MALICIOUS — how_to_access_the_camera_on_hp_laptop.pdf
MALICIOUS — how_to_access_the_camera_on_hp_laptop.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
941af1b02be295e210a87eb051fbf71d472a8679058282b0f3cf11bd7244d497 - SHA-1:
bd4547ddce50c98bb723ccae4b9ca80a898791ff - MD5:
610b56f8d43f87fab828c4b44c880b0d - ssdeep:
1536:MBgxYJLOuHMT/TMH+i4hYwT7tNa6hpRJ4NPllMJWXD5UXLOqSqROnpiFCs:HxlowMkYktNaQROWS5U7OqBROn8FF - TLSH:
T1CF37C0B32197DD9CB5CB9703ADE715ADA59AC2887032DBB000C8B65CC178ABF2E24551 - Submitted as: how_to_access_the_camera_on_hp_laptop.pdf
- File type: pdf · Size: 72373 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!610B56F8D43F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://philabc.ru/pbw?utm_term=how+to+access+the+camera+on+hp+laptop, https://uploads.strikinglycdn.com/files/e5be65de-431b-44f0-8a82-2bc12cc63700/panasonic_kx-tge233b_manual.pdf, https://uploads.strikinglycdn.com/files/6c68a372-7503-4d7c-b207-c4cb59705146/lexique_juridique_franais_arabe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://philabc.ru/pbw?utm_term=how+to+access+the+camera+on+hp+laptop
- https://uploads.strikinglycdn.com/files/e5be65de-431b-44f0-8a82-2bc12cc63700/panasonic_kx-tge233b_manual.pdf
- https://uploads.strikinglycdn.com/files/6c68a372-7503-4d7c-b207-c4cb59705146/lexique_juridique_franais_arabe.pdf
- http://pezeliv.pbworks.com/f/mckenzie_technique_for_herniated_disc.pdf
- https://uploads.strikinglycdn.com/files/d236a559-810a-4d11-846c-eea67e5b2ce0/pafefum.pdf
- https://uploads.strikinglycdn.com/files/8681b84e-4121-4781-a302-f49b872e9f13/what_size_bobbin_for_singer.pdf
- https://cdn-cms.f-static.net/uploads/4484383/normal_6059b25dc8b93.pdf
- https://uploads.strikinglycdn.com/files/e934e715-7dd3-4abd-b5ec-a306dfdbb764/40636287374.pdf
- http://togusan.pbworks.com/f/80958083535.pdf
- https://cdn-cms.f-static.net/uploads/4492892/normal_6054f3b424b82.pdf
- https://uploads.strikinglycdn.com/files/c315cad1-4e98-4495-9bdf-4c5e94d83bd1/is_it_ok_to_stretch_sore_muscles.pdf
- http://tubekikewabi.pbworks.com/w/file/fetch/144440499/91995462607.pdf
- https://static.s123-cdn-static.com/uploads/4407996/normal_60021748988cd.pdf
- http://bofamawetodo.pbworks.com/f/13327815952.pdf
- https://uploads.strikinglycdn.com/files/57a61593-38c9-4393-9ad9-13f6973c1a67/best_double_jogging_stroller_with_car_seat_adapter.pdf
- https://cdn-cms.f-static.net/uploads/4383807/normal_604b2d20622eb.pdf
- https://uploads.strikinglycdn.com/files/c38329e5-fc21-47d9-ba57-a04553d1e80d/westworld_season_3_episode_6_script.pdf
- https://uploads.strikinglycdn.com/files/c7cd756f-012b-4652-bb4c-5102b862935d/difurunagopilewogapar.pdf
- https://uploads.strikinglycdn.com/files/8c0c10d7-7ba6-4574-a617-d33bea9d17a7/how_does_justines_death_affect_victor.pdf
- https://static.s123-cdn-static.com/uploads/4445877/normal_6006556ab8022.pdf
- https://uploads.strikinglycdn.com/files/b60455fe-496f-47b6-81b3-aef647a63bc3/how_to_reset_samsung_refrigerator_error_code_8e.pdf
- http://kefimazusob.pbworks.com/f/vowukigik.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- philabc.ru
- uploads.strikinglycdn.com
- pezeliv.pbworks.com
- cdn-cms.f-static.net
- togusan.pbworks.com
- tubekikewabi.pbworks.com
- static.s123-cdn-static.com
- bofamawetodo.pbworks.com
- kefimazusob.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report