MALICIOUS — zofofefobinefelaju.pdf
MALICIOUS — zofofefobinefelaju.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a3d1fbd2f755ca671b396bfd7134c3cd7bd6a08ef71fbb8a97f3ae899b4ae45a - SHA-1:
a383e2ec3a8f2e020eda11719973bb8bac446f7c - MD5:
a8beecb82877adcc95d07fe15d2dd74c - ssdeep:
1536:lx4Cy/ALNpcBqgAcb/zkYihGxb3FZ2iDZ8L5TxYexl7HWGq+y90mUuVwWQpOCjol:/TLNSDAcvShQb3FUiDUdxCd0WVfCjo1X - TLSH:
T1B839E1F331A7ED8C77DA9F432AB610756446E6886122EB5014887B6CCC7C9BEBF04601 - Submitted as: zofofefobinefelaju.pdf
- File type: pdf · Size: 85592 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://conservationenergy.com/wp-content/plugins/formcraft/file-upload/server/content/files/16139c7c9ed76c---30015257139.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://conservationenergy.com/wp-content/plugins/formcraft/file-upload/server/content/files/16139c7c9ed76c---30015257139.pdf, http://shrlie.com/upload_fck/file/2021-9-1/20210901153155974086.pdf, http://twgo8.com/uploads/base/files/202109021309354806.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BkSY9tpko7c/uplcv?utm_term=vivavideo+pro+mod+apk+2021
- http://conservationenergy.com/wp-content/plugins/formcraft/file-upload/server/content/files/16139c7c9ed76c---30015257139.pdf
- http://shrlie.com/upload_fck/file/2021-9-1/20210901153155974086.pdf
- http://twgo8.com/uploads/base/files/202109021309354806.pdf
- https://heritagelogs.com/wp-content/plugins/super-forms/uploads/php/files/7luc569umneco30p5gfc8nq9m8/duledogules.pdf
- https://elitstroycraft.ru/source/file/pobuxodituwabojoxusugidab.pdf
- http://foto-recepty.sk/images/fotky/50289142002.pdf
- http://professional-tuner.at/uploaded/file/jakikori.pdf
- https://bank-kredit.at/ckfinder/userfiles/files/82096455335.pdf
- https://thehouseconcert.com/ckfinder/userfiles/files/vukuzezipipod.pdf
- http://splogservice.ru/content/file/ririvozetarivifubazozu.pdf
- https://tractorpulling-emmeloord.nl/upload/file/bupevapejo.pdf
- http://addon-colsman.somantec.net/ckfinder/userfiles/files/rurewenasuputegodawete.pdf
- https://thieumaunao.vn/workspace/develop/uploads/ck_upload/files/46101351581.pdf
- http://3duct.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613b504b26ca1---subaxokowonetimejokese.pdf
- http://hongshengfish.com/uploadfiles/20210914/2109141348083630321cysi31k95as.pdf
- https://renewone.de/files/titakazeretijukotizotugiw.pdf
- http://kirks-pool.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613b54859bf2f---76944823933.pdf
- https://biographiewerkstatt-singer.de/userfiles/file/luvalike.pdf
- https://kompaspt1.com/contents/files/26722075283.pdf
- http://pappteam.hu/userfiles/file/16052995540.pdf
- https://vanvoorst.info/uploaded/file/92983392192.pdf
- https://onlineadda.net/ckfinder/userfiles/files/jozufunu.pdf
- http://klenderbio.com/upload/files/69413592582.pdf
- http://cosyromania.com/media/file/68808209466.pdf
Embedded domains
- feedproxy.google.com
- conservationenergy.com
- shrlie.com
- twgo8.com
- heritagelogs.com
- elitstroycraft.ru
- thehouseconcert.com
- splogservice.ru
- tractorpulling-emmeloord.nl
- addon-colsman.somantec.net
- 3duct.com
- hongshengfish.com
- renewone.de
- kirks-pool.com
- biographiewerkstatt-singer.de
- kompaspt1.com
- vanvoorst.info
- onlineadda.net
- klenderbio.com
- cosyromania.com
- www.w3.org
- purl.org
- ns.adobe.com
- foto-recepty.sk
- professional-tuner.at
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report