MALICIOUS — moxevowatulavafimajo.pdf
MALICIOUS — moxevowatulavafimajo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
4e7c4f896a663024745a4595462ecf3454e5653bb78e02524d55efa7e7c6cd13 - SHA-1:
31d75be8ef3d3130110623cf8da8c2f447ec86e4 - MD5:
22b2c1b22c51bc34fa09c9ea2a464cb8 - ssdeep:
1536:Dk/HANqnHE9mzVfev7okYHA2IWfLxswIzT2B8osVHapDoVg:RNKlzVf2BF2PjxswI/2qVYDL - TLSH:
T1CC37D1F3A0ABEDCC6646A703E6B7252D9146E3CC6066AA5041CC777CC0786BEBE11941 - Submitted as: moxevowatulavafimajo.pdf
- File type: pdf · Size: 73315 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffset.ru/wb?keyword=nvidia%20shield%20android%20tv%20games%20list, https://uploads.strikinglycdn.com/files/b6181ecc-f811-4dda-897b-3180dc614629/puzuzijarose.pdf, https://uploads.strikinglycdn.com/files/c9cff636-025b-493a-8565-a80b08e1e2ab/4616356217.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffset.ru/wb?keyword=nvidia%20shield%20android%20tv%20games%20list
- https://uploads.strikinglycdn.com/files/b6181ecc-f811-4dda-897b-3180dc614629/puzuzijarose.pdf
- https://uploads.strikinglycdn.com/files/c9cff636-025b-493a-8565-a80b08e1e2ab/4616356217.pdf
- https://s3.amazonaws.com/kalanejaxutilif/54488571897.pdf
- https://s3.amazonaws.com/baxekojojexusol/56076417654.pdf
- https://s3.amazonaws.com/kisimujuk/80971364744.pdf
- https://uploads.strikinglycdn.com/files/2d97a193-d6c1-414c-9df0-e9536e30e4ef/mobawemanamajeriwop.pdf
- https://uploads.strikinglycdn.com/files/203a5cb4-48b0-41c9-b582-2fe03a6073b3/queue_in_c_library.pdf
- https://uploads.strikinglycdn.com/files/c8965a69-168e-4382-9e83-7ea61bb6f6da/66758298955.pdf
- https://uploads.strikinglycdn.com/files/b03a8e31-97b4-4e0b-ac64-e8db0b704338/67340910421.pdf
- https://mulaxenowaw.weebly.com/uploads/1/3/4/8/134862071/3341344.pdf
- https://uploads.strikinglycdn.com/files/3bae2913-1c5e-418c-a3b8-9dcb6c9ff34a/ted_gunderson.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffset.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- mulaxenowaw.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report