MALICIOUS — sozaze.pdf
MALICIOUS — sozaze.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
b25174be57d034ab2095327155f1e87eeb851ce8490941f111420e1057fe1c53 - SHA-1:
110e0519fff97542f5258abd2f95b8e819890915 - MD5:
c6000a47fdad5a94d4bcef8c45c236ad - ssdeep:
1536:xNwhFyL5bnGBeQMA9nSPpMfSNzCuPdzaPabo2E5nYbYYhkKkvIW3X/3Yj6MBWwpY:WytnGBoAnSPpjNzCwAPaboj5nmYYhyv7 - TLSH:
T1FC39D1E321A7ED5CB74B9F0319AF0269A08EF7481122E69090C8B77DD4BC57D7E10951 - Submitted as: sozaze.pdf
- File type: pdf · Size: 89961 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=gov+eat+out, http://furkansigorta.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160bf1fa167d2b---17916577343.pdf, http://camel-republic.com/media/userfiles/files/guzinunevuxidaki.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=gov+eat+out
- http://furkansigorta.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160bf1fa167d2b---17916577343.pdf
- http://camel-republic.com/media/userfiles/files/guzinunevuxidaki.pdf
- https://rockdental.co.uk/wp-content/plugins/super-forms/uploads/php/files/7f5bbb52d9996c66f75f210708cefa0b/29615596764.pdf
- http://kamennykoberec.eu/editor_uploads/system/files/78303300168.pdf
- https://activepymes.com/pub/file/vuparof.pdf
- http://exmar.it/foto_fck/file/99625885436.pdf
- https://catherinehourihan.art/wp-content/plugins/super-forms/uploads/php/files/151d4438264113df8e29f94b2e1bd324/mukujov.pdf
- https://thejinglelab.com/wp-content/plugins/super-forms/uploads/php/files/0edvgjt4vhvm2v0msr3g3l587c/83194388430.pdf
- https://arerp.kr/data/file///2791899129.pdf
- https://strechybenesov.cz/content/benabifa.pdf
- https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/16095c8cbdcb81---zorafixubitiwerodewulani.pdf
- https://sumangold.net.vn/wp-content/plugins/super-forms/uploads/php/files/beklb8j58e5k1scji684rja4o3/gofufozodupujomelox.pdf
- http://barrarioservicos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1607c3ea1f0b47---66593370074.pdf
- http://www.veronicaneal.com/wp-content/plugins/formcraft/file-upload/server/content/files/1/160ddb1a085d66---rotug.pdf
- https://elicopter-de-inchiriat.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1608a7337b6567---pigizekobefutedufupagena.pdf
- https://computerzone.pk/file/dopazezozebugusokexal.pdf
- https://nikosdimos.gr/userfiles/file/gijituzikeziw.pdf
- http://www.expo-hotel.com/english/wp-content/plugins/formcraft/file-upload/server/content/files/16084e2540f390---43356211077.pdf
- http://la-roofers.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160ac2c4522109---48664823730.pdf
- http://zadonskiy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160a01333c12f6---dijipurigazefafuwojuje.pdf
- http://bertrandetgastineaudesigners.fr/userfiles/file/57019020892.pdf
- http://xn--9w3b270a7kf.kr/ckfinder/userfiles/files/xedumanovuzulajadivijunit.pdf
- http://hhcreunion.com/clients/4/43/43f38dc94a4d709fe78decf5bd9d7370/File/wukodudajizomagigomax.pdf
- http://for-rent-leuven.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d0b146e34a4---72376230559.pdf
Embedded domains
- crysiq.ru
- camel-republic.com
- rockdental.co.uk
- kamennykoberec.eu
- activepymes.com
- exmar.it
- thejinglelab.com
- arerp.kr
- nam.it
- barrarioservicos.com.br
- www.veronicaneal.com
- www.expo-hotel.com
- la-roofers.co.uk
- zadonskiy.ru
- bertrandetgastineaudesigners.fr
- xn--9w3b270a7kf.kr
- hhcreunion.com
- for-rent-leuven.com
- agendatourvietnam.com
- beytarimcilik.com
- angelcabrera.com
- www.w3.org
- purl.org
- ns.adobe.com
- furkansigorta.com.tr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report