MALICIOUS — zizep.pdf
MALICIOUS — zizep.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
fd7889cc61a2dd2a9bdbd022be91c99fa6621031cb296505b42ce32938713f8f - SHA-1:
51015eae1c223fc95f92ebe5457ffeb4cbc9c2e7 - MD5:
2787bf5443af8044b0a400704f9700e1 - ssdeep:
1536:95bLs080R18gADAbqnUrjvuoIz6i1fssg8x2skTgLW:XHS218rAbqUvvqO+ssg8x2dTZ - TLSH:
T13C37DFF37097DC587AC79F1379D214AC688A9A88667196E5008C3FBCC8B86BD7F10520 - Submitted as: zizep.pdf
- File type: pdf · Size: 75050 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!2787BF5443AF
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://druttle.ru/strik?utm_term=will+machine+learning+replace+statistics, http://folugomobok.getenjoyment.net/xijotazeduxabelupifaf.pdf, https://cdn.sqhk.co/gediwuwanol/jebSxhg/tier_list_maker.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://druttle.ru/strik?utm_term=will+machine+learning+replace+statistics
- http://folugomobok.getenjoyment.net/xijotazeduxabelupifaf.pdf
- https://cdn.sqhk.co/gediwuwanol/jebSxhg/tier_list_maker.pdf
- https://cdn-cms.f-static.net/uploads/4459341/normal_60137631005a0.pdf
- http://wabiferofuvud.mygamesonline.org/tubawosixu.pdf
- https://cdn-cms.f-static.net/uploads/4375355/normal_5fd9e31fe6fc9.pdf
- http://freehookup.xyz/fosubikemofoxider3m0xi.pdf
- https://s3.amazonaws.com/wulagisi/where_did_sda_church_come_from.pdf
- http://nout-prokat.website/31091368421qtkq6.pdf
- https://cdn.sqhk.co/zelosoza/qpG5wji/buvozarifurejakisi.pdf
- https://s3.amazonaws.com/vigevot/chcccs015_provide_individualised_support_answers.pdf
- http://sevezor.scienceontheweb.net/princeton_offense_playbook.pdf
- https://cdn.sqhk.co/dajuzafum/igjaSvh/daily_planner_2020.pdf
- https://cdn-cms.f-static.net/uploads/4373016/normal_601acf4e37396.pdf
- https://static.s123-cdn-static.com/uploads/4388407/normal_5ffc94248cee5.pdf
- http://fuvesozufinefi.medianewsonline.com/building_maintenance_plan_template.pdf
- http://pojozija.onlinewebshop.net/nostalgia_rkp630_retro_2.5-ounce_kettle_popcorn_maker_instructions.pdf
- http://umdtheatre.ru/how_to_change_a_bushnell_rangefinder_from_meters_to_yards7v4r9.pdf
- https://cdn.sqhk.co/xovikojux/cD2ig9o/maximum_carnage_sega.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- druttle.ru
- folugomobok.getenjoyment.net
- cdn.sqhk.co
- cdn-cms.f-static.net
- wabiferofuvud.mygamesonline.org
- freehookup.xyz
- s3.amazonaws.com
- sevezor.scienceontheweb.net
- static.s123-cdn-static.com
- fuvesozufinefi.medianewsonline.com
- pojozija.onlinewebshop.net
- umdtheatre.ru
- www.w3.org
- purl.org
- ns.adobe.com
- nout-prokat.website
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report