MALICIOUS — 25dacd9d4b15fc9a9560e9e28ea1069b3cca18fc2b3ebb04a7af758c3393cb97
MALICIOUS — 25dacd9d4b15fc9a9560e9e28ea1069b3cca18fc2b3ebb04a7af758c3393cb97 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
25dacd9d4b15fc9a9560e9e28ea1069b3cca18fc2b3ebb04a7af758c3393cb97 - SHA-1:
4bb1edb2d0e4a37be86a1ab1b6dfa949789f679c - MD5:
f782cc487210bf91ebed90a362ac868a - ssdeep:
1536:BiYaUgH7RRSz8tMveZPKBiU0s1RdmNE1g1i39rSKHtuc43EF7JqQE9HMVR2PMPBN:adS4tcWkh51eNE+ilH7Jqx9HMVR2PyBN - TLSH:
T19D39CFF72083ED8CB6869F47ADE7126D344AD38522778B246088775CC5BCBAE7E14601 - Submitted as: 25dacd9d4b15fc9a9560e9e28ea1069b3cca18fc2b3ebb04a7af758c3393cb97
- File type: pdf · Size: 84605 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F782CC487210
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://jacksth.ru/strik?utm_term=free+online+drawing+classes+for+beginners+youtube, https://cdn.sqhk.co/jigitovewuk/HHoQxgg/79043488111.pdf, https://cdn.sqhk.co/vefapatape/fhiigii/mularifofisetiwelerozafo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/strik?utm_term=free+online+drawing+classes+for+beginners+youtube
- https://cdn.sqhk.co/jigitovewuk/HHoQxgg/79043488111.pdf
- https://cdn.sqhk.co/vefapatape/fhiigii/mularifofisetiwelerozafo.pdf
- https://cdn.sqhk.co/matikefateri/0hghe0q/cartoon_network_schedule_usa_2019.pdf
- https://cdn.sqhk.co/duditizonut/grgcsih/lesujoxinotog.pdf
- https://uploads.strikinglycdn.com/files/37563e7b-8f01-417e-a027-2aaacd51f0a7/baby_girl_nike_shoes_size_6.pdf
- https://cdn.sqhk.co/nuduniguwufo/izRTzij/ladis.pdf
- https://uploads.strikinglycdn.com/files/93fdf5b0-de86-433d-813b-6d9f7c5bc7c3/the_master_key_to_riches_summary.pdf
- https://cdn.sqhk.co/givogaduta/eib3gjs/vikings_game_score_last_night.pdf
- https://cdn.sqhk.co/kisesawaropo/HhjhhXr/cinemark_theater_monaca_pa_showtimes.pdf
- https://4868a29a-6d77-448d-a9c5-bc5c6a1713c3.filesusr.com/ugd/060e50_5d8a88d31ccb4bbd950053167b67a2ae.pdf?index=true
- https://cdn.sqhk.co/bitowiso/amcjcPL/39159037270.pdf
- https://cdn.sqhk.co/ponesigis/efvDjfZ/ink_master_host_fired.pdf
- https://uploads.strikinglycdn.com/files/88bfd8bb-4c18-4224-97d2-ad41fb76a5d8/neil_degrasse_tyson_universe_netflix.pdf
- https://5b2b9875-3923-4577-9ef6-0527498c95e7.filesusr.com/ugd/4e6dd5_7b99edc4e12e47bf8864d0159b135df2.pdf?index=true
- https://cdn.sqhk.co/vozeseseber/Mhcdhc4/trending_hashtags_2020_malaysia.pdf
- https://uploads.strikinglycdn.com/files/c29823e6-a889-4614-9567-e959dbbe6302/55421479876.pdf
- https://d8d691c7-cf48-432b-bece-a54604b57851.filesusr.com/ugd/1e3a4b_5a8ed8ca42a84d459234b61ea1847879.pdf?index=true
- https://cdn.sqhk.co/wepiwojeta/26gjAhi/senadezafifusugujusolide.pdf
- https://uploads.strikinglycdn.com/files/f03bb16e-931b-4551-a618-3b48b7453e5c/68785049131.pdf
- https://952d9f4b-853a-4e85-af28-23c4d489d487.filesusr.com/ugd/8db125_587a617bd65d4d5a98745ff40d32b48f.pdf?index=true
- https://cdn.sqhk.co/bamopilu/yijIxhf/importance_of_ecological_succession.pdf
- https://e5447efa-8854-4d04-834e-f0bbd7438c8b.filesusr.com/ugd/ac612b_d21ccb8f250f4e0a8141c9c3d0c3af79.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- jacksth.ru
- cdn.sqhk.co
- uploads.strikinglycdn.com
- 4868a29a-6d77-448d-a9c5-bc5c6a1713c3.filesusr.com
- 5b2b9875-3923-4577-9ef6-0527498c95e7.filesusr.com
- d8d691c7-cf48-432b-bece-a54604b57851.filesusr.com
- 952d9f4b-853a-4e85-af28-23c4d489d487.filesusr.com
- e5447efa-8854-4d04-834e-f0bbd7438c8b.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report