MALICIOUS — zewakipekadesixilos.pdf
MALICIOUS — zewakipekadesixilos.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f51ef5dd629ffeca78fba6fadfaa1337ab8e6b579fef2354c63ada3131797b6a - SHA-1:
98cd523b3532986215b1259be58b5d3416ec4aca - MD5:
9067f774aa4991ad7a1e436caa442a9c - ssdeep:
1536:8r7e3W5VDk6MoA6pVf8frS2NGIEamUMK5JvOBPMbK2tjHnWAgchTMfofhhHJ9M90:hG5JkgAk8S2NNEaWK5JvgPMbZtjdg0Ms - TLSH:
T18B3AD0F364DBDD8C728BDB471DAB2475A08AEBC85362DAA0508CA22CD47C5BE7F10511 - Submitted as: zewakipekadesixilos.pdf
- File type: pdf · Size: 93729 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://syntra.pl/userfiles/file/mewafamunelapome.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://langumeistras.lt/i/File/sanebebofigidazolidunug.pdf, http://kochamsushi.pl/UserFiles/file/valobadapewikunikilaza.pdf, http://www.toptehnik.si/images/rewibefaneji.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/6naE_Nh8_CY/uplcv?utm_term=cool+android+auto+apps
- https://langumeistras.lt/i/File/sanebebofigidazolidunug.pdf
- http://kochamsushi.pl/UserFiles/file/valobadapewikunikilaza.pdf
- http://www.toptehnik.si/images/rewibefaneji.pdf
- http://xycrusher.com/d/files/nowosubonozetibufazut.pdf
- https://www.sgestrecho.es/wp-content/plugins/formcraft/file-upload/server/content/files/161302dc890e1b---41278772924.pdf
- http://ckrestaurantgroup.com/ckfinder/userfiles/files/96198934640.pdf
- http://syntra.pl/userfiles/file/mewafamunelapome.pdf
- https://www.hauptsache.cc/wp-content/plugins/formcraft/file-upload/server/content/files/161347970c924d---wofej.pdf
- http://divodizain.ru/ckfinder/userfiles/files/51143151597.pdf
- http://ivankotov.ru/img/lib/file/xidekuturaw.pdf
- http://beamstraffic.ae/amb/userfiles/file/48442374729.pdf
- https://dermatologie-chamonix.com/userfiles/file/xalazosoxik.pdf
- http://rvhifi.cz/files/file/48317171212.pdf
- http://kompassztuki.pl/Image/files/18222175600.pdf
- http://vinmexindia.com/uploads/19670878047.pdf
- https://worldkelo.com/wp-content/plugins/super-forms/uploads/php/files/b4873c51c847c645a8f2f43957880ed7/92297025181.pdf
- https://angel-juicer.com/FileData/ckfinder/files/20210909_CEC47C8F9BB08BEC.pdf
- http://thietkewebbacninh.com/webroot/img/files/zabegidirepebagopide.pdf
- http://abnicum.com/files/file/19528300434.pdf
- https://grandiosieventinuziali.it/filesUploads/file/13595631342.pdf
- https://thibiditrading.com/public/userupload/files/23909490509.pdf
- http://qcfloor.com/userfiles/file/wemakifewukeregujobololi.pdf
- http://ciarajewellery.com/editor_upload/file/vipojikizemokibedenimezon.pdf
- http://serextion2006.com/js/upload/files/vafuvubusovovajumujaverir.pdf
Embedded domains
- feedproxy.google.com
- kochamsushi.pl
- xycrusher.com
- www.sgestrecho.es
- ckrestaurantgroup.com
- syntra.pl
- www.hauptsache.cc
- divodizain.ru
- ivankotov.ru
- dermatologie-chamonix.com
- kompassztuki.pl
- vinmexindia.com
- worldkelo.com
- angel-juicer.com
- thietkewebbacninh.com
- abnicum.com
- grandiosieventinuziali.it
- thibiditrading.com
- qcfloor.com
- ciarajewellery.com
- serextion2006.com
- www.w3.org
- purl.org
- ns.adobe.com
- langumeistras.lt
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report