MALICIOUS — ce4054cb20.pdf
MALICIOUS — ce4054cb20.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
a46cc72df6fcc7a6a122a86a037a9bd4916f4f2a4cbe5811c51c5c2ad75f82b5 - SHA-1:
88dd34415197273772f2d119be72646cda532093 - MD5:
14d10dea5f131bba6e2a8f4fe6aa840d - ssdeep:
1536:hpBE8hoXZIYBNzZE1d35PWstHt7/uDFL3ix4S73L9YdRfICldfvDGu:bsD4d39PFW4xXn9YdRgCldfz - TLSH:
T11837D0F36193CDCC764557172EFB1A2C50838A887836DF886484B72CE87C6AD7E51A60 - Submitted as: ce4054cb20.pdf
- File type: pdf · Size: 75010 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=ielts%20writing%20task%201%20general%20sample%20answers, https://static1.squarespace.com/static/5fc285aae5c7695ca9a5ff19/t/5fcad73933fb14715caed0fc/1607128890393/9615522063.pdf, https://static1.squarespace.com/static/5fc130cd8787e879896ddc20/t/5fcaae96f7b7a17f4cfaa81c/1607118488096/pukunodogilagewix.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ielts%20writing%20task%201%20general%20sample%20answers
- https://s3.amazonaws.com/begijufadi/fenabijokatumolide.pdf
- https://static1.squarespace.com/static/5fc285aae5c7695ca9a5ff19/t/5fcad73933fb14715caed0fc/1607128890393/9615522063.pdf
- https://s3.amazonaws.com/batoragubukepo/learning_autocad_plant_3d.pdf
- https://static1.squarespace.com/static/5fc130cd8787e879896ddc20/t/5fcaae96f7b7a17f4cfaa81c/1607118488096/pukunodogilagewix.pdf
- https://static1.squarespace.com/static/5fc4d95c3398ff75154720e4/t/5fc6d70a7995075abdd13964/1606866702670/netubaropikus.pdf
- https://s3.amazonaws.com/tojabixefova/tank_trouble_sites.pdf
- https://static1.squarespace.com/static/5fc0c87788c99b6d37a67a80/t/5fc3042161e25426e19b7e88/1606616098633/how_has_microsoft_office_changed_the_world.pdf
- https://s3.amazonaws.com/nilititonawafim/83635504663.pdf
- https://static1.squarespace.com/static/5fc07dde27a199023ab34438/t/5fc344b4f81c9a2a0c0bb2f8/1606632634465/pathfinder_advanced_class_guide_free_download.pdf
- https://s3.amazonaws.com/vexeliku/www.chase.com_log_on.pdf
- https://s3.amazonaws.com/vibuvomomuv/super_mario_flash_2_version_c.pdf
- https://s3.amazonaws.com/wifukedot/audio_recorder_app_for_android.pdf
- https://s3.amazonaws.com/vibasujefir/57918118392.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- static1.squarespace.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report