MALICIOUS — 1609acd0861d8e---ruvevafapunilagepat.pdf
MALICIOUS — 1609acd0861d8e---ruvevafapunilagepat.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
81b11bfe8e26d3390e2a4ff9067e89428956b048c403d4ad75e4bf9510c8ae58 - SHA-1:
1e26d0d97f0361d59fb52b5521d20dcb56152704 - MD5:
81b245ad253823f243467f3598739627 - ssdeep:
1536:ASrz3daRcUZpuHFShSLQ048TEJruYV5S9Phug3Z+0SqBLBTnG:NCpIOoQ0TTEJrPg3ZPhBlC - TLSH:
T13437CFF36157DC8CBA976F03AAE1102D648BE68970729A58544CF7ACD8BC2FC3E10951 - Submitted as: 1609acd0861d8e---ruvevafapunilagepat.pdf
- File type: pdf · Size: 74080 bytes
- Verdict: malicious (98/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!81B245AD2538
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!81B245AD2538 (rule
PDF/Phish-FAB!81B245AD2538) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://crysiq.ru/uplcv?utm_term=anime+character+generator++english, https://amkboiler.com/wp-content/plugins/super-forms/uploads/php/files/obabk4on9q53i5586vjpv2icol/sawixofajudiwobago.pdf, http://nc2e.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16092d203bb409---31581211066.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crysiq.ru/uplcv?utm_term=anime+character+generator++english
- https://amkboiler.com/wp-content/plugins/super-forms/uploads/php/files/obabk4on9q53i5586vjpv2icol/sawixofajudiwobago.pdf
- http://nc2e.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16092d203bb409---31581211066.pdf
- https://www.isnb.co.uk/wp-content/plugins/super-forms/uploads/php/files/cc5c49ba1b233c7922a6539a1b7e969f/faroxajozisufimibigalefo.pdf
- https://agenciaboom.com/wp-content/plugins/super-forms/uploads/php/files/96pmdjdobiv8mb4bqh6afoao63/sovunejorijepakatasune.pdf
- https://www.entornopublicitario.com/wp-content/plugins/super-forms/uploads/php/files/898200b0532a8eb3efd2e4c4dbbff53d/vavarofewonokojisuzov.pdf
- http://sewakendragroup.com/userfiles/file/86789236632.pdf
- https://saftanton.dk/wp-content/plugins/formcraft/file-upload/server/content/files/1606d675479987---fivipatiwuvenijepasenipaz.pdf
- https://polinagerz.ru/wp-content/plugins/super-forms/uploads/php/files/i5aatq90bpcn74nl5fm0mspqu8/26376778902.pdf
- https://www.verpoort-bouw.be/wp-content/plugins/formcraft/file-upload/server/content/files/1609094f36a3bf---wurevelerujeruvog.pdf
- https://area34.info/wp-content/plugins/super-forms/uploads/php/files/gs0m3kqbcglmhc5786hg22g4g5/zazube.pdf
- http://adanateknikservis.web.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16080f8e996cb2---babinekadajanape.pdf
- https://www.hemoroidklinigi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607af18091863---96458054460.pdf
- http://ednak.com/wp-content/plugins/formcraft/file-upload/server/content/files/16096097808c3e---tavezugijozit.pdf
- https://revapackers.com/wp-content/plugins/super-forms/uploads/php/files/3k4dsj31kt5fg84fq5l2bog79i/netinitumelivafasejusofo.pdf
- https://www.cukoyem.com.tr/wp-content/plugins/super-forms/uploads/php/files/9cuhabiec8f0ns0ajj8bo2sjp3/fulixenoze.pdf
- https://vmkstroi.ru/wp-content/plugins/super-forms/uploads/php/files/a6784618cf226f047309e223d63f0c05/nubaruliwirotefaxalakotob.pdf
- https://www.fifatravels.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607f4f9f590a6---silerogifegejanati.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- crysiq.ru
- amkboiler.com
- nc2e.fr
- www.isnb.co.uk
- agenciaboom.com
- www.entornopublicitario.com
- sewakendragroup.com
- polinagerz.ru
- www.verpoort-bouw.be
- area34.info
- www.hemoroidklinigi.com
- ednak.com
- revapackers.com
- vmkstroi.ru
- www.fifatravels.com
- www.w3.org
- purl.org
- ns.adobe.com
- saftanton.dk
- adanateknikservis.web.tr
- www.cukoyem.com.tr
File paths
- z:\[I/
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report