MALICIOUS — zejajegivolovufi.pdf
MALICIOUS — zejajegivolovufi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bae101778870fdc9fdcd10cdfccb7cccfa9e5c59cc22f04314a34d13107462d5 - SHA-1:
5a718d9b98471d9f9b4a8f1af07a44396da09ccf - MD5:
71af5209b7329133bb8f84131bd622b0 - ssdeep:
1536:cVuKKAq1By3jKiGtvY7Qp8uVlmJDmkjWoyd5dS0vzv0WspO2cR96dn:zQqebvI8uVlmZmkxyd5dVv32ma - TLSH:
T13238C0F32197EE9CB7C7DB476AAE019C648FE3881561DAA00188B26CD5FC67D7B00911 - Submitted as: zejajegivolovufi.pdf
- File type: pdf · Size: 82520 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ambulatorioveterinarioilprato.eu/userfiles/files/43410959692.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=there+ain+t+no+rest+for+the+wicked, https://textosolutionslinguistiques.ca/upload/editor/file/65418752645.pdf, http://ambulatorioveterinarioilprato.eu/userfiles/files/43410959692.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pistant.ru/uplcv?utm_term=there+ain+t+no+rest+for+the+wicked
- https://textosolutionslinguistiques.ca/upload/editor/file/65418752645.pdf
- http://ambulatorioveterinarioilprato.eu/userfiles/files/43410959692.pdf
- http://2girlstrippin.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609f15ec223c2---69277188674.pdf
- http://mfplus.ba/wp-content/plugins/formcraft/file-upload/server/content/files/160845d2214d42---pomenezipakazudabevarowov.pdf
- https://rmdschoolandcollege.com/wp-content/plugins/super-forms/uploads/php/files/hq2pt57jrdnfe7ueo6m9flobq6/judoxebitusi.pdf
- https://www.jemelectric.com/wp-content/plugins/formcraft/file-upload/server/content/files/16086cfb6506fa---widapot.pdf
- https://asiabiru.com/contents//files/59495607944.pdf
- http://xyr59.com/filespath/files/20210816013823.pdf
- https://www.corridar.com/wp-content/plugins/super-forms/uploads/php/files/9kr36h8pcsl4bril2qjf7tqok5/21779757853.pdf
- http://samtekelektrik.com/files/55009681823.pdf
- https://www.frankcapassoandsons.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb8af299998---13009363124.pdf
- http://www.rlktechniek.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1609ebe986553b---82897434374.pdf
- http://cheumst.com/upload/fckeditor/file/90568799330.pdf
- https://www.davidwoodpersonnel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160946e5608fd6---nabovupilavifovel.pdf
- http://debandhelder.nl/ckfinder/userfiles/files/sifogavefilipilojufosojel.pdf
- https://www.andeanskyline.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d8e76a63ba4---56501730403.pdf
- http://aristosaigonhotel.com/uploads/files/wukalakokane.pdf
- http://hopsch.de/uploads/file/wojodakififerele.pdf
- https://vannordenvastgoed.nl/userfiles/file/boleposodoporokirojonure.pdf
- https://paymentor.nl/uploads//file/11749490174.pdf
- https://bisnismedsos.com/userfiles/file/lewavig.pdf
- http://monkey-do.net/userfiles/file/57578962676.pdf
- http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e97b91a985---59056091213.pdf
- http://zenobiacultura.it/userfiles/file///46430434550.pdf
Embedded domains
- pistant.ru
- textosolutionslinguistiques.ca
- ambulatorioveterinarioilprato.eu
- 2girlstrippin.com
- rmdschoolandcollege.com
- www.jemelectric.com
- asiabiru.com
- xyr59.com
- www.corridar.com
- samtekelektrik.com
- www.frankcapassoandsons.com
- www.rlktechniek.nl
- cheumst.com
- www.davidwoodpersonnel.com
- debandhelder.nl
- www.andeanskyline.com
- aristosaigonhotel.com
- hopsch.de
- vannordenvastgoed.nl
- paymentor.nl
- bisnismedsos.com
- monkey-do.net
- vtracauto.com
- zenobiacultura.it
- express-service-auto.fr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report