MALICIOUS — pawigagad.pdf
MALICIOUS — pawigagad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
b5907cadae85f2e2847e1c14cd24facc95dac6b1d6b1cbb556f7ea64edf7de58 - SHA-1:
b15b854f2a6f6b57ce15c9e5f52e2c7548a56d91 - MD5:
d05eb2888d54c6c18a10c89ece840a79 - ssdeep:
1536:7YpSvQ3MIw0VDJU0NfMdlTl1pVkPnefXi1sD7LRyDGl8+up328CF:spSv+MIU6fMdlTDpVkPn01Ryo8+uA7 - TLSH:
T1C838C0F370D7CE9CB68BBB836DA515BC909AD3C5616393500988B32C91782EE7F04562 - Submitted as: pawigagad.pdf
- File type: pdf · Size: 79693 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D05EB2888D54
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://nosinoski.shop/sofewumezagadelipijugs08g.pdf, http://smartcreditus.info/benerazukomuliz15yd.pdf, https://cdn.sqhk.co/kuxixixixi/gdgSij9/37552242322.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/jJyWpsOf3IE/wb?keyword=best%20superhero%20graphic%20novels%20for%20adults
- http://nosinoski.shop/sofewumezagadelipijugs08g.pdf
- http://smartcreditus.info/benerazukomuliz15yd.pdf
- https://cdn.sqhk.co/kuxixixixi/gdgSij9/37552242322.pdf
- https://uploads.strikinglycdn.com/files/a34c301c-4d6f-4864-bf5e-57475a91e7cb/john_deere_lx255_mower_deck_parts.pdf
- http://xibesofene.22web.org/35045460355.pdf
- https://cdn.sqhk.co/beratinuga/bhckGEX/crash_cars_toys.pdf
- http://getdouche.xyz/monti_bristle_blaster1ln5h.pdf
- https://uploads.strikinglycdn.com/files/722c0256-97ab-419b-b928-8daf92416131/rizuvejuvimewapuminifar.pdf
- http://bestita.space/what_is_processing_in_psychology9amo9.pdf
- http://bemuvubovewe.epizy.com/lg_washing_machine_service_near_me.pdf
- https://cdn.sqhk.co/zerurukoraju/o9f9ihz/30379454021.pdf
- http://kumagubugudaxu.rf.gd/48105979072.pdf
- https://uploads.strikinglycdn.com/files/f5594a17-60c0-49e1-ad25-72231b76db06/how_to_teach_sentence_structure_to_kindergarten.pdf
- https://uploads.strikinglycdn.com/files/024a71c7-b884-4b1b-9001-2d1e95bc2e73/xibenexage.pdf
- https://s3.amazonaws.com/piradi/48165745432.pdf
- http://paruweropu.iblogger.org/ranalisotobugima.pdf
- https://uploads.strikinglycdn.com/files/7cb44cfa-500f-49c8-b58d-2163448412c5/juniper_bgp_vrf_configuration_example.pdf
- https://cdn.sqhk.co/wixexozesila/e9jcPqU/retroarch_ps2_bios_files.pdf
- https://s3.amazonaws.com/dusined/57330676034.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- w.no
- feedproxy.google.com
- nosinoski.shop
- smartcreditus.info
- cdn.sqhk.co
- uploads.strikinglycdn.com
- xibesofene.22web.org
- getdouche.xyz
- bestita.space
- bemuvubovewe.epizy.com
- s3.amazonaws.com
- paruweropu.iblogger.org
- www.w3.org
- purl.org
- ns.adobe.com
- kumagubugudaxu.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report