MALICIOUS — zedifadazula.pdf
MALICIOUS — zedifadazula.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
73a9ee3172399cf5781dae21e8e2c3a112bee764f4f884fcdc68bd766aa2223c - SHA-1:
a302b0dbd00fcf393757f1d4e6787414278c4f5b - MD5:
88c340776f6469d3109d7ff72d2a0259 - ssdeep:
1536:5QRCkyUEQCA6dkqkYjRsd2P+TdAQjjzMKRI3o6v/CGh+joWNqIZPLrLWGpOG7/2:GRDyPQC5SX0RsdndpXwKm3/vqGh+jhgL - TLSH:
T1DC39CFF3229BDD8C7A8B5B83AAEB126D618ED7486232D69001C8F62CD5BC57C7F10541 - Submitted as: zedifadazula.pdf
- File type: pdf · Size: 89248 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://ahdjcm.com/upload/files/48152526960.pdf, https://jfefood.com/wp-content/plugins/super-forms/uploads/php/files/6c0d4b0e003ae8b924ef6301729f7329/tibumubutozofo.pdf, https://uclerbaklava.com/resources/file/65642810980.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1xuhb7AK25c/uplcv?utm_term=diocese+of+romblon
- http://ahdjcm.com/upload/files/48152526960.pdf
- https://jfefood.com/wp-content/plugins/super-forms/uploads/php/files/6c0d4b0e003ae8b924ef6301729f7329/tibumubutozofo.pdf
- https://uclerbaklava.com/resources/file/65642810980.pdf
- https://alismobile.co.uk/wp-content/plugins/super-forms/uploads/php/files/da8bc8bac6e37dc53281532fe4950217/53822610859.pdf
- https://sygimportaciones.com/wp-content/plugins/super-forms/uploads/php/files/r63mglotbri8g8i8rhhlvg32u8/fenutuvodaxim.pdf
- http://stkvn.ru/wp-content/plugins/super-forms/uploads/php/files/96a40cb340ef142299d20aab461b43ea/66925173130.pdf
- http://amoy-art.com/Upload/file/69499473221.pdf
- https://www.lindopoint.it/wp-content/plugins/super-forms/uploads/php/files/24c05c1c18505a84532a921a223dbacb/xizezozuwoxelibova.pdf
- https://visaonline-vn.com/wp-content/plugins/super-forms/uploads/php/files/38f5vtq9j3nltmd6bi6aff9ccd/18114988539.pdf
- http://www.loockuniformes.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/16071bf317419a---71310286337.pdf
- http://www.mecateengenharia.com.br/ckfinder/userfiles/files/11783922746.pdf
- https://flycam.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160f9d3fe3c030---61658446767.pdf
- http://www.ebsjosepirosamaria.com/wp-content/plugins/formcraft/file-upload/server/content/files/160dcc30233e66---9790187848.pdf
- https://alamansyria.com/userfiles/file/9791251090.pdf
- http://www.uppld.org/wp-content/plugins/formcraft/file-upload/server/content/files/1606d0bf895396---56080102642.pdf
- http://synphabase.ch/upload/file/71556968290.pdf
- http://atek-ent.com/upload/file/sawuw.pdf
- http://www.a-fairys-choice.com/wp-content/plugins/formcraft/file-upload/server/content/files/16094a1cf2cc37---31480529514.pdf
- https://kodcomputers.ro/2664/uploads/39630578108.pdf
- https://teplitsyoptom.ru/wp-content/plugins/super-forms/uploads/php/files/3db4d013206e309732683e174a818186/23348985907.pdf
- http://evabody.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1610bf4c64d539---83716933955.pdf
- https://geneolock.com/locktactyuma/userfiles/file/foben.pdf
- https://cananalimdar.com/wp-content/plugins/super-forms/uploads/php/files/gs54utpfrh5qdhs2p1i2sgh9u9/27468157553.pdf
- http://pokemom2.com/uploads/files/sogukafikewunukotadu.pdf
Embedded domains
- feedproxy.google.com
- ahdjcm.com
- jfefood.com
- uclerbaklava.com
- alismobile.co.uk
- sygimportaciones.com
- stkvn.ru
- amoy-art.com
- www.lindopoint.it
- visaonline-vn.com
- www.loockuniformes.com.br
- www.mecateengenharia.com.br
- www.ebsjosepirosamaria.com
- alamansyria.com
- www.uppld.org
- synphabase.ch
- atek-ent.com
- www.a-fairys-choice.com
- teplitsyoptom.ru
- geneolock.com
- cananalimdar.com
- pokemom2.com
- aspirans.com
- www.medipratik.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report