MALICIOUS — 13971.pdf
MALICIOUS — 13971.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
855565248fc7b3a3257ec8030f211d8d715f347f4ccf2ca3e440a9bc1569cde4 - SHA-1:
793f5439d6cc427c90638e178e42541e31ab03b9 - MD5:
b732979e41bbdf9b8ed60fa46bbc94ca - ssdeep:
768:oP5zTglnwLdyx5dKAF9Pdt9BBxPIZuLOR/9O73/D2KkXtaRWufsJ71q4NDiO++8J:oPpgWklKuPfxQZuLbKZtl71tiVxygMC - TLSH:
T1F536C0F3729BCC8C6A8BAB43A9B6055D658ED7C4213F87604488B6BD807877D3F11A11 - Submitted as: 13971.pdf
- File type: pdf · Size: 64207 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=ingenuity%20baby%20swing%20instruction%20manual, https://uploads.strikinglycdn.com/files/3ffaad76-ecea-42d1-b18b-19f7a9d44e60/sfgov_org_paystub.pdf, https://kavanezeso.weebly.com/uploads/1/3/4/4/134477356/sowasu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ingenuity%20baby%20swing%20instruction%20manual
- https://uploads.strikinglycdn.com/files/3ffaad76-ecea-42d1-b18b-19f7a9d44e60/sfgov_org_paystub.pdf
- https://kavanezeso.weebly.com/uploads/1/3/4/4/134477356/sowasu.pdf
- https://cdn-cms.f-static.net/uploads/4366364/normal_5f8cf26c8cd0e.pdf
- https://cdn-cms.f-static.net/uploads/4387571/normal_5f98fbd7c44fc.pdf
- https://uploads.strikinglycdn.com/files/c953e77f-596e-4c26-a413-ba9944b01aab/kuniji.pdf
- https://uploads.strikinglycdn.com/files/7bfac136-cf5e-4b3f-8960-5cb88f0fbd51/are_trees_and_abiotic_or_biotic.pdf
- https://uploads.strikinglycdn.com/files/678424d7-09a4-42e2-86ec-823af7fee87e/64686169115.pdf
- https://s3.amazonaws.com/pedokeza/5950130351.pdf
- https://uploads.strikinglycdn.com/files/f91ec5ed-5f59-416d-966f-d498b7754088/skeleton_waiting_for_approval_meme.pdf
- https://cdn-cms.f-static.net/uploads/4408475/normal_5f9287ee011b4.pdf
- https://s3.amazonaws.com/gafedupeba/application_of_computer_in_hospital_pharmacy.pdf
- https://uploads.strikinglycdn.com/files/60a7e8a8-3da8-42a5-9701-49e3fd4025a9/godzilla_king_of_the_monsters_subtit.pdf
- https://cdn-cms.f-static.net/uploads/4374835/normal_5f932ef466352.pdf
- https://uploads.strikinglycdn.com/files/d0e2e796-274a-4a4d-8cfb-42acbfea2e49/kezefabaziraxajapenepibox.pdf
- https://s3.amazonaws.com/xenavuxa/desnutricion_anemia_y_sobrepeso_infantil_en_el_peru.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- kavanezeso.weebly.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report