MALICIOUS — sefejafokilupiz.pdf
MALICIOUS — sefejafokilupiz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f5f2bc1d71b46b8c57999a0fdb4fb4984e558820df69f96af29a5bee9147bd13 - SHA-1:
b407343e79548bc37d59e502a546c0e97fec7f9b - MD5:
e444f57cc14206d5faa028c39cccdb69 - ssdeep:
1536:j8WULgUm8Iw1eT6w1vZXXsZ1Fqx1h065YVQIinQxFfb9zYJLATQAOBLS2tEv5A:EfJID6KvNczFqx5YVQIGwFfb9zY1AkAW - TLSH:
T18938C0F3A0DBDE8C7A9AAF43B9A7255C509FE7C42132AB100484B61DC87C6BD6E11941 - Submitted as: sefejafokilupiz.pdf
- File type: pdf · Size: 78297 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!E444F57CC142
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/2b850016-68a5-4f25-ac3d-cc8c9cbedd0f/riwobabatoginetobosaju.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://resalured.ru/strik?utm_term=2010+chrysler+town+and+country+electrical+problems, https://cdn-cms.f-static.net/uploads/4370746/normal_604afc5ae12ce.pdf, http://kaboliwup.mypressonline.com/naziribifapar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://resalured.ru/strik?utm_term=2010+chrysler+town+and+country+electrical+problems
- https://cdn-cms.f-static.net/uploads/4370746/normal_604afc5ae12ce.pdf
- http://kaboliwup.mypressonline.com/naziribifapar.pdf
- http://solejow.myartsonline.com/how_to_create_edit_profile_page_in_wordpress.pdf
- https://uploads.strikinglycdn.com/files/2b850016-68a5-4f25-ac3d-cc8c9cbedd0f/riwobabatoginetobosaju.pdf
- https://static.s123-cdn-static.com/uploads/4404959/normal_5ffb74296b84f.pdf
- https://uploads.strikinglycdn.com/files/4281480f-86b3-4ad3-87e2-72ff873eff11/57994791821.pdf
- https://98350ace-7ac4-4f38-a9d9-579fdad8050b.filesusr.com/ugd/9b2d9b_a49964dc2cbb491da5a3afc68e402414.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4378149/normal_604558892d02b.pdf
- https://uploads.strikinglycdn.com/files/05262aa7-939a-47d2-930d-4f086425f0f3/zurumavutidigofedemepal.pdf
- http://gipebevu.atwebpages.com/7147178378.pdf
- http://ziposodepow.mywebcommunity.org/6139279034.pdf
- https://static.s123-cdn-static.com/uploads/4378379/normal_6001b9da8e9b3.pdf
- https://0df6220b-9630-4647-aab6-0d9db69b9d59.filesusr.com/ugd/8b97dd_c325d427779a460dbe6c0d3d7453b607.pdf?index=true
- http://xafopawiki.medianewsonline.com/what_comes_on_burger_king_chicken_sandwich.pdf
- https://cdn-cms.f-static.net/uploads/4373297/normal_604ebe36d2afc.pdf
- http://dapekafuxururo.myartsonline.com/adenovirus_tipo_2_canino.pdf
- https://static.s123-cdn-static.com/uploads/4417527/normal_5ff7d6531f191.pdf
- https://uploads.strikinglycdn.com/files/588ab369-7b9a-40dd-9b8c-49103452b08b/how_to_replace_ink_canon_pixma_mg2520.pdf
- https://cdn-cms.f-static.net/uploads/4419205/normal_603d1d045a0c8.pdf
- https://234a0c07-d908-4261-bb83-16b3c96a9b04.filesusr.com/ugd/73e0e6_a90c863b61e44dbd888e461f33298c80.pdf?index=true
- http://fomepufasele.atwebpages.com/life_cycle_of_malaria_plasmodium.pdf
- https://uploads.strikinglycdn.com/files/600228dc-b24c-4099-9d7d-9ffc1fe60843/vogiv.pdf
- http://gajonedorebuko.mywebcommunity.org/engineering_drawing_tools_price_in_sri_lanka.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- resalured.ru
- cdn-cms.f-static.net
- kaboliwup.mypressonline.com
- solejow.myartsonline.com
- uploads.strikinglycdn.com
- static.s123-cdn-static.com
- 98350ace-7ac4-4f38-a9d9-579fdad8050b.filesusr.com
- gipebevu.atwebpages.com
- ziposodepow.mywebcommunity.org
- 0df6220b-9630-4647-aab6-0d9db69b9d59.filesusr.com
- xafopawiki.medianewsonline.com
- dapekafuxururo.myartsonline.com
- 234a0c07-d908-4261-bb83-16b3c96a9b04.filesusr.com
- fomepufasele.atwebpages.com
- gajonedorebuko.mywebcommunity.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report