MALICIOUS — 7743614.pdf
MALICIOUS — 7743614.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
6c53aab8425d3254928f3dce5e9e0a8674784fa4b93ef8cf255edbf04c5dfab7 - SHA-1:
68e932b042b142f76ab404cb567d7c1b44cb6745 - MD5:
4cd455985700487adac0309b209eab5c - ssdeep:
1536:ftQ0IkZC4w4KNNWPlU5GBkh2iSPOrdF0TnB18OfCWJxapH:FQnkEVN2+4G2iSmrdF0bn9JxY - TLSH:
T18A37D0F32697EC8D7B8AAF4355EA016D60AAD6496033E5E804407A2DC57C2BD7E20C70 - Submitted as: 7743614.pdf
- File type: pdf · Size: 75051 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=angular%205%20bootstrap%20admin%20template, https://faxuledobiwud.weebly.com/uploads/1/3/4/3/134311760/2ac4e142.pdf, https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/toxilemak_timabikor_loxetufovi_duponume.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=angular%205%20bootstrap%20admin%20template
- https://s3.amazonaws.com/gupuso/52706746950.pdf
- https://faxuledobiwud.weebly.com/uploads/1/3/4/3/134311760/2ac4e142.pdf
- https://s3.amazonaws.com/sabegokek/fikosowenovugekitamopi.pdf
- https://s3.amazonaws.com/pomaxa/zara_baby_girl_shoe_size_guide.pdf
- https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/toxilemak_timabikor_loxetufovi_duponume.pdf
- https://uploads.strikinglycdn.com/files/50a02bae-0e72-4a51-a0d5-3ff1cc09bcb9/vusativilupinuz.pdf
- https://guvodirafed.weebly.com/uploads/1/3/4/4/134475496/8adb28eecda.pdf
- https://s3.amazonaws.com/zuxadol/tidutobuzubufibulesikuku.pdf
- https://dawugagulinejud.weebly.com/uploads/1/3/4/3/134368664/nezid.pdf
- https://s3.amazonaws.com/risisipajole/iphone_xr_text_number_changed_to_primary.pdf
- https://zedaluridafam.weebly.com/uploads/1/3/4/4/134464222/f2d3462.pdf
- https://s3.amazonaws.com/xenavuxa/12455117555.pdf
- https://cdn-cms.f-static.net/uploads/4375353/normal_5fa1029c20a1c.pdf
- https://uploads.strikinglycdn.com/files/57458daa-7e85-47a4-bff0-75a4f88e1a45/85077615931.pdf
- https://zozabamefopofa.weebly.com/uploads/1/3/4/2/134234868/9288153.pdf
- https://s3.amazonaws.com/fujadabez/zezorujexeviwefiza.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- faxuledobiwud.weebly.com
- nipufijupetobug.weebly.com
- uploads.strikinglycdn.com
- guvodirafed.weebly.com
- dawugagulinejud.weebly.com
- zedaluridafam.weebly.com
- cdn-cms.f-static.net
- zozabamefopofa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report