MALICIOUS — nadimazipasajifi.pdf
MALICIOUS — nadimazipasajifi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
730d8c3a26ebd4e3e7baf92a4994aec8232bf682793afb788d22bb9e146cf769 - SHA-1:
3a1ef49e2150ba4e2f336e682392829886188cee - MD5:
a9667a8f18e590fdfcf26acf6d583148 - ssdeep:
1536:ltqC7V8athVFjp12tzzokYZE4CHIFWOpOaZEWb/oeS+nXSiu4SCXyNv:Pvh8atfw3okYZEdNaZtng4tXo - TLSH:
T14F38D0F361D7CD8C739A9B077AE710AC629AE3CC3021E660108CB76D997C9BD7A10651 - Submitted as: nadimazipasajifi.pdf
- File type: pdf · Size: 82025 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://gitteszoneklinik.dk/ckfinder/userfiles/files/navenusetid.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://irlanc.ru/uplcv?utm_term=japanese+id+card+generator, http://dalaichau.com/files/worabifemero.pdf, https://gitteszoneklinik.dk/ckfinder/userfiles/files/navenusetid.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://irlanc.ru/uplcv?utm_term=japanese+id+card+generator
- http://dalaichau.com/files/worabifemero.pdf
- https://gitteszoneklinik.dk/ckfinder/userfiles/files/navenusetid.pdf
- http://globalsublimation.net/uploadfile/files/jajopuluramemoregate.pdf
- http://fxlcd.com/upload/file/zerolurodonepoxufobur.pdf
- http://royalleasingny.com/admin/images/file/vuvifat.pdf
- http://deborahmayerlawoffices.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/tazug.pdf
- http://www.euro-fly.eu/userfiles/files/80861514892.pdf
- http://gold-carsales.com/js/upload/files/41856171380.pdf
- http://zelene-centrum.cz/webpagebuilder/ckfinder/userfiles/files/pulekigexerupivo.pdf
- https://avela.md/userfiles/file/30595730114.pdf
- http://cnmrobotics.com/files/files/87482850175.pdf
- http://www.britocunhaadvocacia.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/16133665880b25---1962233395.pdf
- https://cometsecurity.in/admin/userfiles/file/62251710310.pdf
- https://fiberglasssupplydepot.com/userfiles/file/18558964911.pdf
- http://multi-accueil.fr/ressource/site-image/files/zazovadetuzazaj.pdf
- https://fuze-pay.com/ckfinder/userfiles/files/64785488146.pdf
- https://scalper.ir/data/files/file/61219448964.pdf
- http://yuc-fac.com/uploadfiles/20210917095401.pdf
- http://trenermichal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1613c6a2c5925f---33258565264.pdf
- http://melissajacksonmd.com/wp-content/plugins/formcraft/file-upload/server/content/files/16135d891ebb24---29035533978.pdf
- http://bargiel.com.pl/ckfinder/userfiles/files/zibotaritoxo.pdf
- https://bestcaps99.com/ckfinder/userfiles/files/86705523817.pdf
- http://np-laser.com/upload_fck/file/2021-9-1/20210901210131679353.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- irlanc.ru
- dalaichau.com
- globalsublimation.net
- fxlcd.com
- royalleasingny.com
- deborahmayerlawoffices.com
- www.euro-fly.eu
- gold-carsales.com
- cnmrobotics.com
- www.britocunhaadvocacia.com.br
- cometsecurity.in
- fiberglasssupplydepot.com
- multi-accueil.fr
- fuze-pay.com
- scalper.ir
- yuc-fac.com
- trenermichal.pl
- melissajacksonmd.com
- bargiel.com.pl
- bestcaps99.com
- np-laser.com
- www.w3.org
- purl.org
- ns.adobe.com
- gitteszoneklinik.dk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report