MALICIOUS — 66425659263.pdf
MALICIOUS — 66425659263.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
184c5f742bc99eb422a572c20c83ac253442060d6eaae74695b06a4c944a6af2 - SHA-1:
bb66e25e1fdb44cf59c5c8e7d0b18c5a2d5b2fad - MD5:
15417ae26381b47d2ba2dfef687757df - ssdeep:
3072:bv/gd6tfhAj39WLKJ6Wg1cmzszdwOCIxAAIyocwcz7LUx0C:rgYvOWLKAVzsJwOC7JoM5 - TLSH:
T17D3CE1F37187ED586A47EB83A5BE2699744E93982131D6900448BF6CC9F82BD7F01A10 - Submitted as: 66425659263.pdf
- File type: pdf · Size: 116390 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://crysiq.ru/pbw?utm_term=analisis+morfosintactico+de+oraciones+compuestas+ejercicios+resueltos, https://uploads.strikinglycdn.com/files/edb26be7-817f-4012-9e3a-9df52a0a1244/fimowijepematujufeduv.pdf, https://uploads.strikinglycdn.com/files/7eaacda4-bb12-48b5-9341-1f2c7af7d7bd/38479908206.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/pbw?utm_term=analisis+morfosintactico+de+oraciones+compuestas+ejercicios+resueltos
- https://uploads.strikinglycdn.com/files/edb26be7-817f-4012-9e3a-9df52a0a1244/fimowijepematujufeduv.pdf
- https://uploads.strikinglycdn.com/files/7eaacda4-bb12-48b5-9341-1f2c7af7d7bd/38479908206.pdf
- http://nigezid.pbworks.com/f/cat_mario_unblocked_games_77.pdf
- https://uploads.strikinglycdn.com/files/e2236921-8979-4394-9cae-2351d4b60401/discovering_dna_structure_worksheet_answers.pdf
- http://vogituvu.pbworks.com/f/form_il-1120-st-v_instructions.pdf
- https://uploads.strikinglycdn.com/files/01bc5eff-debc-4a72-a882-1c10b0a401bd/somaxubimegekozoxa.pdf
- https://uploads.strikinglycdn.com/files/ecb2d5af-de2e-4117-8413-93baa45049a5/33782443996.pdf
- https://uploads.strikinglycdn.com/files/eecba0b9-0d1a-4c13-bae1-91fa27303536/voguvedolorojaxadesi.pdf
- https://dakokegeter.weebly.com/uploads/1/3/4/7/134723120/4694f34450.pdf
- https://farisogu.weebly.com/uploads/1/3/4/3/134307724/wonasobigulada.pdf
- https://uploads.strikinglycdn.com/files/a91c7410-9502-4b06-bd33-74280b0a0917/ziwexumotawamibi.pdf
- http://vifogajo.pbworks.com/f/65447631047.pdf
- https://kavavori.weebly.com/uploads/1/3/4/0/134012315/mizaferozi_bulejufafezamuj.pdf
- http://natizasex.pbworks.com/w/file/fetch/144411603/esquadrao_suicida_acerto_de_contas_online_dublado.pdf
- https://uploads.strikinglycdn.com/files/6f259285-d6c2-4903-afdf-bc976f22b9a3/ai_dungeon_premium_account_free.pdf
- https://zufezegudowoz.weebly.com/uploads/1/3/2/6/132683286/43d1b774.pdf
- https://uploads.strikinglycdn.com/files/96a19b08-2e01-4c0e-b67c-a70109597ad2/kataxotomojutolez.pdf
- https://vagoledos.weebly.com/uploads/1/3/5/3/135320004/nusilogedokomopiwan.pdf
- https://sibujoxosuzeru.weebly.com/uploads/1/3/4/4/134499285/5200922.pdf
- https://uploads.strikinglycdn.com/files/df76bc06-9d1a-489b-b094-a44c1ee810d2/what_is_a_peace_offering_in_spanish.pdf
- http://zuvevetub.pbworks.com/w/file/fetch/144422916/kafepedubexagegega.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- crysiq.ru
- uploads.strikinglycdn.com
- nigezid.pbworks.com
- vogituvu.pbworks.com
- dakokegeter.weebly.com
- farisogu.weebly.com
- vifogajo.pbworks.com
- kavavori.weebly.com
- natizasex.pbworks.com
- zufezegudowoz.weebly.com
- vagoledos.weebly.com
- sibujoxosuzeru.weebly.com
- zuvevetub.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report