MALICIOUS — xafeb.pdf
MALICIOUS — xafeb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
4e59107013df47b6b3aaec0b1c0af79e5784716d52fc3e3d9d3ded536de105e9 - SHA-1:
7ec711cb375a52267f3e7003c2a627557da87af4 - MD5:
91f46101f955a4bc6e0605e10f5e14b4 - ssdeep:
1536:gKZjJpibW/RLTccei0XqfmDOkw4JCWnMeSrP942wKTVnb//cs1eWtj:FZjObWNp0XokvbM3OCSs19 - TLSH:
T19B38D0F361D7DD8CB79BAB136DAB060D1189E3CA553293A1009C776DC8782BE7E20511 - Submitted as: xafeb.pdf
- File type: pdf · Size: 79334 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!91F46101F955
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://dafemum.ru/strik?utm_term=what+is+contingency+theory+examples, https://vufagejibuto.weebly.com/uploads/1/3/1/4/131483336/ea825.pdf, https://uploads.strikinglycdn.com/files/21f70931-5947-4ca1-9842-9744f2d0b2c3/89667641876.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://dafemum.ru/strik?utm_term=what+is+contingency+theory+examples
- https://vufagejibuto.weebly.com/uploads/1/3/1/4/131483336/ea825.pdf
- https://uploads.strikinglycdn.com/files/21f70931-5947-4ca1-9842-9744f2d0b2c3/89667641876.pdf
- https://tufutitos.weebly.com/uploads/1/3/4/4/134491926/2064721.pdf
- https://zakewurez.weebly.com/uploads/1/3/4/4/134471700/kifikufujuxa-nixowim-sifoxijar.pdf
- https://uploads.strikinglycdn.com/files/53433363-3bad-48a2-8446-43526ae96eaa/ripitube.pdf
- https://cdn.sqhk.co/zekuxemelop/0iaRs3C/lagu_binks_sake_brook_version.pdf
- https://uploads.strikinglycdn.com/files/f0773823-6e2a-431f-97f5-d8d34e46e9da/if_two_players_have_a_royal_flush_who_wins.pdf
- https://s3.amazonaws.com/bulujono/39288401737.pdf
- https://s3.amazonaws.com/vunizi/legal_delivery_receipt_template.pdf
- https://cdn.sqhk.co/desogepupema/FjeD1hg/neon_piano_magic_dream_tiles_4_gratuit.pdf
- https://uploads.strikinglycdn.com/files/857417ea-c5a9-498a-b01b-808fdbc40399/how_to_reset_exercise_bike.pdf
- https://d848e4b6-662b-4424-a759-963270729452.filesusr.com/ugd/30e015_5a356e8450a840b79a7890975b598dd0.pdf?index=true
- https://cdn.sqhk.co/delotijuw/Uihilic/23375510340.pdf
- https://vigenuwotefi.weebly.com/uploads/1/3/4/0/134012497/vepulomiwadiz.pdf
- https://7aff118d-26f6-4d76-9bc9-1838009e7274.filesusr.com/ugd/f80014_2d09f7b7eaaa4302abc6d9fd486a3367.pdf?index=true
- https://s3.amazonaws.com/vitelitubovuluj/cavatina_myers_sheet_music.pdf
- https://s3.amazonaws.com/wekibik/christmas_carols_for_choir.pdf
- https://cdn.sqhk.co/zurefaxenov/ggpqjbO/80615115895.pdf
- https://156bb51f-0b62-477f-88ca-8620af00812b.filesusr.com/ugd/e3ff21_fcb6c65c5531407f95f2fe04d8a7f943.pdf?index=true
- https://ab60d57a-1f92-408f-9079-0b325776b613.filesusr.com/ugd/724fb5_60d194b9b0244f9d93e7301c1901c186.pdf?index=true
- https://932aa67c-856a-4fda-9fc8-fe3f50d4acc2.filesusr.com/ugd/a25eee_2026603d86ca4d6ca73a1d069877087f.pdf?index=true
- https://s3.amazonaws.com/netinuwa/activador_windows_8._1_pro.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- dafemum.ru
- vufagejibuto.weebly.com
- uploads.strikinglycdn.com
- tufutitos.weebly.com
- zakewurez.weebly.com
- cdn.sqhk.co
- s3.amazonaws.com
- d848e4b6-662b-4424-a759-963270729452.filesusr.com
- vigenuwotefi.weebly.com
- 7aff118d-26f6-4d76-9bc9-1838009e7274.filesusr.com
- 156bb51f-0b62-477f-88ca-8620af00812b.filesusr.com
- ab60d57a-1f92-408f-9079-0b325776b613.filesusr.com
- 932aa67c-856a-4fda-9fc8-fe3f50d4acc2.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report