MALICIOUS — fifiwekejoz.pdf
MALICIOUS — fifiwekejoz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9bcc673ee9c5583eac93e7be0a1cd2e80a49c07fb7fc9ae406259090065f0e29 - SHA-1:
3057fa48ed616b4334b7e66893fe2c6affe919ad - MD5:
46212a2b767aea6dc0e4ca2c03d7b71e - ssdeep:
1536:eZlJHgyVEBn6crXry2XsuN1kLEPqD4kOVwoF2zFs3Of9BjSJdn1:aTAnBrby2FNvi/YuFz0 - TLSH:
T19439E1F36157CD4C7A876B53BAF7124C708BC2897223E5B00858BB5CD46C6BDAE10692 - Submitted as: fifiwekejoz.pdf
- File type: pdf · Size: 84389 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!46212A2B767A
- Kaspersky (KVRT): HEUR:Hoax.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://lisahyatthealth.com/wp-content/plugins/formcraft/file-upload/server/content/files/160991e51f1400---lovuwoxozeninux.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://oniceh.ru/uplcv?utm_term=research+methodology+qualitative+and+quantitative, http://www.alex-vasilkov.ru/images/wisdom/file/ludaxowez.pdf, http://africanhairbraidingsalon.com/userfiles/file/vumimezuligufop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oniceh.ru/uplcv?utm_term=research+methodology+qualitative+and+quantitative
- http://www.alex-vasilkov.ru/images/wisdom/file/ludaxowez.pdf
- http://africanhairbraidingsalon.com/userfiles/file/vumimezuligufop.pdf
- https://noddy.nu/images/file/12376558271.pdf
- http://lisahyatthealth.com/wp-content/plugins/formcraft/file-upload/server/content/files/160991e51f1400---lovuwoxozeninux.pdf
- http://akgikorea.com/file_upload/fck_upfile/file/81962985123.pdf
- https://agrotehholding.ru/wp-content/plugins/super-forms/uploads/php/files/335058f96b0989255188e37d6d2ee54c/xisunamosewuwu.pdf
- http://for-rent-leuven.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a454a344c7c---raketixitozufakud.pdf
- https://davaocarrental.com/images/file/taxigenorunafog.pdf
- https://greyquotient.com/wp-content/plugins/super-forms/uploads/php/files/c6ff50ad0d902f2593211b9d0a9f095e/20705135127.pdf
- https://www.northwoodmedical.ca/wp-content/plugins/super-forms/uploads/php/files/8ja254v9vuus5ujjmd9odl27al/41964069445.pdf
- https://srp-galabau-rostock.de/wp-content/plugins/super-forms/uploads/php/files/4dtto001cu34qtlskp5798j17n/gopegipe.pdf
- http://applexin.com/ttpsea/files/file/tuwubobe.pdf
- http://discoveryenglish.org/wp-content/plugins/formcraft/file-upload/server/content/files/160a730fcda88f---giwuvekejibora.pdf
- https://communeouchamps.fr/userfiles/file/dalasepirabuditane.pdf
- http://www.birapart.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b320acd3953---53632557343.pdf
- https://ceral.pl/ceral/pliki/file/tupujajixivakugazuwoduba.pdf
- https://www.geosuiteonline.de/wp-content/plugins/formcraft/file-upload/server/content/files/1606cc1ac14f94---bezofupadutodumizuvibuk.pdf
- https://www.charityweiss.de/wp-content/plugins/formcraft/file-upload/server/content/files/1608cb288e4c65---23571892821.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- oniceh.ru
- www.alex-vasilkov.ru
- africanhairbraidingsalon.com
- lisahyatthealth.com
- akgikorea.com
- agrotehholding.ru
- for-rent-leuven.com
- davaocarrental.com
- greyquotient.com
- www.northwoodmedical.ca
- srp-galabau-rostock.de
- applexin.com
- discoveryenglish.org
- communeouchamps.fr
- www.birapart.com
- ceral.pl
- www.geosuiteonline.de
- www.charityweiss.de
- www.w3.org
- purl.org
- ns.adobe.com
- noddy.nu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report