MALICIOUS — long_shadows.pdf
MALICIOUS — long_shadows.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
3cf00fd37f264a212b31ac3fea7575d220ac16e00b8ba0e214c9423389b9d6f3 - SHA-1:
9e4795d09504cf46ac820415cb9b5534caee2760 - MD5:
f5c0cdde453a8b8f01f2cd1e03b958dc - ssdeep:
1536:EeMfl7sxdcs8+VRpKUa1NuzXJ46MmRUF07dfHmK:R8l7ycAja1AzZ4lmaFqff - TLSH:
T1A737D1F3725BCE8D6986E743B5DA1868A08AE3D92531E7514485763CC8B83FC6F10A60 - Submitted as: long_shadows.pdf
- File type: pdf · Size: 70337 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://gettraff.ru/strik?keyword=long+shadows+pdf, https://cdn-cms.f-static.net/uploads/4369166/normal_5f9c558866da0.pdf, https://cdn-cms.f-static.net/uploads/4369928/normal_5f8ac5196c214.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=long+shadows+pdf
- https://cdn-cms.f-static.net/uploads/4369166/normal_5f9c558866da0.pdf
- https://s3.amazonaws.com/lonozote/nenewobavabaf.pdf
- https://cdn-cms.f-static.net/uploads/4369928/normal_5f8ac5196c214.pdf
- https://cdn-cms.f-static.net/uploads/4411701/normal_5f933725a7d97.pdf
- https://tezexitebab.weebly.com/uploads/1/3/4/6/134600353/427787.pdf
- https://cdn-cms.f-static.net/uploads/4368996/normal_5f8c4dac56b21.pdf
- https://uploads.strikinglycdn.com/files/1be9f295-3905-4c27-bbe4-e59e25b56590/scottsboro_an_american_tragedy_watch_online.pdf
- https://cdn-cms.f-static.net/uploads/4377678/normal_5fa6c3cc317e0.pdf
- https://s3.amazonaws.com/nokiva/peverezugeko.pdf
- https://uploads.strikinglycdn.com/files/3d263a82-1c9f-48d3-9a97-6a149974fdb6/83396170791.pdf
- https://rifuxegu.weebly.com/uploads/1/3/4/5/134525143/6909097.pdf
- https://s3.amazonaws.com/ditiruz/dinifedififelujele.pdf
- https://uploads.strikinglycdn.com/files/47a421d3-4782-4841-8060-099db6c6720c/lifefitness_5500_hr.pdf
- https://uploads.strikinglycdn.com/files/b0f377c9-110d-41d4-9d19-8e13f3f1dac5/6channels_16dsp_effect.pdf
- https://s3.amazonaws.com/lodunixodetum/is_the_study_of_matter_and_energy_complete.pdf
- https://uploads.strikinglycdn.com/files/841383e6-65cd-49a9-b753-2bb4e7d4acbc/laxukobutefilitanit.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- tezexitebab.weebly.com
- uploads.strikinglycdn.com
- rifuxegu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report