MALICIOUS — zifigefix.pdf
MALICIOUS — zifigefix.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9277899b56ecf0a1d9e203b02c7495767a5a3ab8744a865e451ab371aa0bcce6 - SHA-1:
3f9a95bb6911ac331cb3ca487e5a3c3025d76e71 - MD5:
0564b238285ea2f3ce079b7334bbc104 - ssdeep:
1536:SSEsOE+QOktat8bLffkwVOVt55bR4wvWCjKVRpvb7uCFkHWspO2zB0:MZnktaGnXdVmt55FPRjK7pvHvk622 - TLSH:
T14338C0F36297DD9CBA4B8F0715FA10AC708AD6882572F9600188BB2CD57C6BDBF10951 - Submitted as: zifigefix.pdf
- File type: pdf · Size: 81139 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://creativesilhouettes.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16135a7d3150c7---96574932933.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://bushregenerators.net/userfiles/files/14233024090.pdf, http://onlinemidias.com/ckfinder/userfiles/files/12926548125.pdf, https://praktijk.zorglink.nl/ckfinder/userfiles/files/nugos.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/A3Ryygt5BCM/uplcv?utm_term=top+shooting+game+for+android
- https://bushregenerators.net/userfiles/files/14233024090.pdf
- http://onlinemidias.com/ckfinder/userfiles/files/12926548125.pdf
- https://praktijk.zorglink.nl/ckfinder/userfiles/files/nugos.pdf
- http://rajasthanmetals.com/userfiles/file/51809355440.pdf
- https://creativesilhouettes.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16135a7d3150c7---96574932933.pdf
- https://efsanepin.com/calisma2/files/uploads/bixeputob.pdf
- http://chulatutoracademy.com/chulatutor/ckfinder/userfiles/files/29991213671.pdf
- https://fanaf.com/article_ressources/file/dagoxavolorovigegala.pdf
- http://pngroup.pl/ckfinder/userfiles/files/46601077457.pdf
- https://wolfgang-photography.com/userfiles/files/gurunag.pdf
- https://novamakine.com/upload/ckfinder/files/furowarom.pdf
- https://www.mozartcantat.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16133a913d8bb3---23245488142.pdf
- http://massimomoroni.it/userfiles/files/tusigewenesoseba.pdf
- https://maloneslandscape.com/wp-content/plugins/formcraft/file-upload/server/content/files/16138f94b7402e---zabafikomuja.pdf
- https://nuregio.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613ea33892c6d---zisoja.pdf
- http://stilistspb.online/public/files/uploads/files/97629660636.pdf
- https://www.acta-mobilier.fr/ckfinder/userfiles/files/gobupegijiwezedew.pdf
- http://choragwica.pl/userfiles/file/15542087487.pdf
- http://laboratorioshamalab.com/userfiles/file/furinuki.pdf
- https://shinyjewellers.com/wp-content/plugins/super-forms/uploads/php/files/balebdujqu08g05uveees21b6p/6806395525.pdf
- https://dichocungtoi.com/userfiles/file/riwixarelolewafodebo.pdf
- http://rhondadejean.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/zasowewibevowires.pdf
- http://music-saikung.com/ckfinder/userfiles/files/78384389702.pdf
- https://cakesandcupcakes.net/userfiles/files/98109705067.pdf
Embedded domains
- feedproxy.google.com
- bushregenerators.net
- onlinemidias.com
- praktijk.zorglink.nl
- rajasthanmetals.com
- creativesilhouettes.ca
- efsanepin.com
- chulatutoracademy.com
- fanaf.com
- pngroup.pl
- wolfgang-photography.com
- novamakine.com
- www.mozartcantat.nl
- massimomoroni.it
- maloneslandscape.com
- nuregio.de
- stilistspb.online
- www.acta-mobilier.fr
- choragwica.pl
- laboratorioshamalab.com
- shinyjewellers.com
- dichocungtoi.com
- rhondadejean.com
- music-saikung.com
- cakesandcupcakes.net
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report