MALICIOUS — 49be48_8d804862b7c348db9b442a8964210e7e.pdf
MALICIOUS — 49be48_8d804862b7c348db9b442a8964210e7e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
59f0ae60695d4cebda42c3bbe9f0bd635647a6a496843e33c683216390655ee7 - SHA-1:
46472d3b71899df77cb40552bc24614c1e564e90 - MD5:
629f1ba102487f86a4526f0e6cfeb511 - ssdeep:
1536:25aUmnF9RmjoA3BcD2jq4a+XSnVrOWOc79Oour18vDNkiW8zZ8ysU6KZaLNjE:jlDbSpXUvt79OB+xk2t8jdaKG - TLSH:
T1C23AD1F32157DD8CBA85EF83EAB6696C744BD6C83122CA7014887E9CC4795BE2E54D00 - Submitted as: 49be48_8d804862b7c348db9b442a8964210e7e.pdf
- File type: pdf · Size: 93899 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://jacksth.ru/wix?keyword=screen+mirroring+assistant+apk+download, http://danokob.epizy.com/ncert_full_form_in_kannada.pdf, https://xegoratan.weebly.com/uploads/1/3/2/7/132712572/fd2eb0bb1b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/wix?keyword=screen+mirroring+assistant+apk+download
- http://danokob.epizy.com/ncert_full_form_in_kannada.pdf
- https://xegoratan.weebly.com/uploads/1/3/2/7/132712572/fd2eb0bb1b.pdf
- http://gevegure.rf.gd/mt_yonah_climbing_guide.pdf
- http://komikewewi.iblogger.org/larazusiminesizevixafa.pdf
- https://cdn.sqhk.co/xawobovuji/AlUigVp/70257455304.pdf
- http://wepukuxazej.rf.gd/pusiluzepaxebu.pdf
- http://pususarejopo.epizy.com/n_mosfet_depletion_datasheet.pdf
- http://noxesufod.epizy.com/72508705516.pdf
- http://faxajipemafeb.epizy.com/3d_max_photo_frame_free.pdf
- https://napolapivu.weebly.com/uploads/1/3/5/3/135303388/tapoxikidul.pdf
- http://mimasajikataza.iblogger.org/best_cartoon_movies_2017_free.pdf
- http://nivugugop.rf.gd/adelaide_hourly_weather_report.pdf
- http://pusejik.epizy.com/51149579582.pdf
- http://pumujavebedopa.iblogger.org/99620742269.pdf
- http://gomotejux.iblogger.org/xaralodunuwili.pdf
- https://lurusavi.weebly.com/uploads/1/3/2/7/132710630/nimerifivifex_ketosif_bepopariki_jebezezoduv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- jacksth.ru
- danokob.epizy.com
- xegoratan.weebly.com
- komikewewi.iblogger.org
- cdn.sqhk.co
- pususarejopo.epizy.com
- noxesufod.epizy.com
- faxajipemafeb.epizy.com
- napolapivu.weebly.com
- mimasajikataza.iblogger.org
- pusejik.epizy.com
- pumujavebedopa.iblogger.org
- gomotejux.iblogger.org
- lurusavi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- gevegure.rf.gd
- wepukuxazej.rf.gd
- nivugugop.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report