MALICIOUS — mawitumuzezonafigadafi.pdf
MALICIOUS — mawitumuzezonafigadafi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
86d11ab04ea75369f6020c85154cc2385f7cd0f74962e0f28f28dca5624cd92d - SHA-1:
03904b8617bbbd96f07c19bacccb25790912caf5 - MD5:
4d67686a1388d549f2330695460f44a9 - ssdeep:
1536:9zHdm4kcwA8mdThik6u2tH7MmmyTbztso/j3SW8pO+gWPZTiy+X7MJ:jQAXPTSH7MBuzB/D9+3ZTitXq - TLSH:
T16837AFF731DBDD9C7A8BD74369A72158544AE78841329BA00088BB7CC53C6BE7F10A50 - Submitted as: mawitumuzezonafigadafi.pdf
- File type: pdf · Size: 72467 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://smalternatywa.pl/media/upload/files/77b761d4a81f88f34fcf9ff7ab76587b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://jrpst.pl/userfiles/file/41232385350.pdf, http://ros.by/ckfinder/userfiles/files/jonaxixivizepedomumam.pdf, http://ksklinika.ru/ckfinder/userfiles/files/67625810790.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/3vuEKuznOb8/uplcv?utm_term=how+to+increase+internet+speed+in+android+phone
- http://jrpst.pl/userfiles/file/41232385350.pdf
- http://ros.by/ckfinder/userfiles/files/jonaxixivizepedomumam.pdf
- http://ksklinika.ru/ckfinder/userfiles/files/67625810790.pdf
- http://www.coverseg.com/uploads/ckfinder/files/34748050217.pdf
- https://htapigroup3.com/contents/files/66448373833.pdf
- http://smalternatywa.pl/media/upload/files/77b761d4a81f88f34fcf9ff7ab76587b.pdf
- https://bf-pomosch.ru/wp-content/plugins/super-forms/uploads/php/files/si2n3if954oj7jkid6aa6jc0f0/borazixoteni.pdf
- http://winfielddeli.com/ckfinder/userfiles/files/muxofifefubus.pdf
- https://hydratrend.com/application/third_party/ckfinder/userfiles/files/65842803056.pdf
- https://projekt-lesen.de/userfiles/file/rusasenonemipozebuviluvob.pdf
- http://imoroz.by/upload/file/tijatilusedifosemiroriju.pdf
- http://tongchangkj.com/uploadfile/file///2021092423185072.pdf
- http://hoteldanang.com/uploads/images/files/gakokulimukezanugipukuba.pdf
- http://tacchigroup.com/public/thread/risorse/file/44683229609.pdf
- http://www.sunaryem.com.tr/wp-content/plugins/super-forms/uploads/php/files/q28atjms9jea6r9mnmhr8mak22/68904425093.pdf
- http://tw-jia.com/uploads/files/202109190629067279.pdf
- https://elitstroycraft.ru/source/file/bozesefanuv.pdf
- http://phdpecs.hu/userfiles/files/36466485737.pdf
- https://torgradio.ru/new/files/file/varenuromegifalenasoruvog.pdf
- http://clairerolo.com/userfiles/file/waxuwefamanelasune.pdf
- http://norilskgu.ru/userfiles/file/21337492488.pdf
- http://fmdscu.net/userfiles/file/wilunomejotovefufedot.pdf
- https://31app.com/userfiles/file/57695087351.pdf
- https://stomatoloska-ordinacija-rijeka.com/files/regazopaxula.pdf
Embedded domains
- feedproxy.google.com
- jrpst.pl
- ksklinika.ru
- www.coverseg.com
- htapigroup3.com
- smalternatywa.pl
- bf-pomosch.ru
- winfielddeli.com
- hydratrend.com
- projekt-lesen.de
- tongchangkj.com
- hoteldanang.com
- tacchigroup.com
- tw-jia.com
- elitstroycraft.ru
- torgradio.ru
- clairerolo.com
- norilskgu.ru
- fmdscu.net
- 31app.com
- stomatoloska-ordinacija-rijeka.com
- irina-beha.com
- verynailscm.com
- sampoernastrategic.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report