MALICIOUS — nigolixanelet.pdf
MALICIOUS — nigolixanelet.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
a3f1d41d533b976e0f5ee32cd43c136311bb9982537a113ccc134649b4e5579a - SHA-1:
60b8161d34ee2ff9462388c45f8791547b7b8ba9 - MD5:
b4e4aa2a14f710d97fd2a58518777e14 - ssdeep:
3072:1EgPGZ0hWpMPgHp/jbhe9zloKhxS3buoOP/CXKDiI//cW:1TPG3p/jbe/g9OP/Cjs - TLSH:
T1EC3CF1F35297CD4DB68B5B63B9B5222960CEE32C6071979804C8716C84B9EFD2C25E21 - Submitted as: nigolixanelet.pdf
- File type: pdf · Size: 119057 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffking.ru/wb?keyword=scientific%20calculator%20app%20android, https://static1.squarespace.com/static/5fc72439f2297e36a9fcf3c7/t/5fc8aa4bd6e0cc37e3422174/1606986320012/xinivag.pdf, https://cdn-cms.f-static.net/uploads/4409092/normal_5f9355201d4c4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/wb?keyword=scientific%20calculator%20app%20android
- https://static1.squarespace.com/static/5fc72439f2297e36a9fcf3c7/t/5fc8aa4bd6e0cc37e3422174/1606986320012/xinivag.pdf
- https://cdn-cms.f-static.net/uploads/4409092/normal_5f9355201d4c4.pdf
- https://s3.amazonaws.com/kozikixoju/96408773920.pdf
- https://cdn-cms.f-static.net/uploads/4402963/normal_5f97017b199da.pdf
- https://uploads.strikinglycdn.com/files/747ead4a-1e9f-45bb-8a2b-50ffca2257d6/20178079917.pdf
- https://cdn-cms.f-static.net/uploads/4417534/normal_5f960384e5c87.pdf
- https://s3.amazonaws.com/jajuzasalikirut/36283902466.pdf
- https://uploads.strikinglycdn.com/files/ca238e5a-f3dd-4760-b458-31f5033a5732/68249715788.pdf
- https://rurasudi.weebly.com/uploads/1/3/4/4/134485231/45b0aedb1c.pdf
- https://cdn-cms.f-static.net/uploads/4486045/normal_5fa93c40d57e0.pdf
- https://static1.squarespace.com/static/5fc5a0ade2fce462bcac1c8d/t/5fce0f63c00f007cea0efd2c/1607339876514/56141202044.pdf
- https://cdn-cms.f-static.net/uploads/4370533/normal_5f88627498560.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- static1.squarespace.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- rurasudi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report