MALICIOUS — wizizamelifilek.pdf
MALICIOUS — wizizamelifilek.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dd0d4e820a77e78761e302ba26aa1f5f0a4f40883f535c6e26921052a97805ad - SHA-1:
73ab686922df3c75e0f836f5f9dfefaf0c3684bc - MD5:
53e910ec6617403fd1bff42f4c2b6cd3 - ssdeep:
1536:kxLwwM9lPcqj1rD3dy7/7qPlLbQaEWUec/WHpOvTWhK+c3SjUoFBJqcKg:KkVcqj1Ny3qPl/QLcOvUK+c3Sjz3q+ - TLSH:
T16137BFE320D7DD5C7A8B5F571AE719A8A04BE38C3522DAA0004CB77C94BCABE6F14511 - Submitted as: wizizamelifilek.pdf
- File type: pdf · Size: 75825 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://tetobox-budapest.hu/uploads/files/lutojonuveluwinivagurexe.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://orrizon.ru/images/file/zafagijiduxaromitoj.pdf, http://tetobox-budapest.hu/uploads/files/lutojonuveluwinivagurexe.pdf, https://sensormaticltd.com/app/templates/js/ckfinder/userfiles/files/91977754151.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1KS0DP0cxss/uplcv?utm_term=france+ligue+1+log
- https://orrizon.ru/images/file/zafagijiduxaromitoj.pdf
- http://tetobox-budapest.hu/uploads/files/lutojonuveluwinivagurexe.pdf
- https://sensormaticltd.com/app/templates/js/ckfinder/userfiles/files/91977754151.pdf
- https://mandalaconfeccao.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16133e627cd08f---gopoposenoveme.pdf
- http://erkerlaender.de/wp-content/plugins/formcraft/file-upload/server/content/files/1614193727f8d3---63912344469.pdf
- https://fiberglasssupplydepot.com/userfiles/files/wekixolinujef.pdf
- https://ermolino.mebel18.com/uploads/files/wepumemukexebisogirul.pdf
- https://cyberbirddog.com/userfiles/files/ramobinugukirerikap.pdf
- http://thicongdiennuocmiennam.com/uploads/files/bozapuxaw.pdf
- http://daiichilogistics.com/uploads/news_file/javomatirepeviwil.pdf
- https://siliconautomation.com/userfiles/file/dimalokine.pdf
- http://skalamatbaa.com/userfiles/file/ximamusewam.pdf
- https://smarttactic.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1614064aa45c9f---kajenexolexezitexepiga.pdf
- http://jumpinfit.it/userfiles/files/44273391235.pdf
- http://miyagi.chi-kara.net/Upload/files/21956433537.pdf
- http://trips-in.com/ckupload/files/14085418852.pdf
- http://npcbalkan.net/ckeditor/ckfinder/userfiles/files/29185372531.pdf
- http://vncdata.net/app/webroot/uploads/files/bimapobijodiniwomuwe.pdf
- http://pradakshinam.com/fck_uploads/file/rijemufigejiwometigimoxij.pdf
- https://creteservices.com/FCKeditor/userimages/file/17370459148.pdf
- http://www.luminicaambiental.com/wp-content/plugins/formcraft/file-upload/server/content/files/16130663f93eda---kojurigaruroba.pdf
- http://rcmo.ru/upload/files/jutokoj.pdf
- https://bepcongnghiepphuchung.vn/userfiles/file/tukegabipatenozajim.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- orrizon.ru
- sensormaticltd.com
- mandalaconfeccao.com.br
- erkerlaender.de
- fiberglasssupplydepot.com
- ermolino.mebel18.com
- cyberbirddog.com
- thicongdiennuocmiennam.com
- daiichilogistics.com
- siliconautomation.com
- skalamatbaa.com
- jumpinfit.it
- miyagi.chi-kara.net
- trips-in.com
- npcbalkan.net
- vncdata.net
- pradakshinam.com
- creteservices.com
- www.luminicaambiental.com
- rcmo.ru
- www.w3.org
- purl.org
- ns.adobe.com
- tetobox-budapest.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report