MALICIOUS — zabujido.pdf
MALICIOUS — zabujido.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
734b5c5e19b1092abd77b2d379692dd50dfa8ed116697e081bb8ce4f79490c81 - SHA-1:
2cca11af239f6339e803c2c798514a3e5c3b4cbc - MD5:
c58c8cc657f25eb73e3a73cf839a6413 - ssdeep:
1536:LkLplIr6q87R+kcf9qtli38jO8+WTaaWOpOwrY2M+4X9WZSBt4dmM:2lzt7R+Lf9QlieO8r2PwrY5XISBCL - TLSH:
T12D38BFF72197DD8C364ECB1369EB149CA08EE7891262DA60408CB67DC4BCABE7E00551 - Submitted as: zabujido.pdf
- File type: pdf · Size: 83969 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://videoacceso.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612382036777e---maropubapowojuwem.pdf, http://sylvianapoles.com/clients/e/e6/e63d90d46a840f0b3195f531cec11f6e/File/45097980842.pdf, http://fmi.lu/userfiles/files/43366807311.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/6naE_Nh8_CY/uplcv?utm_term=articles+worksheet+class+2
- http://videoacceso.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612382036777e---maropubapowojuwem.pdf
- http://sylvianapoles.com/clients/e/e6/e63d90d46a840f0b3195f531cec11f6e/File/45097980842.pdf
- http://fmi.lu/userfiles/files/43366807311.pdf
- https://perleyparish.org/wp-content/plugins/super-forms/uploads/php/files/3af7ac08f2e4e513c056047097205c55/49197213087.pdf
- http://endustriyelkiralama.com/wp-content/plugins/super-forms/uploads/php/files/adr3ddmfo0c3dmubu3tqkouhos/jalibapolamadekinarum.pdf
- https://phoenixknights.co.uk/wp-content/plugins/super-forms/uploads/php/files/3a533f2b51a6046a7c0672b2487dfcd2/bikemap.pdf
- http://www.sunarpazarlama.com/wp-content/plugins/super-forms/uploads/php/files/j6bc2p4adaaafmsoupd67vr133/fagimabusigekipoturom.pdf
- http://dansecyr.ca/pdf/file/48167223669.pdf
- http://gmicropilotes.com/uploads/files/beturotezufefesetixipewu.pdf
- http://es-umzuege-transporte.de/wp-content/plugins/super-forms/uploads/php/files/3e3424bd985f1b8403ba27ebe7277701/riluwedenodisufu.pdf
- https://digireg.se/upload/sizigetikatojev.pdf
- http://namhungholdings.com/uploads/ckfinder/files/janofamenimezebewadas.pdf
- https://www.colegiodesafio.net/home/wp-content/plugins/formcraft/file-upload/server/content/files/1606cc19c8b890---fugikujonimapijonigasodu.pdf
- https://www.lowdoc-loans.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16093f701dd09f---86630898266.pdf
- http://drentmedischadvies.nl/uploads/files/xolazebizokiko.pdf
- http://edu-family72.ru/content/images/uploads/file/96265387204.pdf
- http://halongbaycruises.org/upload/files/6511489877.pdf
- https://ilc.ua/wp-content/plugins/super-forms/uploads/php/files/apql2dv6kf2fahagjtj41r6np7/57167939999.pdf
- https://bednidhitraders.com/userfiles/file/najeludiz.pdf
- http://agriturismoilnoceto.com/userfiles/files/52899987214.pdf
- https://motoquadro.de/userfiles/file/20602766231.pdf
- https://kantankacreative.com/wp-content/plugins/super-forms/uploads/php/files/6b75cd9f9d9fed96d4b6d0afc8673543/wolototoronexuzadaziloxe.pdf
- http://ceomit.com/fckupload/file/58807378057.pdf
- http://goldnumber.info/userfiles/file/14396528557.pdf
Embedded domains
- feedproxy.google.com
- videoacceso.com
- sylvianapoles.com
- perleyparish.org
- endustriyelkiralama.com
- phoenixknights.co.uk
- www.sunarpazarlama.com
- dansecyr.ca
- gmicropilotes.com
- es-umzuege-transporte.de
- digireg.se
- namhungholdings.com
- www.colegiodesafio.net
- www.lowdoc-loans.com.au
- drentmedischadvies.nl
- edu-family72.ru
- halongbaycruises.org
- ilc.ua
- bednidhitraders.com
- agriturismoilnoceto.com
- motoquadro.de
- kantankacreative.com
- ceomit.com
- goldnumber.info
- tecsal.com.br
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report