MALICIOUS — jigikuxetapomeded.pdf
MALICIOUS — jigikuxetapomeded.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fd6010cf87ee1be081ff3e3d7fc8fb95dae69ea5c65d1631fe67664ba3bcd87d - SHA-1:
4292cd80a8765d5e50d599e720b7b1d8349633e6 - MD5:
f2b32bdc9cfda0c618b38a07caf821cd - ssdeep:
1536:lkq9HNpTdodeGlqp3GXjrr73UVGMdW4Z4brO7ZWbpONtM01ilYA:xNNp2dLGGXz73UVGVm7bNtL1o7 - TLSH:
T12F38D0F36197CD8C7E475B036AF60168D09AD39871229AD044C87ABDC578ABD7E10A82 - Submitted as: jigikuxetapomeded.pdf
- File type: pdf · Size: 77403 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://freemansphotography.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613435551cc93---2690506481.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://oniceh.ru/uplcv?utm_term=chin+chin+menu+pdf, https://jecoexports.com/ckfinder/userfiles/files/nagoxuti.pdf, https://dewalt-naradi.cz/media/upload/editor/file/zopafukugofakomutunexexi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oniceh.ru/uplcv?utm_term=chin+chin+menu+pdf
- https://jecoexports.com/ckfinder/userfiles/files/nagoxuti.pdf
- https://dewalt-naradi.cz/media/upload/editor/file/zopafukugofakomutunexexi.pdf
- http://ventmetal.ru/userfiles/files/gukiboxitubinuzox.pdf
- https://schreinerheusi.de/wp-content/plugins/formcraft/file-upload/server/content/files/1614159d618329---zelujozirudonuvobivo.pdf
- http://freemansphotography.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613435551cc93---2690506481.pdf
- https://velvetskin.pl/wp-content/plugins/super-forms/uploads/php/files/b1dfacaac48c459a657697c0a78f7b1e/suketunigodup.pdf
- http://zentrumok.com/userfile/files/belosovogewevimimufal.pdf
- https://fond.ru/userfiles/file/dijupikodozavisa.pdf
- http://evrokomplekt.ru/userfiles/file/21909708345.pdf
- https://pikhospital.com/ck_uploads/uploads/files/febaxexovetejujuvubufukiw.pdf
- http://www.ncstarim.com.tr/wp-content/plugins/super-forms/uploads/php/files/lamk25rprhr72dputtd5v7juj5/julazixudogimanoxifipeli.pdf
- https://smartcirclegroup.com/userfiles/file/57672250406.pdf
- https://congchunghadong.com/uploads/files/xotalitokopegipibufowos.pdf
- http://www.loockuniformes.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/16144c581026a4---mobitizozuxanom.pdf
- https://forumsevens.com/images/file/4302467695.pdf
- http://honmamon-s.com/img_seminar/userfiles/file/varijezobaripiwufida.pdf
- https://npkfertilizerproduction.com/d/files/gufamin.pdf
- http://marchmontnews.com/imgs/file/dorirawabavasu.pdf
- https://www.e-oswiata.olesnica.pl/ckfinder/userfiles/files/betevijufomok.pdf
- http://baugeraeteverleih.de/benutzerdateien/63644879239.pdf
- http://vaynhe.com/upload/files/zefokuvazoruzejuro.pdf
- http://border-collie.ru/sites/default/files/file/jiberomov.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- oniceh.ru
- jecoexports.com
- ventmetal.ru
- schreinerheusi.de
- freemansphotography.com
- velvetskin.pl
- zentrumok.com
- fond.ru
- evrokomplekt.ru
- pikhospital.com
- smartcirclegroup.com
- congchunghadong.com
- www.loockuniformes.com.br
- forumsevens.com
- honmamon-s.com
- npkfertilizerproduction.com
- marchmontnews.com
- www.e-oswiata.olesnica.pl
- baugeraeteverleih.de
- vaynhe.com
- border-collie.ru
- www.w3.org
- purl.org
- ns.adobe.com
- dewalt-naradi.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report