MALICIOUS — nojib.pdf
MALICIOUS — nojib.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
84d191723ef5c98022798d5a7936e56508791e058fb3ea6c8631fd56026fc426 - SHA-1:
d1ab21066b967d0ec404e0050db888a4549ca192 - MD5:
dd8be33cb37db7ae9e0a88f5012d0ab1 - ssdeep:
1536:ltG0MjGARMQcfUOe7kMkbiwWxlFYuhXcgWspORsmuvtMcOu:riGAVkbUFDRc7Rs1Mo - TLSH:
T18237C0F361ABCE5C775A9F0376B71059A08AD6482162EE5040487B6C8AFC5BDBF00E50 - Submitted as: nojib.pdf
- File type: pdf · Size: 72087 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://montex.pro/uploads/userfiles/file/57692605567.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://palaciodelosnavas.com/userfiles/file/mevotalubudib.pdf, http://e-kva.ru/admin/ckfinder/userfiles/files/11807485445.pdf, http://montex.pro/uploads/userfiles/file/57692605567.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/fzgW7-mxBc0/uplcv?utm_term=roku+ultra+lt+manual+pdf
- http://palaciodelosnavas.com/userfiles/file/mevotalubudib.pdf
- http://e-kva.ru/admin/ckfinder/userfiles/files/11807485445.pdf
- http://montex.pro/uploads/userfiles/file/57692605567.pdf
- http://jjw-led.com/userfiles/file/21253196932.pdf
- http://palirna-frydek.cz/uploaded/file/kisewa.pdf
- http://spbmedax.ru/sites/default/files/uploads/suwenu.pdf
- http://santehnika34.ru/images/file/34894967637.pdf
- http://ms-krmelin.cz/app/webroot/files/files/gipejofuwikezigumibik.pdf
- https://hearing-outlet.com/uploads/files/202109070654141851.pdf
- http://unseretochter.ch/images/file/63804124883.pdf
- https://fancybox.pamlskovnik.cz/ckfinder/userfiles/files/28397030105.pdf
- http://iact2001.com/userData/board/file/fumev.pdf
- http://discoveryenglish.org/wp-content/plugins/formcraft/file-upload/server/content/files/161386d1ac9234---77816148166.pdf
- http://stickers-moins-cher.com/userfiles/stickers-moins-cher.com/file/gatixezitijut.pdf
- http://culfordequestriancentre.org/UserFiles/file/tubunezubisevezoj.pdf
- https://nsstore.mx/ckeditor/ckfinder/archivossubidos/files/nujolosiwugofiroxi.pdf
- https://www.ferienhof-schneider.de/wp-content/plugins/formcraft/file-upload/server/content/files/16138a881f30ca---37122129179.pdf
- https://www.sudoku-cool.com/ckfinder/userfiles/files/butojidinejiluguladut.pdf
- https://toptenstudy.com/upload/files/BodyFile__61312BF0BF65E.pdf
- http://flagrant-desir.com/userfiles/file/85775385034.pdf
- https://cursosadistanciayonline.com/medios/files/96118819548.pdf
- https://vresponse.net/userfiles/file/68314389643.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- palaciodelosnavas.com
- e-kva.ru
- montex.pro
- jjw-led.com
- spbmedax.ru
- santehnika34.ru
- hearing-outlet.com
- unseretochter.ch
- iact2001.com
- discoveryenglish.org
- stickers-moins-cher.com
- culfordequestriancentre.org
- nsstore.mx
- www.ferienhof-schneider.de
- www.sudoku-cool.com
- toptenstudy.com
- flagrant-desir.com
- cursosadistanciayonline.com
- vresponse.net
- www.w3.org
- purl.org
- ns.adobe.com
- palirna-frydek.cz
- ms-krmelin.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report