MALICIOUS — walmart_black_friday_hours_ma.pdf
MALICIOUS — walmart_black_friday_hours_ma.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
2f7a871a1dfe73a26681c0ef026e9a6f5d5314916bee4dd4f3d07a3a113935ff - SHA-1:
6874c16c835fefb0d0ecba14dec18026f0e00a68 - MD5:
0995c37721d13d0d04a7b4f497d1036e - ssdeep:
1536:g+jF031AQYNt7uMXXtKznLtDxQU6kosidoKI3tulT2KNVUFcj3L:zFCG57XtupDxQUdoOKIdu2KHacv - TLSH:
T14B39D0F3A047DC4D7A9B6753AC76102868CEC684A13287A451C8776DC87C6ED6F349E0 - Submitted as: walmart_black_friday_hours_ma.pdf
- File type: pdf · Size: 84723 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!0995C37721D1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://mezovuduw.ru/strik?utm_term=walmart+black+friday+hours+ma, https://a208a2de-cee2-48c2-86e3-c620a022946d.filesusr.com/ugd/dda32d_cf267b9290f3461d85bcd6fb6b7d6ac7.pdf?index=true, https://1618b3f4-dcc0-4047-a816-eeb1cbe43c51.filesusr.com/ugd/a01749_eb2b561768ec402f9e6d262bf54b408e.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://mezovuduw.ru/strik?utm_term=walmart+black+friday+hours+ma
- https://a208a2de-cee2-48c2-86e3-c620a022946d.filesusr.com/ugd/dda32d_cf267b9290f3461d85bcd6fb6b7d6ac7.pdf?index=true
- https://1618b3f4-dcc0-4047-a816-eeb1cbe43c51.filesusr.com/ugd/a01749_eb2b561768ec402f9e6d262bf54b408e.pdf?index=true
- https://uploads.strikinglycdn.com/files/f5b56836-80ed-4e93-85cf-1e95cdeaf446/tozok.pdf
- https://cdn-cms.f-static.net/uploads/4489057/normal_606e542970f78.pdf
- https://cdn-cms.f-static.net/uploads/4494889/normal_600eacc76682b.pdf
- https://cdn-cms.f-static.net/uploads/4382965/normal_60369810996fa.pdf
- https://uploads.strikinglycdn.com/files/a50cac85-edb2-410f-a203-cf884abd6081/which_diet_app_is_the_best.pdf
- https://cdn-cms.f-static.net/uploads/4454303/normal_6055749fb2688.pdf
- https://s3.amazonaws.com/mafavuzenoliki/gokasan.pdf
- https://static.s123-cdn-static.com/uploads/4476925/normal_5ffdc582b4d0c.pdf
- https://cdn-cms.f-static.net/uploads/4390638/normal_6023d17221279.pdf
- https://6b21c484-99f8-4e97-b77a-b77c054bfe5d.filesusr.com/ugd/f139d4_9be9869bdc9f4d7b810bd9be85e3c7e7.pdf?index=true
- https://s3.amazonaws.com/jasipefulaxiduj/41443096798.pdf
- https://static.s123-cdn-static.com/uploads/4417805/normal_5ffcf37c2ca01.pdf
- https://cdn-cms.f-static.net/uploads/4489414/normal_601d3681a40cf.pdf
- https://cdn-cms.f-static.net/uploads/4485946/normal_6055809da632c.pdf
- https://uploads.strikinglycdn.com/files/82685b84-4159-405b-95f8-6c50a61a7905/canon_mx432_scanner_not_working.pdf
- https://s3.amazonaws.com/divikufifir/54104199726.pdf
- https://4a31e3f8-49e3-4331-b1a9-c0bb7a6b9dbc.filesusr.com/ugd/599f1c_07230e131dba481d814bbfb75cf9c199.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4464707/normal_5ff5ae46c2711.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- mezovuduw.ru
- a208a2de-cee2-48c2-86e3-c620a022946d.filesusr.com
- 1618b3f4-dcc0-4047-a816-eeb1cbe43c51.filesusr.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- static.s123-cdn-static.com
- 6b21c484-99f8-4e97-b77a-b77c054bfe5d.filesusr.com
- 4a31e3f8-49e3-4331-b1a9-c0bb7a6b9dbc.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report