MALICIOUS — zumukidalosisesud.pdf
MALICIOUS — zumukidalosisesud.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d8156eeaebdd06f1ce046b6b57ef4bf60858323ac600dcdca46a2fa2e94bd8b9 - SHA-1:
f8e653f33bfc6f7927aec6562b30d4813ff95cec - MD5:
751be9a58f70e3e5fc7d1d38b11bba43 - ssdeep:
1536:HzE6ktFqKtRBhkUThxGml7EKV2eyubTDd/qNgHI0lWpj2FmwqZqRph2Pt1TznbgD:TEtFptWAm2ECyend/qNgo0lsHcph2Vt+ - TLSH:
T18A38E1F3614BDDCCE3856F5379FA02987087C6C42076AA6054D9ABACCCBC66C6D60A50 - Submitted as: zumukidalosisesud.pdf
- File type: pdf · Size: 81805 bytes
- Verdict: malicious (75/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!751BE9A58F70
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4387056/normal_5fdf82517c437.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://druttle.ru/wb?keyword=what%20are%20the%2017%20prophetic%20books%20of%20the%20old%20testament, https://static.s123-cdn-static.com/uploads/4387056/normal_5fdf82517c437.pdf, http://sethel.xyz/fast_browser_video_downloader_private_video_saver_apkoq2kf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://druttle.ru/wb?keyword=what%20are%20the%2017%20prophetic%20books%20of%20the%20old%20testament
- https://static.s123-cdn-static.com/uploads/4387056/normal_5fdf82517c437.pdf
- http://sethel.xyz/fast_browser_video_downloader_private_video_saver_apkoq2kf.pdf
- http://helplnstagram-confirm.com/candle_ear_wax_treatment_singaporeodmqj.pdf
- http://prolac.ru/asterix_and_obelix_meet_cleopatra_parents_guide7fulw.pdf
- https://xexafuru.weebly.com/uploads/1/3/1/0/131070851/73134f35ee137a.pdf
- https://sebikiwar.weebly.com/uploads/1/3/5/9/135962157/6779734.pdf
- http://djami.ru/52754730095s6d2e.pdf
- http://com-servers.online/dizepelumisisebotigexuo7v1y.pdf
- http://goldotzyv.ru/wuronevejizexoye7l.pdf
- https://s3.amazonaws.com/padosumifubobo/canada_visa_family_information_form_signature.pdf
- https://xatotaga.weebly.com/uploads/1/3/4/7/134726025/josukanoxo.pdf
- https://s3.amazonaws.com/lizuseguwix/9505776318.pdf
- http://mon-fortuneo.best/harbor_pilot_salary_floridasaiaf.pdf
- http://markettop.pro/zimokumanamijuspwdp.pdf
- https://jezuvafu.weebly.com/uploads/1/3/5/3/135348480/darabiba.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- druttle.ru
- static.s123-cdn-static.com
- sethel.xyz
- helplnstagram-confirm.com
- prolac.ru
- xexafuru.weebly.com
- sebikiwar.weebly.com
- djami.ru
- com-servers.online
- goldotzyv.ru
- s3.amazonaws.com
- xatotaga.weebly.com
- markettop.pro
- jezuvafu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- mon-fortuneo.best
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report