MALICIOUS — zimod.pdf
MALICIOUS — zimod.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b4faeaa428dcc8c1db61e19b02dacbe0b287d86a5660bf2a262ffb7cecd8043a - SHA-1:
64401435c203b350bd7aae4eecaa0e3f71e12bd2 - MD5:
ae11c672f21cb52a2cce277264df759a - ssdeep:
1536:vc/4q7HT8gfQN5eMD31MKdTQV7NK5FPINdk4+/oOui7y/ZwWfnN6vJIUW6pOu2Wv:k/n7TpQ3vDFBTopEFPkd3Oj7yBXo2NuF - TLSH:
T1D238D1F36297DD0C778B9B4365A70279608AD7CC2122EB50048C7B7CA5BC9BDBE14960 - Submitted as: zimod.pdf
- File type: pdf · Size: 83953 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://studiocastigli.eu/userfiles/files/nedivavixoxirogekitof.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://studiocastigli.eu/userfiles/files/nedivavixoxirogekitof.pdf, https://patriot.ch/wp-content/plugins/super-forms/uploads/php/files/05bqe919kos96tabqu7e82gppv/vogagitaji.pdf, https://wholisticvibrations.com/wp-content/plugins/super-forms/uploads/php/files/80e8712e48afe4d448b233c5c693d799/jitamemofupapek.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/A3Ryygt5BCM/uplcv?utm_term=pdf+creator+software+free+download+filehippo
- http://studiocastigli.eu/userfiles/files/nedivavixoxirogekitof.pdf
- https://patriot.ch/wp-content/plugins/super-forms/uploads/php/files/05bqe919kos96tabqu7e82gppv/vogagitaji.pdf
- https://wholisticvibrations.com/wp-content/plugins/super-forms/uploads/php/files/80e8712e48afe4d448b233c5c693d799/jitamemofupapek.pdf
- http://chsbicentennialclassof1976.com/clients/c/c2/c283bfa2537a82fb79a670aa087b4bd4/File/83032079216.pdf
- http://cherishedmomentphotos.com/clients/8/84/84fe84b553acfcd191e166b7401b6f02/File/50449084063.pdf
- https://portsidestrategies.com/wp-content/plugins/super-forms/uploads/php/files/0157256238a3e5db416aea1b032e640f/lupigutitojade.pdf
- http://linza-market.ru/upload/files/tiligifawugedikogir.pdf
- https://ph2020.org/FCKeditor/file/buliwolemukitapo.pdf
- http://gf-location.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1609a5fe9eee44---funamuxel.pdf
- http://victorylimo1.com/wp-content/plugins/formcraft/file-upload/server/content/files/160737a40e6915---51774077186.pdf
- http://artechq8.com/beta/uploads/files/tavatumuwojufevuno.pdf
- https://quangcaoxetaxi.vn/upload/fck/file/siwotutadosenufadopagorak.pdf
- http://www.deadclan.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16095f5486746c---8446133435.pdf
- http://shreejians.com/userfiles/file/96261415727.pdf
- http://dodogs.ru/sites/default/files/file/291486360.pdf
- http://dentherapia.hu/files/file/xofapavuvenimani.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/gr551f3tb1e63f86f3g5lhtan5/57155680848.pdf
- http://ndt-tl.ru/upload/file/zibupogaresesozufozi.pdf
- https://www.sudburyhighspeedinternet.ca/wp-content/plugins/super-forms/uploads/php/files/9fb46fc389372b7a1fbd233977e4e2a4/zasowezilo.pdf
- https://africanresearchcenter.com/userfiles/file/kikutesefinanukematurok.pdf
- https://www.ideaklinikizmir.com/wp-content/plugins/formcraft/file-upload/server/content/files/160761ba67e76c---30615321255.pdf
- http://posekatzahradu.cz/files/file/69877198159.pdf
- https://amirep.com/wp-content/plugins/super-forms/uploads/php/files/0a1da16f4eb79b72c6001d52d6d8b37b/85261944238.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- studiocastigli.eu
- patriot.ch
- wholisticvibrations.com
- chsbicentennialclassof1976.com
- cherishedmomentphotos.com
- portsidestrategies.com
- linza-market.ru
- ph2020.org
- gf-location.fr
- victorylimo1.com
- artechq8.com
- www.deadclan.nl
- shreejians.com
- dodogs.ru
- www.nuricomuvakfi.org
- ndt-tl.ru
- www.sudburyhighspeedinternet.ca
- africanresearchcenter.com
- www.ideaklinikizmir.com
- amirep.com
- www.w3.org
- purl.org
- ns.adobe.com
- quangcaoxetaxi.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report