MALICIOUS — nakipigakazus-xufozafi-gafigotuk-fuxojo.pdf
MALICIOUS — nakipigakazus-xufozafi-gafigotuk-fuxojo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
877b11819e7bc2f2a8da180a78a457e71657837bb79e8d5ad4b57d61e353e5d3 - SHA-1:
5abb188dca79e6442e6cf46d3eef25cb2cee24be - MD5:
41342afe7a07f523d49a3b3456157ee7 - ssdeep:
1536:xLzsVVEsqd0yQJvMb2CnY3Naj2jYs6mQs1nuZt3nIVPlM5Ok/3RjKBGSlK5:WEH0JJvMb2AUsjcAguZt3nX/5Ww - TLSH:
T11737D0F3A1C7DE487A9A8F536DFA151D2189D398A032C7253588B66C84783BE7E10E11 - Submitted as: nakipigakazus-xufozafi-gafigotuk-fuxojo.pdf
- File type: pdf · Size: 72682 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafffe.ru/wb?keyword=spinach%20chromatography%20lab%20answers, https://fofavaduk.weebly.com/uploads/1/3/4/4/134436242/dorexomibuviga_wupazafop.pdf, https://cdn-cms.f-static.net/uploads/4371791/normal_5f8a67bff1861.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/wb?keyword=spinach%20chromatography%20lab%20answers
- https://fofavaduk.weebly.com/uploads/1/3/4/4/134436242/dorexomibuviga_wupazafop.pdf
- https://cdn-cms.f-static.net/uploads/4371791/normal_5f8a67bff1861.pdf
- https://judemozosuduj.weebly.com/uploads/1/3/4/3/134306717/tazupati.pdf
- https://cdn-cms.f-static.net/uploads/4417145/normal_5f9cc385129fa.pdf
- https://uploads.strikinglycdn.com/files/a969eeba-6774-4701-ba16-93610bbb3e40/the_harry_potter_movie_series_in_order.pdf
- https://fijudemi.weebly.com/uploads/1/3/4/4/134400988/2350427.pdf
- https://morutasatosode.weebly.com/uploads/1/3/4/3/134366393/e7070ac27e0.pdf
- https://uploads.strikinglycdn.com/files/32616846-468f-4f2c-918a-a05c2bd8d8c2/febavisiwidipinatid.pdf
- https://pekedilude.weebly.com/uploads/1/3/4/3/134324883/7896443.pdf
- https://lorovojiwu.weebly.com/uploads/1/3/4/3/134318747/83e257fa4e17.pdf
- https://s3.amazonaws.com/wazotojemov/cos_my_banner_web_login.pdf
- https://rinalodejivew.weebly.com/uploads/1/3/4/3/134383373/070e5bbf355.pdf
- https://guxitubekin.weebly.com/uploads/1/3/4/2/134267073/a9453fd11b.pdf
- https://pezopipowom.weebly.com/uploads/1/3/1/4/131406060/d9432a51c7311a1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- fofavaduk.weebly.com
- cdn-cms.f-static.net
- judemozosuduj.weebly.com
- uploads.strikinglycdn.com
- fijudemi.weebly.com
- morutasatosode.weebly.com
- pekedilude.weebly.com
- lorovojiwu.weebly.com
- s3.amazonaws.com
- rinalodejivew.weebly.com
- guxitubekin.weebly.com
- pezopipowom.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report