MALICIOUS — bebelugavekufa.pdf
MALICIOUS — bebelugavekufa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
a26ef708569a406adde0a5d4ef845b61a910f3326056edf1358071ee0f6fcd97 - SHA-1:
897fa0e0de6a97e5431a1c137232fa95f4ea801a - MD5:
65d3a465777fbe5a51d6d523696a126e - ssdeep:
1536:UFhyXoxlBXJgr7MiGAaiY3c7fv0qTX9sytludK5/:4BlPgspivfv596y/ - TLSH:
T1DF36C0F37097EC8C6B4EAB5769AA0D485C46D68C30B287E414C8B76CC8F869D6F14D12 - Submitted as: bebelugavekufa.pdf
- File type: pdf · Size: 67581 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffset.ru/wb?keyword=btw%20aangifte%20nieuwbouw%20formulier, https://cdn-cms.f-static.net/uploads/4420039/normal_5fb9dbd586d47.pdf, https://uploads.strikinglycdn.com/files/ef6931a0-114f-4498-aeef-4043e65da9f6/podetusotezusarapopixegux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffset.ru/wb?keyword=btw%20aangifte%20nieuwbouw%20formulier
- https://cdn-cms.f-static.net/uploads/4420039/normal_5fb9dbd586d47.pdf
- https://uploads.strikinglycdn.com/files/ef6931a0-114f-4498-aeef-4043e65da9f6/podetusotezusarapopixegux.pdf
- https://uploads.strikinglycdn.com/files/09903e3b-0b59-49f1-9d57-d482716d6035/squeezo_strainer_for_sale.pdf
- https://sulabejo.weebly.com/uploads/1/3/4/6/134689147/ef8b7ae30.pdf
- https://uploads.strikinglycdn.com/files/4bc81138-634d-43cf-b4da-189855fde9d5/clark_the_shark_activities.pdf
- https://s3.amazonaws.com/fosagobomap/cisco_catalyst_2960xr-_24ts-_i_switch_datasheet.pdf
- https://nejufolij.weebly.com/uploads/1/3/4/8/134883139/xewujevulujuvu-jigejivivizetat-wanelema.pdf
- https://pafovawulawagi.weebly.com/uploads/1/3/4/5/134581771/tezuvaliv.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbdff4c145a8629dc76f837/1606287181374/tomonanagurelaxorirex.pdf
- https://uploads.strikinglycdn.com/files/ca73658c-1272-4e6c-89ee-8d80ebba7033/gunekurefadesujanajig.pdf
- https://uploads.strikinglycdn.com/files/6c897ded-4464-4927-af35-3443167c8f9f/kevegiwanasib.pdf
- https://gitinegu.weebly.com/uploads/1/3/4/6/134648864/1da264e728cd.pdf
- https://s3.amazonaws.com/lusabifef/fountain_pen_converter_guide.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbcf50eef3361272aeb5386/1606219022882/crime_scene_tool_box.pdf
- https://cdn-cms.f-static.net/uploads/4401983/normal_5fa6e32eed9fc.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffset.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- sulabejo.weebly.com
- s3.amazonaws.com
- nejufolij.weebly.com
- pafovawulawagi.weebly.com
- static1.squarespace.com
- gitinegu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report