MALICIOUS — 2949169.pdf
MALICIOUS — 2949169.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
b5b0bf947078c02eb5b11597521ea1f8ae965f73e0cae585a90c24aa04fb4254 - SHA-1:
054da8e3f01fa69b384078f97f4875a7a1246363 - MD5:
165055a9fca118712cb270449b02914b - ssdeep:
1536:bjVMV9hrbyYIU4KiFEydUYj2VjyoBjYdSgKmRIGrHA8lepu:dUhrG1bK0EydHwjBBlyIo/lz - TLSH:
T14739E1B3509BCE4C7FC34B571AB621592487E39C5022CBA058D97A3C887C6BD7E21B91 - Submitted as: 2949169.pdf
- File type: pdf · Size: 85822 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafffi.ru/wb?keyword=divine%20divinity%20original%20sin%20crafting%20guide, https://static1.squarespace.com/static/5fbfda27a5bc066edf9fc50f/t/5fc516f0e18c5c478e9cb3c4/1606751987780/41125419441.pdf, https://rutujuxifir.weebly.com/uploads/1/3/4/6/134632780/salaxegeletijaketi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffi.ru/wb?keyword=divine%20divinity%20original%20sin%20crafting%20guide
- https://s3.amazonaws.com/zarelusipofox/domesatisedu.pdf
- https://static1.squarespace.com/static/5fbfda27a5bc066edf9fc50f/t/5fc516f0e18c5c478e9cb3c4/1606751987780/41125419441.pdf
- https://rutujuxifir.weebly.com/uploads/1/3/4/6/134632780/salaxegeletijaketi.pdf
- https://s3.amazonaws.com/bunobu/34734223085.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rezareludufiven-voxodopi.pdf
- https://nurosamemozixa.weebly.com/uploads/1/3/4/3/134375837/vugodavezuf.pdf
- https://cdn-cms.f-static.net/uploads/4367656/normal_5fa30b54d9c3f.pdf
- https://s3.amazonaws.com/zuxadol/qci_yoga_book_in_hindi_free_download.pdf
- https://s3.amazonaws.com/pusolefosex/diccionario_de_administracion_publica_colombiana.pdf
- https://pozegitewo.weebly.com/uploads/1/3/4/7/134758724/bbdcd248f893.pdf
- https://uploads.strikinglycdn.com/files/93564710-0c65-4a6d-8ee6-a7352905d1e9/watership_down_richard_adams_epub.pdf
- https://s3.amazonaws.com/tumasun/xupasavonuxi.pdf
- https://s3.amazonaws.com/robumuduluwise/aisi_4140_standard.pdf
- https://uploads.strikinglycdn.com/files/64aafe80-1b7f-4b56-9d9d-bb5485975f33/81154237869.pdf
- https://static1.squarespace.com/static/5fc1138816f6d44b07bfcb5c/t/5fc157d79d79364840bf885c/1606506456111/ziwafaloguvitipubudi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffi.ru
- s3.amazonaws.com
- static1.squarespace.com
- rutujuxifir.weebly.com
- vuxozajuje.weebly.com
- nurosamemozixa.weebly.com
- cdn-cms.f-static.net
- pozegitewo.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report