MALICIOUS — 2520beb6b29c0e6a4345c6dc1b2bd930e0080acfd0bdcdee26098b1023afb7f8
MALICIOUS — 2520beb6b29c0e6a4345c6dc1b2bd930e0080acfd0bdcdee26098b1023afb7f8 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
2520beb6b29c0e6a4345c6dc1b2bd930e0080acfd0bdcdee26098b1023afb7f8 - SHA-1:
51b0f93605892e6130e3c224e05bb21bed118fdb - MD5:
c5035a94a921cc5898cf5c4e47a8c6b1 - ssdeep:
1536:eR3VYoba001tYxiGirh0TrpsqkB2P78epZqY/zY3Hc6qep9uM06Y:elYoJUGs07Z8epZb7ic6qep9uMa - TLSH:
T17D39D0F3219BDD9CB78B7B436EBA546C408ED399A022D6504148B37C84BC6ED7E60E50 - Submitted as: 2520beb6b29c0e6a4345c6dc1b2bd930e0080acfd0bdcdee26098b1023afb7f8
- File type: pdf · Size: 87943 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!C5035A94A921
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://botokaw.ru/123?utm_term=video+live+wallpaper+anime+android, https://uploads.strikinglycdn.com/files/41ca6bd7-e211-4351-850d-5dfecaddeee0/60973537374.pdf, http://ribafaga.rf.gd/vodewizuwinubabugeli.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://botokaw.ru/123?utm_term=video+live+wallpaper+anime+android
- https://s3.amazonaws.com/wisuw/driver_booster_pc_app.pdf
- https://s3.amazonaws.com/dugibabafod/how_to_change_my_schlage_door_code.pdf
- https://uploads.strikinglycdn.com/files/41ca6bd7-e211-4351-850d-5dfecaddeee0/60973537374.pdf
- https://s3.amazonaws.com/wujixus/the_odyssey_book_xiv_summary.pdf
- https://s3.amazonaws.com/jonora/apache_ant_windows_10.pdf
- http://ribafaga.rf.gd/vodewizuwinubabugeli.pdf
- https://uploads.strikinglycdn.com/files/7b83bdb6-7671-41e1-9569-ee27fa687b58/bunker_hill_security_system_62368_manual.pdf
- https://uploads.strikinglycdn.com/files/81b55d39-5762-4d9f-a069-d04fe7f28ffb/how_to_learn_dental_terminology.pdf
- https://uploads.strikinglycdn.com/files/a078343e-33a4-4afc-beae-664ccad53002/cradle_to_cradle_design_def.pdf
- https://uploads.strikinglycdn.com/files/ea9db038-fd65-42c0-a4c8-c7df71f44805/psychoanalytic_criticism_in_literature.pdf
- https://uploads.strikinglycdn.com/files/f77a9eca-a5d9-4c14-9594-82030cd663a2/wilderness_survival_training_southern_california.pdf
- https://s3.amazonaws.com/divexikav/lesafaduzukozerasi.pdf
- https://s3.amazonaws.com/sebunuzu/19266942913.pdf
- https://uploads.strikinglycdn.com/files/c99d14bf-55a7-44bc-ab35-999b12edc241/wojar.pdf
- https://cdn.sqhk.co/gadukupuwe/idJgjTZ/classic_arcade_games_download_free_full_version.pdf
- https://cdn.sqhk.co/wevafixap/vih2W2y/gopabamuzivedimefirurit.pdf
- https://s3.amazonaws.com/kiguteperilodu/koxezewarutujizuzalalapaz.pdf
- https://uploads.strikinglycdn.com/files/261aed3e-f95f-4a3c-b35d-9cbc72c92ac3/gobokizovotetave.pdf
- https://cdn.sqhk.co/sixitigoxeto/iijijaM/66400436542.pdf
- https://uploads.strikinglycdn.com/files/116a8182-ab13-4b34-8a45-9027fce90290/contra_3_game_genie_codes.pdf
- https://cdn.sqhk.co/wenejusuzixe/DHDxiit/hdfc_diners_club_credit_card_apply.pdf
- https://uploads.strikinglycdn.com/files/fb555f14-79bb-4288-a3e7-f410cd26dedb/22601244502.pdf
- https://cdn.sqhk.co/terasovo/ie5hjvY/92366577433.pdf
- http://demunoj.epizy.com/answered_meaning_in_bengali.pdf
Embedded domains
- botokaw.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn.sqhk.co
- demunoj.epizy.com
- www.w3.org
- purl.org
- ns.adobe.com
- ribafaga.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report