MALICIOUS — af4e73_5d1da2e403094b59b588844936240450.pdf
MALICIOUS — af4e73_5d1da2e403094b59b588844936240450.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
2e684ba5727b44f1232853625cd9aac603d568e62cee729ba4f13aa489d3b3aa - SHA-1:
ac3239eb0a85a1fe779e67492836d189dae1cf10 - MD5:
55b05f809f384a05e524df5c7d5bd378 - ssdeep:
1536:0f6k4jxB0Hqio01SBwMI2yJyLu9r85bbHhnLwNvjY27c2PXTIf:W6XjDS1QBwN3J2u9r8lBnkzo2Ps - TLSH:
T18B39C0F311D7EC8CB69B9F6369B9166D6089C3C85122E79400C86B2D85BC7BE7F10921 - Submitted as: af4e73_5d1da2e403094b59b588844936240450.pdf
- File type: pdf · Size: 85410 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!55B05F809F38
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://kuzutuzo.ru/wix?keyword=sims+freeplay+apkpure, http://tazizinujumijoj.mywebcommunity.org/aat_bookkeeping_controls.pdf, http://tipofeliluget.medianewsonline.com/23497096473.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://kuzutuzo.ru/wix?keyword=sims+freeplay+apkpure
- http://tazizinujumijoj.mywebcommunity.org/aat_bookkeeping_controls.pdf
- https://s3.amazonaws.com/vebenok/nifeduratini.pdf
- https://s3.amazonaws.com/wurivuve/chernobyl_2019_soundtrack.pdf
- http://tipofeliluget.medianewsonline.com/23497096473.pdf
- http://9gusevshop.space/motuzowe2iq0m.pdf
- https://s3.amazonaws.com/saxefi/used_to_vs_would_worksheet.pdf
- http://rowowesofazov.medianewsonline.com/how_to_make_corn_bags_for_toss_game.pdf
- https://s3.amazonaws.com/sorogamat/afro_cuban_rhythms_drum_set.pdf
- http://wozekozexufoxol.scienceontheweb.net/61592460799.pdf
- http://viniveba.mywebcommunity.org/english_grammar_practice_test_with_answers.pdf
- http://movawizaxaxato.mywebcommunity.org/intex_sand_filter_pump_instructions.pdf
- http://midarujiwuvi.mygamesonline.org/bacteriocin_classification.pdf
- http://positajugopisu.myartsonline.com/63149612665.pdf
- https://0ddd2631-58c7-464c-86d0-a5d1d8121c04.filesusr.com/ugd/301b85_8f8c583fc8184cfabf0f5bebfb35f2b2.pdf?index=true
- http://mobeditobaxul.scienceontheweb.net/bomapabogowid.pdf
- https://cf4de027-7369-46c2-bf93-d69cabef2b5e.filesusr.com/ugd/868b90_c772d274b088469281f111938e11825d.pdf?index=true
- http://health2health.online/10829652849zupe6.pdf
- https://8eeb1f0a-0cdd-4c66-98a4-83777b49fb54.filesusr.com/ugd/64f9d2_557c8dacbd00450fa5afe20561cacb3f.pdf?index=true
- http://pifowovumuwe.medianewsonline.com/kikotevediduw.pdf
- https://b1706aec-e9b1-4c6c-9a93-f14ef4a1c402.filesusr.com/ugd/3b47cb_d2c0fb216dfb47f68e816a1485a370e3.pdf?index=true
- https://s3.amazonaws.com/rupatojuko/moruwenibupogupixised.pdf
- http://bufibinokurun.scienceontheweb.net/english_grammar_in_arabic_language.pdf
- http://cabinetshq.xyz/diary_of_a_wimpy_kid_deep_end_lexile_levelgrr1e.pdf
- http://zonizubiro.getenjoyment.net/flywheels_and_fluctuation_of_energy.pdf
Embedded domains
- kuzutuzo.ru
- tazizinujumijoj.mywebcommunity.org
- s3.amazonaws.com
- tipofeliluget.medianewsonline.com
- 9gusevshop.space
- rowowesofazov.medianewsonline.com
- wozekozexufoxol.scienceontheweb.net
- viniveba.mywebcommunity.org
- movawizaxaxato.mywebcommunity.org
- midarujiwuvi.mygamesonline.org
- positajugopisu.myartsonline.com
- 0ddd2631-58c7-464c-86d0-a5d1d8121c04.filesusr.com
- mobeditobaxul.scienceontheweb.net
- cf4de027-7369-46c2-bf93-d69cabef2b5e.filesusr.com
- health2health.online
- 8eeb1f0a-0cdd-4c66-98a4-83777b49fb54.filesusr.com
- pifowovumuwe.medianewsonline.com
- b1706aec-e9b1-4c6c-9a93-f14ef4a1c402.filesusr.com
- bufibinokurun.scienceontheweb.net
- cabinetshq.xyz
- zonizubiro.getenjoyment.net
- tixshopclub.space
- 6c473ef0-402e-45f0-9f95-6bc7e89a6a1a.filesusr.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report