MALICIOUS — zinakuvexabuv.pdf
MALICIOUS — zinakuvexabuv.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
92ab5929db1930aba1789c2654d9e48c4c131c8dfbb61c75228f8baef5e2f812 - SHA-1:
7f9e4f49334eca3b2d12ca1212d7512121cd8619 - MD5:
2f6b2001eb2e310080a1813d0e7e9399 - ssdeep:
1536:KwmWUXAhAmRolOtuanorhAdHlrIJPXIw8iWGpOKHHv7sDAWqiw1scCCWIV7:LmpAFwSHIhAdFrIJcLKnv7sDCR1scCC9 - TLSH:
T1A739C0F310D7DD4C368BDF4369AA22686446E7CC2435EA9445CCB66C987C97DBF00A90 - Submitted as: zinakuvexabuv.pdf
- File type: pdf · Size: 85752 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://justbuymeds.net/userfiles/file/guzitovovabukeje.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://szerecsengyogyszertar.hu/editor_up/97794332157.pdf, http://romanasulcikova.cz/userfiles/77407105792.pdf, http://www.christinemartin.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1608420ea144ed---28017765442.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/A3Ryygt5BCM/uplcv?utm_term=you+are+attractive
- http://szerecsengyogyszertar.hu/editor_up/97794332157.pdf
- http://romanasulcikova.cz/userfiles/77407105792.pdf
- http://www.christinemartin.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1608420ea144ed---28017765442.pdf
- http://chonburi33.com/userfiles/file/77237908505.pdf
- https://justbuymeds.net/userfiles/file/guzitovovabukeje.pdf
- https://maspacientes.es/wp-content/plugins/super-forms/uploads/php/files/141eeg2sk1g74u6nfeov9anmdp/bobel.pdf
- https://t4g.nasscomfoundation.org/wp-content/plugins/super-forms/uploads/php/files/t3qtqvf3t7gogjcd95idli0mf4/56534716513.pdf
- https://expeditions-travel.com/wp-content/plugins/formcraft/file-upload/server/content/files/16095d43323385---96984173713.pdf
- http://moveisgarciadigital.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160821e0759f8f---xobafijevusipeteraxiwumo.pdf
- http://www.yemany.com/yemfiles/files/91698334615.pdf
- https://avenirpourtous.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160ca55808457f---88215646112.pdf
- http://inwallendorf.de/userfiles/file/40919865571.pdf
- https://thealloywheelcentre.co.uk/wp-content/plugins/super-forms/uploads/php/files/76fe902a8c2dc86d26f095b1f5d82333/57723573641.pdf
- http://www.blackhillsdancecentre.com/wp-content/plugins/formcraft/file-upload/server/content/files/16083d1df0e2c2---18590376034.pdf
- http://accronline.com/userfiles/file/fuxuriwepiporuguwigiv.pdf
- https://bluebeakbranding.com/wp-content/plugins/super-forms/uploads/php/files/6aa6c2837980b05b43ad18a7d705ccfc/xibusemizovilegisadiron.pdf
- https://www.bouwenaaneensterkwerkgeversmerk.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16097af0f1607b---13249010728.pdf
- https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/f4098a5d04844bfa796e612f494d2089/71795089384.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/13ja8q5pdp4n1t1dhodlfhhrv3/labepib.pdf
- https://www.tctnanotech.com/wp-content/plugins/super-forms/uploads/php/files/ed9f301a690f6f3e465ffb161e05256a/kebopono.pdf
- http://lnianemarzenie.pl/userfiles/file/mojejalemejo.pdf
- https://www.totalblissbeauty.com.au/application/third_party/ckfinder/userfiles/files/24769315901.pdf
- http://mauchlineware.com/html/chapelstreet/web/userfiles/files/17670379248.pdf
- https://gulfb2b.com/userfiles/file/70133861151.pdf
Embedded domains
- feedproxy.google.com
- www.christinemartin.co.uk
- chonburi33.com
- justbuymeds.net
- maspacientes.es
- t4g.nasscomfoundation.org
- expeditions-travel.com
- moveisgarciadigital.com.br
- www.yemany.com
- avenirpourtous.fr
- inwallendorf.de
- thealloywheelcentre.co.uk
- www.blackhillsdancecentre.com
- accronline.com
- bluebeakbranding.com
- www.bouwenaaneensterkwerkgeversmerk.nl
- ahi.com.ua
- www.nuricomuvakfi.org
- www.tctnanotech.com
- lnianemarzenie.pl
- www.totalblissbeauty.com.au
- mauchlineware.com
- gulfb2b.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report