MALICIOUS — nanunijitaxepijesopakojip.pdf
MALICIOUS — nanunijitaxepijesopakojip.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7af0c6c3310c98422f926322fb5a6eeb76ada1393cce99ec9b0e824307893684 - SHA-1:
874ba572eef9b8c784ea843e6c467f0f5491a7f8 - MD5:
339eff3c1ffc5d482bd849a88f569084 - ssdeep:
1536:BEICHyVNIGLzmJwmg8xe0RUSzYuTO/SNIuc+6WCah/FHuWXd/GHZ6r7AW90FFGLe:/Nu68M0WSzYcOwIuc+3Cah/F3dOHZU7e - TLSH:
T17D39CFF7626BDD1D725A9B136AF711AC2086D3886261E66001887BACC4FC8BD7F10952 - Submitted as: nanunijitaxepijesopakojip.pdf
- File type: pdf · Size: 88046 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://zit-tech.com/userfiles/files/borugaxu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://zit-tech.com/userfiles/files/borugaxu.pdf, https://terminarz.online/kosmetyczka/krakow/files/potukirexokitonabus.pdf, http://ettermanenterprises.com/ckfinder/userfiles/files/37085168728.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1KS0DP0cxss/uplcv?utm_term=animation+maker+app+for+android
- http://zit-tech.com/userfiles/files/borugaxu.pdf
- https://terminarz.online/kosmetyczka/krakow/files/potukirexokitonabus.pdf
- http://ettermanenterprises.com/ckfinder/userfiles/files/37085168728.pdf
- https://tuabogadoangel.com/wp-content/plugins/super-forms/uploads/php/files/77af3c868fb9f7c8eb981bc7e8c8462f/83179514821.pdf
- http://nfc-lampang.com/user_img/files/dipimavoka.pdf
- https://phatgiaolongan.com/upload/ckupload/files/33839936432.pdf
- https://mavibusiness.it/file/62180088725.pdf
- http://shinies.ru/img/lib/file/nebefuvesabiweris.pdf
- https://dauglita.lt/components/com_mijoshop/opencart/image/data/files/84716363134.pdf
- http://bjhtdszdh.com/v15/Upload/file/2021910239521161.pdf
- https://gencshow.com/upload/ckfinder/files/lisosel.pdf
- http://qdsenfeng.com/data/files/31279289149.pdf
- https://perfecthospitals.org/FCKeditor/file/88224249138.pdf
- http://motorlustor.net/userfiles/file/67014610033.pdf
- http://aftp.bg/userfiles/file/zededok.pdf
- http://abwingsbuffalo.com/uploads/files/41651278731.pdf
- http://artkulinaria.pl/sites/default/files/file/jerululagisamalubakisaja.pdf
- https://affordans.com/ckfinder/userfiles/files/69566278147.pdf
- http://anquocrealty.com/uploads/image/files/7246056043.pdf
- http://jtravel.clickis.kr/FileData/ckfinder/files/20210908_4FD0BA4FE5A4B3E0.pdf
- https://autotronics.vn/userfiles/file/wagil.pdf
- https://www.tai.gr/wp-content/plugins/formcraft/file-upload/server/content/files/161398060807ae---9253848533.pdf
- http://ninda.vn/userfiles/files/87904961374.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- zit-tech.com
- terminarz.online
- ettermanenterprises.com
- tuabogadoangel.com
- nfc-lampang.com
- phatgiaolongan.com
- mavibusiness.it
- shinies.ru
- bjhtdszdh.com
- gencshow.com
- qdsenfeng.com
- perfecthospitals.org
- motorlustor.net
- abwingsbuffalo.com
- artkulinaria.pl
- affordans.com
- anquocrealty.com
- jtravel.clickis.kr
- www.w3.org
- purl.org
- ns.adobe.com
- dauglita.lt
- aftp.bg
- autotronics.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report