MALICIOUS — zoxuw.pdf
MALICIOUS — zoxuw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cb96a093e59ef015972959c1aec150f950d2fb335b875e3b0cd74b73c5cd5164 - SHA-1:
2af9d0ac9c9c43a314034f5ab102ab28d14fd6e3 - MD5:
6c9350193eb989001ecb1d65ce542b6e - ssdeep:
1536:fRgNQV3CsyRAaHQy41Wnll6cKO7WILwXthQqJKYM9W4f0ap9:qNiiQy4Cll6vZJKYM9nfJ9 - TLSH:
T16736D0FB7127EDCC37A65B037AB940196809E5ECB12095600488BB2CDC796FD7E20935 - Submitted as: zoxuw.pdf
- File type: pdf · Size: 67383 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbdee3108845d09244f1893/1606282802145/gasemij.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafffe.ru/wb?keyword=ultrasound%20guided%20dilation%20and%20curettage%20cpt%20code, https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbdee3108845d09244f1893/1606282802145/gasemij.pdf, https://static1.squarespace.com/static/5fc50dfce5c7695ca9b64519/t/5fc5998a145a8629dc71fa0c/1606785419054/ashokan_farewell_sheet_music.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/wb?keyword=ultrasound%20guided%20dilation%20and%20curettage%20cpt%20code
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbdee3108845d09244f1893/1606282802145/gasemij.pdf
- https://static1.squarespace.com/static/5fc50dfce5c7695ca9b64519/t/5fc5998a145a8629dc71fa0c/1606785419054/ashokan_farewell_sheet_music.pdf
- https://bizidijekivaza.weebly.com/uploads/1/3/4/5/134502856/f298e8d492.pdf
- https://buvitefano.weebly.com/uploads/1/3/4/1/134131500/d32531c0d6.pdf
- https://jononosafopobof.weebly.com/uploads/1/3/4/6/134649788/68e3d373.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbcf0da72f8b574a0f22e1c/1606217946769/data_link_layer_protocols_mcq.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5b03f8cdb769c6da300e/1606376196241/suction_cup_towel_bar_target.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf498bf81c9a2a0c9828c3/1606371724052/descendants_of_abraham_and_keturah.pdf
- https://static1.squarespace.com/static/5fc304a32e34347c70520823/t/5fc5135d3c6ccf69f3ff8650/1606751072562/osrs_f2p_firemaking_guide.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- static1.squarespace.com
- bizidijekivaza.weebly.com
- buvitefano.weebly.com
- jononosafopobof.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report