MALICIOUS — jifuwitonovejaze.pdf
MALICIOUS — jifuwitonovejaze.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
71709f3792e37f04dafee88102e34882dacf485b36f2b70864f7d59446f92c94 - SHA-1:
128449d9604445e2f0d479505d3617fb2c4ca8bf - MD5:
f02133906e1b70da6bd1c4758361584a - ssdeep:
1536:V1iyXxCc3zH/YvTHGMho0U7rqyG2jDQSFAPw5iQLMOcguN4ZWOSxqg0L207/OySG:iyXxCRTml02OyXFAPw5pLMBgvlAqg0Ln - TLSH:
T11939C0E32197CD4D779BDB93A9EB11A8E08A93846026DF5111887BBCC87C5BD7F00861 - Submitted as: jifuwitonovejaze.pdf
- File type: pdf · Size: 86912 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://adec-interiors.net/Uploads/file/mikivarubabim.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=form+4+lightsaber+combat, https://10fci.org/userfiles/file/wubevawod.pdf, http://makesrealsense.com/ckfinder/userfiles/files/82998216388.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://medvor.ru/uplcv?utm_term=form+4+lightsaber+combat
- https://10fci.org/userfiles/file/wubevawod.pdf
- http://makesrealsense.com/ckfinder/userfiles/files/82998216388.pdf
- http://czyxchem.com/upload/files/luletukavixozorinav.pdf
- https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/9dec7ab53e47dd62870fbdfb9cb916dc/ganirefekoxugepug.pdf
- https://transcendenceit.com/wp-content/plugins/super-forms/uploads/php/files/50458ed81ec1f31572c854b094797e66/gajefibudit.pdf
- http://adec-interiors.net/Uploads/file/mikivarubabim.pdf
- https://newsru.md/upload/userfiles/files/milavamegaj.pdf
- http://thailaundry.com/imgUpload/files/jaredexelis.pdf
- http://milliondollardesiclub.com/upload_files/featured/files/pugivusowetafabijom.pdf
- http://orvosvalaszto.hu/uploads/files/17979133956.pdf
- http://corporatiegids.nl/uploads/files/zamubumiwavusaxatopem.pdf
- http://bwemfjhjk.friend-match.com/upload/files/48563315557.pdf
- https://k-barrierfree.com/FileData/ckfinder/files/20210906_8281E0023BA392C4.pdf
- http://zehanbiopharma.com/upload/files/bawuxi.pdf
- http://chinahongji.com/d/files/sirodogopogopojubazu.pdf
- http://driver-jazda.pl/upload/file/toxolexurixuwo.pdf
- https://www.temtechnologies.fr/ckfinder/userfiles/files/banebabusokaminekafo.pdf
- https://gift-edu.ru/wp-content/plugins/super-forms/uploads/php/files/e52830dfef1aa2f758fd63001685075f/jubugukuzezen.pdf
- http://fsf-vastroad.com/userfiles/file/28161533027.pdf
- http://www.absolutecateringla.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f08e30ba7e---7478757554.pdf
- http://libron.pl/fckupload/assets/file/19963188208.pdf
- http://studionegrelli.it/userfiles/files/moveravekixowawimamasapu.pdf
- http://www.shjkyq.com/up_files/FCK/file/rakobukolujimajovotide.pdf
- https://tectrongim.com/uploads/files/81407154874.pdf
Embedded domains
- medvor.ru
- 10fci.org
- makesrealsense.com
- czyxchem.com
- amezdigital.com
- transcendenceit.com
- adec-interiors.net
- thailaundry.com
- milliondollardesiclub.com
- corporatiegids.nl
- bwemfjhjk.friend-match.com
- k-barrierfree.com
- zehanbiopharma.com
- chinahongji.com
- driver-jazda.pl
- www.temtechnologies.fr
- gift-edu.ru
- fsf-vastroad.com
- www.absolutecateringla.com
- libron.pl
- studionegrelli.it
- www.shjkyq.com
- tectrongim.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report