MALICIOUS — zenomazageberami.pdf
MALICIOUS — zenomazageberami.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 6 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fc8272a5c8409712de39ee7adf77c9435b5deb5a96633a4296cc017357c36a3e - SHA-1:
9cfd923a2029321ff8ffed526a543a3c092a2b84 - MD5:
88ea37657f11651207c0b6b72fe0dd50 - ssdeep:
1536:Vf6XtRqkRcMRIUI61Ape5UCsGave+LkVg8k6PSP4b9:sXakRTRf/1ApQJGW+kVg8Q+ - TLSH:
T14F38C0F36097DC4C7A8B5F43ACEB296C64D8D3C862339B554444366CC478ABE6E60631 - Submitted as: zenomazageberami.pdf
- File type: pdf · Size: 80104 bytes
- Verdict: malicious (94/100)
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!88EA37657F11
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://22e365c6-0853-42e1-82f8-83473bf9c0bf.filesusr.com/ugd/217d68_0b6866a5c0fd448b91b4f4b5d8ef9c8a.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://raxegujanamefas.atwebpages.com/how_to_play_mastermind_rogue.pdf, https://22e365c6-0853-42e1-82f8-83473bf9c0bf.filesusr.com/ugd/217d68_0b6866a5c0fd448b91b4f4b5d8ef9c8a.pdf?index=true, http://vevaxogejaz.scienceontheweb.net/waiting_for_godot_beckett.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/bQ3nTxENlgE/wb?keyword=acting%20for%20animators%204%20pdf
- http://raxegujanamefas.atwebpages.com/how_to_play_mastermind_rogue.pdf
- https://22e365c6-0853-42e1-82f8-83473bf9c0bf.filesusr.com/ugd/217d68_0b6866a5c0fd448b91b4f4b5d8ef9c8a.pdf?index=true
- http://vevaxogejaz.scienceontheweb.net/waiting_for_godot_beckett.pdf
- https://9b704b87-3668-414c-a24e-b30400fe0e33.filesusr.com/ugd/51c472_466cd9016fd54012a5b9784025e7dd68.pdf?index=true
- https://cdn.sqhk.co/winanuwumovu/3gcutPN/94977036558.pdf
- http://tesar-krd.ru/4537874090sr9n9.pdf
- http://idealica-it.website/finding_the_area_of_compound_shapes_worksheetobiy0.pdf
- https://9f9bd9fa-00fe-4673-b34e-9a629881f524.filesusr.com/ugd/09273f_b4eb41e78c99445b97d861a0216cbafa.pdf?index=true
- http://hotita.space/how_to_promote_bilingualismmpqpe.pdf
- http://lamejix.scienceontheweb.net/nevada_durable_power_of_attorney_form.pdf
- https://cdn.sqhk.co/wezupobuwab/NsijXic/1920x1080_anime_wallpaper_4k.pdf
- https://e222b685-7c7f-4cee-b050-218328c89257.filesusr.com/ugd/c0232f_7a66477260d94afeb2acae4b8a676cfd.pdf?index=true
- http://kigaruzolalo.mypressonline.com/folopow.pdf
- https://84daacc9-7e90-4c5d-b1ed-526950900c49.filesusr.com/ugd/73f3b0_2eb33963ca5d4823991518cd0652349b.pdf?index=true
- http://nenegifivujaxu.mypressonline.com/buchanan_biochemistry_and_molecular_biology_of_plants.pdf
- http://genolewedusu.myartsonline.com/ethical_conduct_in_the_workplace.pdf
- https://4779f2f8-a33e-4327-9c78-21ee0bcf4620.filesusr.com/ugd/31bf02_60e9dc44f8ce41feab99bb3536390ef6.pdf?index=true
- https://78fa80b2-8629-447b-ad63-53e91e8d4948.filesusr.com/ugd/8f02de_ab65148ceaa54583ba769ebf5371d6d1.pdf?index=true
- http://tefetuzuzip.myartsonline.com/61250925960.pdf
- http://mukanebesiva.atwebpages.com/microwave_turntable_not_turning_and_not_heating.pdf
- http://lezeninimi.medianewsonline.com/pajomozurevugow.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- raxegujanamefas.atwebpages.com
- 22e365c6-0853-42e1-82f8-83473bf9c0bf.filesusr.com
- vevaxogejaz.scienceontheweb.net
- 9b704b87-3668-414c-a24e-b30400fe0e33.filesusr.com
- cdn.sqhk.co
- tesar-krd.ru
- 9f9bd9fa-00fe-4673-b34e-9a629881f524.filesusr.com
- hotita.space
- lamejix.scienceontheweb.net
- e222b685-7c7f-4cee-b050-218328c89257.filesusr.com
- kigaruzolalo.mypressonline.com
- 84daacc9-7e90-4c5d-b1ed-526950900c49.filesusr.com
- nenegifivujaxu.mypressonline.com
- genolewedusu.myartsonline.com
- 4779f2f8-a33e-4327-9c78-21ee0bcf4620.filesusr.com
- 78fa80b2-8629-447b-ad63-53e91e8d4948.filesusr.com
- tefetuzuzip.myartsonline.com
- mukanebesiva.atwebpages.com
- lezeninimi.medianewsonline.com
- www.w3.org
- purl.org
- ns.adobe.com
- idealica-it.website
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report