotorcycleinsurancepa.com/wp-content/plugins/super-forms/uploads/php/files/ebb3ccba8020512b3cab8fbf9adf2891/47315697100.pdf
- https://empezo.xyz/js/ckfinder/userfiles/files/lajefalofoxuvunum.pdf
- https://dfa-finanz.de/wp-content/plugins/formcraft/file-upload/server/content/files/160ba8e6b834b0---goribopepo.pdf
- https://brusroom.com/wp-content/plugins/super-forms/uploads/php/files/f860d48e5eb3994f23f1500a55046b2f/67128258912.pdf
Embedded domains
- garglob.ru
- kes-stv.ru
- eastendmediation.com
- sntaviator.ru
- petswithlove.com
- casaperferiesantamariagoretti.com
- artistalexanderkanevskywinnerinternationalaward.com
- iccj.jp
- southportrubbish.com
- ylgems.com
- minervatech.work
- julieesteban.com
- www.digitalsofts.com
- mecaniquekd.ca
- www.cargeacrew.com.br
- skup-laptopow.com
- toyteepee.com
- koreabulk.net
- torbay.ru
- audreyheselmans.com
- www.cheapmotorcycleinsurancepa.com
- empezo.xyz
- dfa-finanz.de
- brusroom.com
- vizzzio.ru
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report