MALICIOUS — gerokamokex.pdf
MALICIOUS — gerokamokex.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
73b339b6c3c6f65133f8da064fb95ae679667bcdd67b92a849cbc1e11c767e14 - SHA-1:
f4f292617b6fe59a07303629bb7c27c9e0ed3c76 - MD5:
634b71708fa95de03343976e395ec7f4 - ssdeep:
1536:+xkjM/P+kWfy70KY2X4qi0XCBieXtXCnYoOOwQvYsOC56DOZC:0kMGh0uimtwkQgzCYDl - TLSH:
T18338D1F331C3EE4CBA8BAF436DE7694E618AC38C6136D6A540C8765CDA7C29E1D10614 - Submitted as: gerokamokex.pdf
- File type: pdf · Size: 82194 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!634B71708FA9
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://5a995288-ce6f-4ae3-a3e6-14272d8003db.filesusr.com/ugd/7be1cd_e7034522f5e84916b4a25433a22bbc10.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://zajinet.ru/wb?keyword=call%20of%20duty%20cold%20war%20beta, https://cdn.sqhk.co/wixefawoz/eTggWVy/rowiwurevuj.pdf, https://gutamunimidujad.weebly.com/uploads/1/3/4/6/134667749/4a9eb99dc992f6.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://zajinet.ru/wb?keyword=call%20of%20duty%20cold%20war%20beta
- https://cdn.sqhk.co/wixefawoz/eTggWVy/rowiwurevuj.pdf
- https://gutamunimidujad.weebly.com/uploads/1/3/4/6/134667749/4a9eb99dc992f6.pdf
- http://pozidijapepore.atwebpages.com/is_1400_a_good_sat_score_for_ucla.pdf
- https://5a995288-ce6f-4ae3-a3e6-14272d8003db.filesusr.com/ugd/7be1cd_e7034522f5e84916b4a25433a22bbc10.pdf?index=true
- https://xiwupezarevapo.weebly.com/uploads/1/3/2/6/132681984/zumadi.pdf
- http://rarebuzoxexovom.22web.org/bepovoxiwivivatipaguwiv.pdf
- https://8e12fe21-47c1-448c-af9e-883e7c84523b.filesusr.com/ugd/52ac5e_fca01be8b1e747459477c14e0992298f.pdf?index=true
- https://97a45c9e-1ab5-462a-bfe2-fded34b9a8b9.filesusr.com/ugd/b50c55_f6dd142812304d1f95ff21abf7f567a1.pdf?index=true
- http://devivitonewe.sportsontheweb.net/jovelemekemosesabovolug.pdf
- https://54957a25-093b-4cbd-a4f0-8eb5fea931f0.filesusr.com/ugd/8ba634_b9a29aa0280f45f5b0f9d449d1d0eff6.pdf?index=true
- https://5e54824a-8208-41b0-8aeb-7c017e8cfb46.filesusr.com/ugd/f64db8_0edeea003ac24cd296d7a6355ede088f.pdf?index=true
- https://cdn.sqhk.co/lunabati/hbATijn/die_in_100_ways_online.pdf
- https://cdn.sqhk.co/wixumenez/E5vUUij/58671800700.pdf
- https://dadazifetulo.weebly.com/uploads/1/3/0/9/130969312/5108283.pdf
- http://nepogewapiw.epizy.com/16640115240.pdf
- https://cdn.sqhk.co/toromerepowa/wlhjchc/lean_canvas_vs_business_model_canvas_deutsch.pdf
- http://tesetibixofi.epizy.com/more_than_words_uke_tabs.pdf
- http://tumafabo.22web.org/emergency_medicine_doctor_salary_ohio.pdf
- https://f0198b83-f3fe-41b4-8315-bacd7eabb238.filesusr.com/ugd/2b3f46_723cd7f61556415288544a9b2d19a7d5.pdf?index=true
- https://8ed7b8cb-9bae-4def-ad9b-66b28cd11f91.filesusr.com/ugd/740d8c_8c63373c62e84e27adf29f210442b6fe.pdf?index=true
- https://rogubofiduga.weebly.com/uploads/1/3/1/0/131069879/0a1e5cc2.pdf
- https://d52369c8-37f2-40d9-9d5f-d682b3b4a2e4.filesusr.com/ugd/6d5a7b_9eeaf567c2454dcd81b167bcbb6e67a8.pdf?index=true
- https://nonejazusedebe.weebly.com/uploads/1/3/6/0/136099570/vaxokadewaxaligi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- zajinet.ru
- cdn.sqhk.co
- gutamunimidujad.weebly.com
- pozidijapepore.atwebpages.com
- 5a995288-ce6f-4ae3-a3e6-14272d8003db.filesusr.com
- xiwupezarevapo.weebly.com
- rarebuzoxexovom.22web.org
- 8e12fe21-47c1-448c-af9e-883e7c84523b.filesusr.com
- 97a45c9e-1ab5-462a-bfe2-fded34b9a8b9.filesusr.com
- devivitonewe.sportsontheweb.net
- 54957a25-093b-4cbd-a4f0-8eb5fea931f0.filesusr.com
- 5e54824a-8208-41b0-8aeb-7c017e8cfb46.filesusr.com
- dadazifetulo.weebly.com
- nepogewapiw.epizy.com
- tesetibixofi.epizy.com
- tumafabo.22web.org
- f0198b83-f3fe-41b4-8315-bacd7eabb238.filesusr.com
- 8ed7b8cb-9bae-4def-ad9b-66b28cd11f91.filesusr.com
- rogubofiduga.weebly.com
- d52369c8-37f2-40d9-9d5f-d682b3b4a2e4.filesusr.com
- nonejazusedebe.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report