MALICIOUS — 5fabb426db37b8b2c0d18cc7f86ae4df2f558aec3bb39868e4684e8cf31769be
MALICIOUS — 5fabb426db37b8b2c0d18cc7f86ae4df2f558aec3bb39868e4684e8cf31769be is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 6 of 50 detection engines flagged it.
Identification
- SHA-256:
5fabb426db37b8b2c0d18cc7f86ae4df2f558aec3bb39868e4684e8cf31769be - SHA-1:
ceff460396e64d5ea4956f4c650cb4a85781fe57 - MD5:
927f761c15f289a4f4373f0ec7c87102 - ssdeep:
1536:IeSorCX0OUgF7Mety1ahh4LJX/sMf3ltPC5RgqtBK0tIvlc5aYk25vw:M3EOdFget6ahh4LdvttPC5RpyYIu55kH - TLSH:
T19438C0F3505BEC6C299A6F43AAB716A8A0C9C3C86031DB9044C8B66DC47C3FD7D61991 - Submitted as: 5fabb426db37b8b2c0d18cc7f86ae4df2f558aec3bb39868e4684e8cf31769be
- File type: pdf · Size: 77459 bytes
- Verdict: malicious (92/100)
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!927F761C15F2
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://archism.ru/pbw?utm_term=play+online+subway+surfers+game+free, https://uploads.strikinglycdn.com/files/4852f396-9e05-4e4f-96bb-35d0f1a0bc52/94330507205.pdf, http://bajaduxaxusi.pbworks.com/f/ronizulonoxiw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://archism.ru/pbw?utm_term=play+online+subway+surfers+game+free
- https://uploads.strikinglycdn.com/files/4852f396-9e05-4e4f-96bb-35d0f1a0bc52/94330507205.pdf
- http://bajaduxaxusi.pbworks.com/f/ronizulonoxiw.pdf
- https://uploads.strikinglycdn.com/files/f1f99142-54c6-47e0-9979-778f06cb8cd0/list_of_persuasive_essay_topics_for_high_school_students.pdf
- http://binovilijire.pbworks.com/w/file/fetch/144997254/lafekipupoperodoz.pdf
- https://uploads.strikinglycdn.com/files/5a49d173-77ea-4aa7-aa82-00f076f646a5/motuvesul.pdf
- https://uploads.strikinglycdn.com/files/5aeb953f-2f6e-47e7-b43f-d3d7b805ac34/829599195.pdf
- https://uploads.strikinglycdn.com/files/c04f1b86-c00c-4213-ad18-3268429f546a/77818015967.pdf
- https://uploads.strikinglycdn.com/files/74f2da28-7ac2-454b-827e-0c212fe3fbd2/18890935729.pdf
- https://uploads.strikinglycdn.com/files/d92bc725-5906-413b-a8b1-a319b4a4fc9a/56335995433.pdf
- https://cdn-cms.f-static.net/uploads/4446942/normal_605129c0213fd.pdf
- https://uploads.strikinglycdn.com/files/2439f2d0-5403-4830-a98b-bce8a87ad122/7573104957.pdf
- https://uploads.strikinglycdn.com/files/7a534384-0d5b-4aa6-b4c7-f9c6f899cdba/xaganix.pdf
- https://uploads.strikinglycdn.com/files/eb4a4b3a-b17b-4910-a309-60100cf729ab/90882992655.pdf
- https://uploads.strikinglycdn.com/files/c5f677ea-d058-4ef8-81f9-1c6aeee8961a/what_does_chinese_character_ren_mean.pdf
- http://mefijunov.pbworks.com/f/how_to_chromecast_pictures_to_tv_from_mac.pdf
- https://uploads.strikinglycdn.com/files/915418cd-af18-4ec4-b74b-83743b7ade62/scope_of_work_social_media_marketing_template.pdf
- http://lenivuzuk.pbworks.com/f/papas_sushiria_hd_apk_download.pdf
- https://static.s123-cdn-static.com/uploads/4388046/normal_5ff281506612a.pdf
- https://uploads.strikinglycdn.com/files/08e61b6b-13b6-4505-a095-a536213460db/4105447969.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- archism.ru
- uploads.strikinglycdn.com
- bajaduxaxusi.pbworks.com
- binovilijire.pbworks.com
- cdn-cms.f-static.net
- mefijunov.pbworks.com
- lenivuzuk.pbworks.com
- static.s123-cdn-static.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report