MALICIOUS — ferige.pdf
MALICIOUS — ferige.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d4e25b58bc7a4b56a9f535be19cd2f4e3b57bd2bfbac379f6fc6901a1212e389 - SHA-1:
91cab075c4e41d05787d080bbc774466d185b60f - MD5:
4fccbddbf022f83ae3d4903db905a220 - ssdeep:
1536:l4VQecijSdKIKSTvfrZmPpE6MeoIUHJPoz8INRWcFnl+3g97ZWbpONfKC:6VzcijSwIKSrjZmPpE6M7KvBFl97bNH - TLSH:
T12738D0F3209BED5C72479F177AFB215CA446C2C92176EBA0119CB66C887C5BD7E00A21 - Submitted as: ferige.pdf
- File type: pdf · Size: 82774 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://mountmedpharmacy.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/16083430081a87---jijesov.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=peugeot+partner+2001+service+manual, https://albawadiroad.com/userfiles/files/julivepututatasob.pdf, http://citadelcaralarms.com/userfiles/file/85902355027.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=peugeot+partner+2001+service+manual
- https://albawadiroad.com/userfiles/files/julivepututatasob.pdf
- http://citadelcaralarms.com/userfiles/file/85902355027.pdf
- http://mountmedpharmacy.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/16083430081a87---jijesov.pdf
- http://bazatalty.pl/wp-content/plugins/super-forms/uploads/php/files/f67c0e0e9433056b957c6d403dc3375f/tariv.pdf
- https://gamepinleri.com/calisma2/files/uploads/fodegurutazegawasako.pdf
- http://gymostrov.eu/gymostrov/userfiles/file/8433391725.pdf
- http://www.injamal.es/nueva/ckfinder/userfiles/files/87561263615.pdf
- https://elsadaulte.com/ckfinder/userfiles/files/gukitufuke.pdf
- https://medgarlci.com/wp-content/plugins/super-forms/uploads/php/files/2c7907a0c4927cec3e9a5edff9c7908c/85055198106.pdf
- https://ehblending.com/wp-content/plugins/super-forms/uploads/php/files/4189b246697523cc3ca4b9553eaada3d/rufosexajuvupizumuse.pdf
- https://bbensonmft.com/wp-content/plugins/super-forms/uploads/php/files/0daf11ac54ba0f57c55f809a40238a17/50337826933.pdf
- http://ahkjt.com/upfile/file/nurufaluxemowugisabopan.pdf
- http://dabien.co.kr/wp-content/plugins/formcraft/file-upload/server/content/files/1606ef4967a11c---senizinoxarur.pdf
- https://gaseg.com/wp-content/plugins/super-forms/uploads/php/files/o3prjckecejktk249fk6nln6nt/ramamajebepuwopedegup.pdf
- http://joewhitefamilysite.com/clients/59967/File/jilon.pdf
- http://raunlarose.us/wp-content/plugins/formcraft/file-upload/server/content/files/160780bea173fa---vogumevaxinifok.pdf
- http://sieckultury.pl/wp-content/plugins/super-forms/uploads/php/files/2d2fac975c2c7a7754cfdcb99ff62b8f/87078294950.pdf
- http://antik-cafe-bergen.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609630ea9383c---relewolalegu.pdf
- http://centrons.com/uploaded/file/201114245860f2acda7d5d7.pdf
- http://padgettlawreunion.com/clients/79772/File/74311357892.pdf
- http://dagmar-e.de/userfiles/file/92037208094.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- crysiq.ru
- albawadiroad.com
- citadelcaralarms.com
- mountmedpharmacy.co.za
- bazatalty.pl
- gamepinleri.com
- gymostrov.eu
- www.injamal.es
- elsadaulte.com
- medgarlci.com
- ehblending.com
- bbensonmft.com
- ahkjt.com
- dabien.co.kr
- gaseg.com
- joewhitefamilysite.com
- raunlarose.us
- sieckultury.pl
- antik-cafe-bergen.de
- centrons.com
- padgettlawreunion.com
- dagmar-e.de
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report