MALICIOUS — jifume.pdf
MALICIOUS — jifume.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
9e7d625bd8b21847463b432d1a8e7da698dd33d6e9c3d1fafccdeba285c2b288 - SHA-1:
a89cc34596ae260a3f1a138eb6f307f74ab31787 - MD5:
2ea27b997ceac8a7a6d4bafd0df43508 - ssdeep:
1536:8Xg7cztu6zyDXt9NQc6o+Cmo7BTYazM2o71WObyJyh7ABg0Q2WspORhlxw+:v7czAqyNeoJ7BTYaz5Avb3h/0QpRrL - TLSH:
T1F839C0F722A7DD5C775B8B039AB711AD944BE3942231EB9000887B7CC5BC9BD6B20550 - Submitted as: jifume.pdf
- File type: pdf · Size: 84901 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://celeb.huh.hu/UserFiles/File/ridegasunas.pdf, http://104408017.linker.tw/files/sezadukasaziruxivodoz.pdf, http://screen.by/images/file/98449246062.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=ml+adventure+mod+apk+2020
- http://celeb.huh.hu/UserFiles/File/ridegasunas.pdf
- http://104408017.linker.tw/files/sezadukasaziruxivodoz.pdf
- http://screen.by/images/file/98449246062.pdf
- https://drainscovers.com/wp-content/plugins/super-forms/uploads/php/files/327177a0c8881ba214b82cd81704b26e/xokilaxokedekogif.pdf
- http://www.ncstarim.com.tr/wp-content/plugins/super-forms/uploads/php/files/ilrr13jbcia0rnebuh87kqfnc5/gokunurum.pdf
- https://avphunter.ro/ckfinder/userfiles/files/sajaritukuzuno.pdf
- http://kd-council.com/upfile/files/45943640891.pdf
- http://yokohama-model.com/userfiles/files/koril.pdf
- http://mcserpenti.com/userfiles/file/32675781213.pdf
- http://piqiso.ru/userfiles/file/bexajagur.pdf
- https://piti.leaddeehub.com/userfiles/files/wefuzuvajerujobalefamez.pdf
- http://studiogaleazzo.eu/userfiles/files/14818931411.pdf
- http://salonlomi.pl/wp-content/plugins/formcraft/file-upload/server/content/files/161332fee6a48f---nujavek.pdf
- http://pomelieagency.com/userfiles/files/rabag.pdf
- https://www.capitalroofingct.com/wp-content/plugins/formcraft/file-upload/server/content/files/16139fe13ce662---58662134879.pdf
- http://szermgrt.hu/uploads/ckfinder/userfiles/files/ranajofurufukarobawagot.pdf
- http://lauraestetica.com/userfiles/files/rudolivuxerenemozubi.pdf
- http://almawred-sy.com/files/adminfiles/files/xijewoj.pdf
- http://nazycakes.com/userfiles/file/55284252734.pdf
- https://magyar-logyogyasz.hu/fileok/file/25355560795.pdf
- https://amkboiler.com/wp-content/plugins/super-forms/uploads/php/files/4ru2nj36uk8toul3mvj6nkg44i/98998289730.pdf
- http://le-lemniscus-incandescent.fr/ckeditor/upload/files/54144736940.pdf
- http://asu78.ru/userfiles/file/45426209065.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- 104408017.linker.tw
- drainscovers.com
- kd-council.com
- yokohama-model.com
- mcserpenti.com
- piqiso.ru
- piti.leaddeehub.com
- studiogaleazzo.eu
- salonlomi.pl
- pomelieagency.com
- www.capitalroofingct.com
- lauraestetica.com
- almawred-sy.com
- nazycakes.com
- amkboiler.com
- le-lemniscus-incandescent.fr
- asu78.ru
- www.w3.org
- purl.org
- ns.adobe.com
- celeb.huh.hu
- screen.by
- www.ncstarim.com.tr
- avphunter.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report