MALICIOUS — japivulisesufuzuzid.pdf
MALICIOUS — japivulisesufuzuzid.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
157c69d26aad99d22ecbe24d769dba0df8bef25fa76bb34f61bfa76e9e79af48 - SHA-1:
56b1aca37313f23b46607fb50256a0e0b75f76df - MD5:
559a2f3ff17b387d745770eb31aad270 - ssdeep:
1536:AHnhVH5+92c8bx90Pzig2CqszBjWsrBUJESKvS1gwezR8qeR/L9P:UhVo92cex907igH/dj3rktH/rRN - TLSH:
T11237E0F76247EE5C77855B03A9B5112C1816EB08A27399E0508CB63CC9AC4FD7EB4C62 - Submitted as: japivulisesufuzuzid.pdf
- File type: pdf · Size: 70696 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffnew.ru/strik?utm_term=eason+chan+las+vegas, https://uploads.strikinglycdn.com/files/d1f616ee-b7a1-4294-8ff3-63129c917fd7/maryland_fly_fishing_guides.pdf, https://uploads.strikinglycdn.com/files/70f062ba-fe13-42a2-b0fd-0100e5f877ad/46625095985.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffnew.ru/strik?utm_term=eason+chan+las+vegas
- https://uploads.strikinglycdn.com/files/d1f616ee-b7a1-4294-8ff3-63129c917fd7/maryland_fly_fishing_guides.pdf
- https://uploads.strikinglycdn.com/files/70f062ba-fe13-42a2-b0fd-0100e5f877ad/46625095985.pdf
- https://uploads.strikinglycdn.com/files/35002a9f-a2a1-4b24-a7c8-4885a69fa858/48803701560.pdf
- https://uploads.strikinglycdn.com/files/04740c2c-2661-4fc7-b4b6-82cb67b676c0/modomojimesibapav.pdf
- https://xameramavojipav.weebly.com/uploads/1/3/4/2/134265998/bugadi.pdf
- https://sebiwijojemobod.weebly.com/uploads/1/3/4/0/134097571/f4104fffc5b.pdf
- https://uploads.strikinglycdn.com/files/1212ef54-33c9-4270-b1bf-779fff3f1046/ejemplos_de_fichas_de_cita_textual.pdf
- https://uploads.strikinglycdn.com/files/cbcfb89a-4cdb-42c0-8239-e392c37ed858/zirixeloxedafef.pdf
- https://uploads.strikinglycdn.com/files/15372827-6b05-4112-a490-c6e89d30bdfb/dodunet.pdf
- https://uploads.strikinglycdn.com/files/01bc0fda-d252-4c67-8a33-e89a3bf3f8a7/43229671612.pdf
- https://uploads.strikinglycdn.com/files/c73074b1-d978-49b0-a772-2a7fc4cab0ac/vopenovuzetopu.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f8760c702183.pdf
- https://cdn-cms.f-static.net/uploads/4388063/normal_5f9041a2b0866.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffnew.ru
- uploads.strikinglycdn.com
- xameramavojipav.weebly.com
- sebiwijojemobod.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report