MALICIOUS — 1613d88407c8ae---nazota.pdf
MALICIOUS — 1613d88407c8ae---nazota.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7d32a879ea1e375842282170494cb61021c1152a2d613c2b596d45657cfad821 - SHA-1:
40b7301fcdb5309c80a893dcf800ed64fb7d2a48 - MD5:
c2d48fc45eac2e2fd6bfe0aa9100c9d1 - ssdeep:
1536:0LhKBz4GlH+ZYy8Sgpu9CuCqKL06Ek4B4WKHRtnT6NaWwpOSQRQ:YEBJ44JqgEk9HbnT6NNSL - TLSH:
T19639CFF3A1F7DCCC76AB9F536AFA1569A089D7CC2132D96080C4666C90BC97E7E10850 - Submitted as: 1613d88407c8ae---nazota.pdf
- File type: pdf · Size: 84935 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://sgyscom.com/upload_fck/file/2021-9-9/20210909135811514431.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://sgyscom.com/upload_fck/file/2021-9-9/20210909135811514431.pdf, https://euinsuti.ro/app/webroot/files/userfiles/files/nixutafulipubunofo.pdf, http://oreade-breche.fr/userfiles/file/bemuvutivibumopag.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BvfzZFkJO3s/uplcv?utm_term=hot+vpn+pro+apk
- http://sgyscom.com/upload_fck/file/2021-9-9/20210909135811514431.pdf
- https://euinsuti.ro/app/webroot/files/userfiles/files/nixutafulipubunofo.pdf
- http://oreade-breche.fr/userfiles/file/bemuvutivibumopag.pdf
- http://kvbm.org/pds/userfiles/files/jijepujexonoboxubusob.pdf
- http://portakalweb.net/home/portakal/public_html/ckfinder/userfiles/files/rewoselejaxevumil.pdf
- http://nayyaralidada.com/alpha/ckfinder/userfiles/files/vojupolozivumogufajo.pdf
- http://swapnakoodu.com/fck_uploads/file/60215935239.pdf
- https://jamisonfurnace.ca/userfiles/files/gapev.pdf
- http://bulk-supplies.com/userfiles/files/84535789678.pdf
- https://oneremote.ru/wp-content/plugins/super-forms/uploads/php/files/04d6bb0db56b5131fab00ff46472ee05/23536659872.pdf
- http://arcstema.com/userfiles/files/92907453596.pdf
- http://kelvista.lt/images/files/lalologozirogeburevimok.pdf
- https://darkoyunpin.com/calisma2/files/uploads/83788886861.pdf
- http://nabisori.com/userfiles/file/wetebogarozidovefubu.pdf
- http://tgroupsrl.com/userfiles/files/pebanelexufubovokanodoz.pdf
- http://cieplej.pl/imgturysta/file/23437800943.pdf
- http://awkontrakt.pl/ckfinder/userfiles/files/99176353051.pdf
- http://zhouzhuanx.com/v15/Upload/file/202197122212644.pdf
- https://gift-edu.ru/wp-content/plugins/super-forms/uploads/php/files/61a82f56eeda8f7bff3ab9b9029776fb/41707873096.pdf
- http://mrybalko.ru/files/64412396140.pdf
- https://ksi-system.pl/editorfiles/file/laratadag.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- sgyscom.com
- oreade-breche.fr
- kvbm.org
- portakalweb.net
- nayyaralidada.com
- swapnakoodu.com
- jamisonfurnace.ca
- bulk-supplies.com
- oneremote.ru
- arcstema.com
- darkoyunpin.com
- nabisori.com
- tgroupsrl.com
- cieplej.pl
- awkontrakt.pl
- zhouzhuanx.com
- gift-edu.ru
- mrybalko.ru
- ksi-system.pl
- www.w3.org
- purl.org
- ns.adobe.com
- euinsuti.ro
- kelvista.lt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report