MALICIOUS — 65056e130bf941256f4d124a7f3a49a863f41f1e6e48bf64837f06c66290c513
MALICIOUS — 65056e130bf941256f4d124a7f3a49a863f41f1e6e48bf64837f06c66290c513 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
65056e130bf941256f4d124a7f3a49a863f41f1e6e48bf64837f06c66290c513 - SHA-1:
a9d999e7fa134154faadb5d4a587cfc40191bd65 - MD5:
e73b2f1363262e3ec75e63e6629e444c - ssdeep:
1536:PqrYL9kGSHgi0fwVx4g3orPG4E3hSxfs/D55smEyj:v9tSAi0fyoDG3mfs/HsmN - TLSH:
T12B37D0F35057EC8CBA5A5B139EBA589D748ED3492137A79048C87B2CC5AC6AE7E10C40 - Submitted as: 65056e130bf941256f4d124a7f3a49a863f41f1e6e48bf64837f06c66290c513
- File type: pdf · Size: 76241 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!E73B2F136326
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://wastran.ru/pbw?utm_term=qismat+movie+hd+download, https://static.s123-cdn-static.com/uploads/4412161/normal_5fcf330cf3aa4.pdf, https://rujapunilibufig.weebly.com/uploads/1/3/4/7/134713438/5340348.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://wastran.ru/pbw?utm_term=qismat+movie+hd+download
- https://static.s123-cdn-static.com/uploads/4412161/normal_5fcf330cf3aa4.pdf
- https://rujapunilibufig.weebly.com/uploads/1/3/4/7/134713438/5340348.pdf
- https://uploads.strikinglycdn.com/files/a5a105e2-ac03-4724-a76e-eaa159643b3d/vakulelibulikogokezaw.pdf
- https://cdn-cms.f-static.net/uploads/4416666/normal_6034c3a7127b4.pdf
- https://ralakugifobiw.weebly.com/uploads/1/3/4/5/134589758/4277567.pdf
- https://dujedagopodiku.weebly.com/uploads/1/3/4/5/134580966/eaf457.pdf
- https://sojisesoto.weebly.com/uploads/1/3/1/4/131437607/xupetufazizaz-zugosopo-logubuxusoj.pdf
- https://zemibojonu.weebly.com/uploads/1/3/5/3/135324970/2074279.pdf
- https://uploads.strikinglycdn.com/files/9bb873c9-7682-4ee4-9a8f-8f6a1f92ac25/samsung_scx-3405fw_printer_driver_for_mac.pdf
- https://uploads.strikinglycdn.com/files/095085a1-d06f-4b0e-883e-3d27262b564b/22517716826.pdf
- https://uploads.strikinglycdn.com/files/0058866c-572d-4fbf-b7c5-41e8699820ac/do_chanel_shoes_run_small.pdf
- https://uploads.strikinglycdn.com/files/41e5d1bd-76cf-4965-89c3-cb237b0e04e0/how_to_use_dyson_ball_on_thick_carpet.pdf
- https://webejalabedag.weebly.com/uploads/1/3/7/5/137518867/nusubowanazagu.pdf
- https://cdn-cms.f-static.net/uploads/4467564/normal_6056024c2afd0.pdf
- https://uploads.strikinglycdn.com/files/469df6f7-1afe-412e-8062-98cfe120a06c/samsung_tv_software_update_error_606.pdf
- https://ruzudafuzozuxu.weebly.com/uploads/1/3/4/8/134847081/8274470.pdf
- https://fagugirawax.weebly.com/uploads/1/3/4/3/134388021/9904936.pdf
- https://uploads.strikinglycdn.com/files/15038dc2-fe89-4233-8b40-a71a034ca557/how_to_remove_bassinet_from_graco_pack_and_play.pdf
- https://cdn-cms.f-static.net/uploads/4456135/normal_6033579b869f9.pdf
- https://uploads.strikinglycdn.com/files/889d0065-7c47-4d1c-84d2-dfb0ae33acb7/10-3_practice_areas_of_regular_polygons_form_k_answer_key.pdf
- https://cdn-cms.f-static.net/uploads/4454048/normal_6039cb85b7a1b.pdf
- https://nuruvubapifak.weebly.com/uploads/1/3/1/4/131452890/ravevasagor.pdf
- https://uploads.strikinglycdn.com/files/5115bfb2-e17d-4fdb-9e56-825396f246cc/13210783782.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- wastran.ru
- static.s123-cdn-static.com
- rujapunilibufig.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- ralakugifobiw.weebly.com
- dujedagopodiku.weebly.com
- sojisesoto.weebly.com
- zemibojonu.weebly.com
- webejalabedag.weebly.com
- ruzudafuzozuxu.weebly.com
- fagugirawax.weebly.com
- nuruvubapifak.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- U:\Q
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report