MALICIOUS — nenejagevekawasebofuz.pdf
MALICIOUS — nenejagevekawasebofuz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d3866e7310905369cd030b92ecb1b1e4a01eb8cf1d8cbdba41840f64e6ec6ba3 - SHA-1:
1a0aa9153cd44c8b11f3f6f214a1c977fbc06c1e - MD5:
fb8613175b91c26016f4ebfb6aaad2d0 - ssdeep:
1536:A735BD4aaKfb1mmvf0aK6uB8Bez2nsQhTv1pLhWR/WkNpOPNOuiNWhqK1Nxr:i5+RS1mu46uB8BXsQhTvRLPNziGqK1n - TLSH:
T1AA39C0F360C7DE4C7A4B9F43BAAA11A8B44EC3885026D7548185B67CD97C9BDBF10901 - Submitted as: nenejagevekawasebofuz.pdf
- File type: pdf · Size: 88404 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://www.kzhep.in.ua/wp-content/plugins/super-forms/uploads/php/files/3unqn700kb5hthgnd4na95dv95/42855965803.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: http://korealabels.com/ckfinder/userfiles/files/tuzegixewiwerivisiv.pdf, https://gccpay.net/wp-content/plugins/super-forms/uploads/php/files/a2cc1afc9f1f573921771b223ade3eaa/jizavodolulibavesuwu.pdf, https://www.parkgest.ch/wp-content/plugins/formcraft/file-upload/server/content/files/16075cb342e5ef---nodepat.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/BkSY9tpko7c/uplcv?utm_term=how+to+calculate+trapezoidal+volume
- http://korealabels.com/ckfinder/userfiles/files/tuzegixewiwerivisiv.pdf
- https://gccpay.net/wp-content/plugins/super-forms/uploads/php/files/a2cc1afc9f1f573921771b223ade3eaa/jizavodolulibavesuwu.pdf
- https://www.parkgest.ch/wp-content/plugins/formcraft/file-upload/server/content/files/16075cb342e5ef---nodepat.pdf
- http://www.kzhep.in.ua/wp-content/plugins/super-forms/uploads/php/files/3unqn700kb5hthgnd4na95dv95/42855965803.pdf
- http://europeanprofservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c2b281f0770---81011074312.pdf
- https://traveltokiev.com/wp-content/plugins/super-forms/uploads/php/files/9t9ct09hiqum1gnl3uff5vtsv3/78770892371.pdf
- http://lovec.bg/root/ckfinder/userfiles/files/kalegobodedezefexumavazal.pdf
- http://componentcnc.hu/uploads/ckfinder/userfiles/files/86949086799.pdf
- https://www.cibaospalaser.com/wp-content/plugins/super-forms/uploads/php/files/p4ec0kadbtkfippuopc7hg1uic/deruvanopuporajubamoxuku.pdf
- https://webgirls-studio.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d1d2a1226d2---dikuxijuxemorasuno.pdf
- http://inewbus.com/wp-content/plugins/super-forms/uploads/php/files/82aug456t1anvk5e3e6dl63nr0/86400247459.pdf
- http://www.thebetterinsurance.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608fbb15000d0---gisufewebow.pdf
- http://www.davidwoodpersonnel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607da32f46248---49825681469.pdf
- http://onmamtour.com/FileData/ckfinder/files/20210713_C52730F084F88116.pdf
- http://tiwtactic.com/userfiles/files/riwetulelefifumomazegu.pdf
- http://ttmplus.com/userfiles/files/92837731706.pdf
- https://technok.cz/wp-content/plugins/super-forms/uploads/php/files/7dd0a99d600015df37e445b95a849c84/48924358289.pdf
- http://terapie-psi.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160a2b74a6b428---61997980381.pdf
- https://mavismanagement.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a22c573291e---nugedisukizatiga.pdf
- https://zivotzaokny.eu/res/file/88408610148.pdf
- https://cabsfromheathrow.com/userfiles/file/12717937331.pdf
- https://moniimpex.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f5bad1a4ed---62163964659.pdf
- http://www.mtpartnersfl.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d8ea04a2c5a---13240712577.pdf
- http://elitaliaweb.it/upload/file/86248110673.pdf
Embedded domains
- feedproxy.google.com
- korealabels.com
- gccpay.net
- www.parkgest.ch
- www.kzhep.in.ua
- europeanprofservices.com
- traveltokiev.com
- www.cibaospalaser.com
- webgirls-studio.com
- inewbus.com
- www.thebetterinsurance.com
- www.davidwoodpersonnel.com
- onmamtour.com
- tiwtactic.com
- ttmplus.com
- mavismanagement.com
- zivotzaokny.eu
- cabsfromheathrow.com
- moniimpex.com
- www.mtpartnersfl.com
- elitaliaweb.it
- www.w3.org
- purl.org
- ns.adobe.com
- lovec.bg
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report