MALICIOUS — numiveb_zujegedetis_velovunimazuf.pdf
MALICIOUS — numiveb_zujegedetis_velovunimazuf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
55960c33ab59ec0e4660891d8cdad166e59419495aaa42cc4e957bcd3984dd74 - SHA-1:
e180015afc320d1e4a027a0bc1a1a09b324328d8 - MD5:
c52c5d2b71339c4c0178668453b30eef - ssdeep:
1536:Xnhk9I8ysM7NzQx1xfqNCwoC0ec5i9e80snWkYQwYb9:Xu98sQzU1cnBDT0srw2 - TLSH:
T19236D0F311EBCE8CAB859B5798AB052C6497D7C43132EB90649CBA2CD47C6BC7D10A50 - Submitted as: numiveb_zujegedetis_velovunimazuf.pdf
- File type: pdf · Size: 67775 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafficel.ru/wb?keyword=la%20la%20la%20ringtone%20%20bestwap, https://gakuwalexutibok.weebly.com/uploads/1/3/4/3/134332976/5828a66efc425b.pdf, https://uploads.strikinglycdn.com/files/b8d0ddb7-d766-47b5-9c2c-942512a22dd9/36270069939.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/wb?keyword=la%20la%20la%20ringtone%20%20bestwap
- https://gakuwalexutibok.weebly.com/uploads/1/3/4/3/134332976/5828a66efc425b.pdf
- https://uploads.strikinglycdn.com/files/b8d0ddb7-d766-47b5-9c2c-942512a22dd9/36270069939.pdf
- https://uploads.strikinglycdn.com/files/1772003f-867b-4958-903e-62cca64d1826/zoo_phonics.pdf
- https://uploads.strikinglycdn.com/files/2c67834a-f625-4ed6-b95e-95d946ee3940/algebra_with_pizzazz_answer_key_166.pdf
- https://s3.amazonaws.com/veraxawewib/fuwamivulidukigamizaxigew.pdf
- https://uploads.strikinglycdn.com/files/b695ad92-19ec-4a27-b378-bb66e420d6e0/bilkent_kapsamlC4B1_burs.pdf
- https://s3.amazonaws.com/kizuporowefib/bifefasegasa.pdf
- https://uploads.strikinglycdn.com/files/67af62c2-58f0-42ec-af72-3b23d8f75009/uc_browser_application_free.pdf
- https://uploads.strikinglycdn.com/files/ace029e3-c184-422e-b744-103427bfd493/wibeduz.pdf
- https://dutajidadu.weebly.com/uploads/1/3/4/7/134730474/c62ab695cfd.pdf
- https://s3.amazonaws.com/sasufufa/22187242773.pdf
- https://s3.amazonaws.com/firudegix/fitejokufitokigudijew.pdf
- https://s3.amazonaws.com/sakaburepagase/tuzirol.pdf
- https://s3.amazonaws.com/fejenijovekozu/regelepijatulob.pdf
- https://uploads.strikinglycdn.com/files/562e9679-28ff-4a2e-a53c-0c893e35bae5/lapupopulukilawud.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- gakuwalexutibok.weebly.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- dutajidadu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report