MALICIOUS — zekegafetedijo.pdf
MALICIOUS — zekegafetedijo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bef98e957f0cd2fd1d0c46ccc9e2c4f5cbd7036e443b55f645ee040dcba74275 - SHA-1:
24d6fd7f60ade5b83d3a53aa1959e37cff6ef84c - MD5:
1ef4a836a56484348e4d067d09158b3a - ssdeep:
1536:Kit6kmiA6tgcqtkZo6PjVtTresKJUH9CdEfKtpWYpO2+WiOzzF1gcNBZkGCOhdOP:3BmiL8mpTes/2A2pzzFacNEGfPOky - TLSH:
T1CA38D0F351A7DE5C778B5B079ABB11A8644AD7CD6132EA5040CCBA6CD47CABDBE00440 - Submitted as: zekegafetedijo.pdf
- File type: pdf · Size: 81913 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.optionassurance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160737189588fa---295000581.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://idfusionllc.com/wp-content/plugins/super-forms/uploads/php/files/0a7f20107cdc1d883e9a551a7b3ab335/82529613371.pdf, http://nrnchina.com/test/images/ckfinder/files/71093361990.pdf, https://reparationmobile.net/userfiles/file/vijimusimiw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/3CAf4wW3hvY/uplcv?utm_term=r+list+loaded+packages
- https://idfusionllc.com/wp-content/plugins/super-forms/uploads/php/files/0a7f20107cdc1d883e9a551a7b3ab335/82529613371.pdf
- http://nrnchina.com/test/images/ckfinder/files/71093361990.pdf
- https://reparationmobile.net/userfiles/file/vijimusimiw.pdf
- https://autoschiller.de/wp-content/plugins/formcraft/file-upload/server/content/files/160acf0c9089a8---tutepodapaxovusiwuw.pdf
- http://harasim.cz/uploaded/files/11973916183.pdf
- https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/65b8a8bc1e4b4c1d198973ea9f6f56ce/44997049014.pdf
- http://rkmaster.ru/uploads/files/86547532140.pdf
- http://audiomaster.se/wp-content/plugins/formcraft/file-upload/server/content/files/16098a9cab47ed---dejekasepitagedakuve.pdf
- https://www.areatransfers.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ac806dba0a0---24392212265.pdf
- http://www.optionassurance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160737189588fa---295000581.pdf
- https://highrise.pl/file/13425679295.pdf
- https://sip7.pl/autoinstalator/sip7.online/wp-content/plugins/super-forms/uploads/php/files/87d51d781f8f82acf2a7f99ec1cbf23c/42513268034.pdf
- https://nusamulticentralestari.com/Uploads/userfiles/files/48356545304.pdf
- https://artsketch.ru/wp-content/plugins/super-forms/uploads/php/files/973ee38c6c150ccda3bf1287743d2603/86440734760.pdf
- http://ahsaipu.com/v15/Upload/file/202152325444857.pdf
- https://www.vibrationmonitoring.asia/wp-content/plugins/formcraft/file-upload/server/content/files/160ae3ac975a72---69689284153.pdf
- https://mebelpozakazu.ru/wp-content/plugins/super-forms/uploads/php/files/77489a9076424932bbebe0bd6b50b21a/gepefunedogujawedewikakus.pdf
- http://baschin-heizung.com/meineBilderAlbertGrundschule/file/92867457900.pdf
- https://omomediacion.com/wp-content/plugins/super-forms/uploads/php/files/e7af9e7007201f8eecc868057cbec990/livugududavizitumudam.pdf
- https://microfocus-realize2020mea.com/wp-content/plugins/super-forms/uploads/php/files/b72fc9db3b8e02d45a8ac7e3afa59a93/zebekoxobiginakebajapeze.pdf
- https://lightupalife.org.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160ac68fbc5790---62637810987.pdf
- https://www.icslights.com/wp-content/plugins/super-forms/uploads/php/files/f1f12855474d6ecf7ab8fe42c477bde8/59900303567.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- idfusionllc.com
- nrnchina.com
- reparationmobile.net
- autoschiller.de
- adbadog.com
- rkmaster.ru
- audiomaster.se
- www.areatransfers.com
- www.optionassurance.ca
- highrise.pl
- sip7.pl
- sip7.online
- nusamulticentralestari.com
- artsketch.ru
- ahsaipu.com
- www.vibrationmonitoring.asia
- mebelpozakazu.ru
- baschin-heizung.com
- omomediacion.com
- microfocus-realize2020mea.com
- lightupalife.org.uk
- www.icslights.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report