MALICIOUS — f6e461cbd401094.pdf
MALICIOUS — f6e461cbd401094.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
68b66634d26397be5106ab03da858f405d512c69183239da023e5757bdad27d9 - SHA-1:
bc3fbe33bca486ef7835e44853a33a2603423a0d - MD5:
0e9d9e20943651ba5301b1cae2098546 - ssdeep:
1536:GJ9cDIovrBsUv943MTQgbRrrTvrDfKGvlQNFhna7B:G0IsrBsUv9ESbRrrTiGNQNFhnG - TLSH:
T1EA35C0F3B147DD8C3AC99F47ABB7042D554EC6446132DAA044D8B72C84B8B5E3E24E61 - Submitted as: f6e461cbd401094.pdf
- File type: pdf · Size: 60141 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafffi.ru/wb?keyword=kindergarten%20rhyming%20words%20worksheets%20pdf, https://tiferivirukituk.weebly.com/uploads/1/3/4/4/134433041/jebani.pdf, https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe03553485235c868bf00d/1606288213758/juremejevogavifusili.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffi.ru/wb?keyword=kindergarten%20rhyming%20words%20worksheets%20pdf
- https://tiferivirukituk.weebly.com/uploads/1/3/4/4/134433041/jebani.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe03553485235c868bf00d/1606288213758/juremejevogavifusili.pdf
- https://cdn-cms.f-static.net/uploads/4417419/normal_5f9573170b480.pdf
- https://cdn-cms.f-static.net/uploads/4424692/normal_5f981ac9ccc93.pdf
- https://cdn-cms.f-static.net/uploads/4381318/normal_5fa9196a1c4e7.pdf
- https://static1.squarespace.com/static/5fc14b808139af037647f366/t/5fc6fb13a3696915e218fbee/1606875923333/57081917357.pdf
- https://cdn-cms.f-static.net/uploads/4382638/normal_5f9a327487443.pdf
- https://uploads.strikinglycdn.com/files/f8e87690-4fb8-448c-944f-2a8189fd3bd1/25292997267.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbd07e0d334513fae436bf7/1606223841740/2300705952.pdf
- https://watuwejaxor.weebly.com/uploads/1/3/4/4/134437052/fosiduzuwoposafofusi.pdf
- https://uploads.strikinglycdn.com/files/b1b861dd-a17c-4df6-bba2-109b1d6d73d7/52098438183.pdf
- https://uploads.strikinglycdn.com/files/30aa7322-1985-4563-865b-29217894f0c8/datej.pdf
- https://uploads.strikinglycdn.com/files/1c8b21d9-31c7-4460-a5dd-743919b72f01/45218990236.pdf
- https://uploads.strikinglycdn.com/files/576abcc6-528f-4703-beaf-57a56677aee0/96038362020.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffi.ru
- tiferivirukituk.weebly.com
- static1.squarespace.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- watuwejaxor.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report