MALICIOUS — mezedi.pdf
MALICIOUS — mezedi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bda9175f56c3714f308ee2a90852a2eb0686b0dfcba54142d8ced5a752be0718 - SHA-1:
476f6860f6b98aa84f629d91ec4ee008d63d1c2c - MD5:
847642c6c05e25132e4b88e9a9919dc6 - ssdeep:
1536:neCPnCvNfL8e4R5Zc30CT/yZZbIJbkrVs0WZ1t4XQWspO2sTEElvtcWzWG8jpM/8:eCPCfLZ4R43xjynbItgCtnI72svvtPzS - TLSH:
T1A538CFF33197DD4CBB87CB53A9FA1119704AD68C1572EA905088BB2C897C6BCAF10751 - Submitted as: mezedi.pdf
- File type: pdf · Size: 84159 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://topimmigrationlawyer.org/ckfinder/userfiles/files/90743373222.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://drafthe.ru/uplcv?utm_term=ejercicios+de+palabras+agudas+llanas+y+esdrujulas+4o+primaria, https://jordan.si/dokumenti/file/23311640046.pdf, http://dogalakustik.com/depo/sayfaresim/file/xazavoxujofuziwipowedab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://drafthe.ru/uplcv?utm_term=ejercicios+de+palabras+agudas+llanas+y+esdrujulas+4o+primaria
- https://jordan.si/dokumenti/file/23311640046.pdf
- http://dogalakustik.com/depo/sayfaresim/file/xazavoxujofuziwipowedab.pdf
- http://furkansigorta.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160cc92d88e176---77535180850.pdf
- http://www.kickcommerce.com/userfiles/file/fazurixolokif.pdf
- https://trotusgrup.ro/ckfinder/userfiles/files/pafuganabumev.pdf
- http://macabrey-luthier.fr/data/Files/pelibefekaketisu.pdf
- http://topimmigrationlawyer.org/ckfinder/userfiles/files/90743373222.pdf
- https://bititechnika.com/uploads/file/tigufewarusofisiterevipus.pdf
- http://progfin.pl/userfiles/file/1480991478.pdf
- https://maharajganjtimes.com/assets/ckfinder/core/connector/php/uploads/files/16026281854.pdf
- http://mariamozharova.ru/uploads/files/92636793975.pdf
- http://joshuadacosta.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c09bf40a40d---sepenexilexor.pdf
- https://dedywiredja.com/wp-content/plugins/formcraft/file-upload/server/content/files/16079b4cfc8ec4---44749298714.pdf
- https://area5srl.it/file/tezuzejovikibabo.pdf
- https://shoreluxurylimos.com/userfiles/files/43156676224.pdf
- https://www.ciabrini-immobilier.com/wp-content/plugins/super-forms/uploads/php/files/k8uiv7cg137cb342eposqst812/nevam.pdf
- http://www.sunarpazarlama.com/wp-content/plugins/super-forms/uploads/php/files/bq72eskajk37bmbkrnbf23otb0/damokidekudifidito.pdf
- https://www.mnspineandsport.com/wp-content/plugins/super-forms/uploads/php/files/57350458e08934e2064a54e2e6b2ab27/xexezapife.pdf
- https://www.tai.gr/wp-content/plugins/formcraft/file-upload/server/content/files/160825ceeed7ec---fabumiwufodosa.pdf
- http://www.kreasoft.mx/wp-content/plugins/formcraft/file-upload/server/content/files/160a6cfce93afa---29215001734.pdf
- https://vanphongphampmc.com/upload/files/katurozidisupulovux.pdf
- http://www.marjojaspers.nl/ckfinder/userfiles/files/buzojaligavelug.pdf
- http://startmatbaa.com/userfiles/file/43454819215.pdf
- https://viajespereira.com/wp-content/plugins/formcraft/file-upload/server/content/files/160984c7f12e64---72811502924.pdf
Embedded domains
- drafthe.ru
- dogalakustik.com
- www.kickcommerce.com
- macabrey-luthier.fr
- topimmigrationlawyer.org
- bititechnika.com
- progfin.pl
- maharajganjtimes.com
- mariamozharova.ru
- joshuadacosta.com
- dedywiredja.com
- area5srl.it
- shoreluxurylimos.com
- www.ciabrini-immobilier.com
- www.sunarpazarlama.com
- www.mnspineandsport.com
- www.kreasoft.mx
- vanphongphampmc.com
- www.marjojaspers.nl
- startmatbaa.com
- viajespereira.com
- www.w3.org
- purl.org
- ns.adobe.com
- jordan.si
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report