MALICIOUS — zovoluwizi.pdf
MALICIOUS — zovoluwizi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
cc147937e903f191d63d5fd045dfd45e0a5a00b0fed58f1fe31ae8d4ecaa65e1 - SHA-1:
40fc85ead83cd05e33c2831f5c8bb7966953e095 - MD5:
fd0eb29352e1c4ce6762f43a94f06e18 - ssdeep:
1536:8DUoz/YqLtSS6ML39M1gJBP9iioz8ylDyMuw+2cK0slDz/:GYqH62dyAs+lK0s1 - TLSH:
T1B336C0F3224FCECC7B55AB47A8E9601CB8C9D9C83270D7558888B668D9B85BCBF41540 - Submitted as: zovoluwizi.pdf
- File type: pdf · Size: 67065 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://gettraff.ru/wb?keyword=free%20fourth%20grade%20division%20worksheets, https://static1.squarespace.com/static/5fc5be7c27a199023ad675ed/t/5fc8cfdc970db930d9c9ba63/1606995937190/bojutulegasanada.pdf, https://static1.squarespace.com/static/5fc368e8c6229360ecbce8a9/t/5fc8c7fd13f8d93bf20d24df/1606993917652/maferunig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=free%20fourth%20grade%20division%20worksheets
- https://static1.squarespace.com/static/5fc5be7c27a199023ad675ed/t/5fc8cfdc970db930d9c9ba63/1606995937190/bojutulegasanada.pdf
- https://static1.squarespace.com/static/5fc368e8c6229360ecbce8a9/t/5fc8c7fd13f8d93bf20d24df/1606993917652/maferunig.pdf
- https://s3.amazonaws.com/mujesogi/weekly_meeting_room_schedule_template.pdf
- https://uploads.strikinglycdn.com/files/27738af7-21c0-4006-81e4-01ff4050181b/2015_junior_miss_pageant_nudist_cont.pdf
- https://static1.squarespace.com/static/5fc30d46116eb00e3c59ffbc/t/5fc5cfba61e25426e10172f4/1606799292508/9124019098.pdf
- https://s3.amazonaws.com/luworizesupox/katedazeranatezijuki.pdf
- https://uploads.strikinglycdn.com/files/dc8741aa-a78a-48de-aa28-e6cd4ec2fefe/76227584978.pdf
- https://s3.amazonaws.com/satudifin/46171139418.pdf
- https://tezadogiva.weebly.com/uploads/1/3/4/5/134522012/ragamaso_lewilo_rodekafe.pdf
- https://static1.squarespace.com/static/5fc2b942c6d96458362de91d/t/5fcf0775caa95a391e64934f/1607403384156/gang_war_mafia_hack_apk_download.pdf
- https://fikamuvereza.weebly.com/uploads/1/3/4/7/134754658/talowukogepas.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- static1.squarespace.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- tezadogiva.weebly.com
- fikamuvereza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report