MALICIOUS — 13620260682.pdf
MALICIOUS — 13620260682.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
b77b441926d4aac4a97d9f2e9f2d8b3c3e1f27ae76d77847a1da7cc42f3195e7 - SHA-1:
da4e8fc65cca87da4a3379f54baa67c3a29f71f7 - MD5:
59fb6f4556753ee347f24234c317e241 - ssdeep:
1536:yV5xpyX42tRU8yERn3cgvczI7GoOqS6TO7lQG5poW/K9I+rufWLd:4PpyI2zB3TUzKGvqSj7l9S9I+rufI - TLSH:
T13F38D0F36197DD8D7BC6DB4368A654687185DA8D6132CA601088B77CC438AFE7C60EA0 - Submitted as: 13620260682.pdf
- File type: pdf · Size: 79478 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafffe.ru/strik?keyword=krunker+hacks+aimbot+no+download, https://cdn-cms.f-static.net/uploads/4384029/normal_5f9996b4f1bd9.pdf, https://cdn-cms.f-static.net/uploads/4415544/normal_5f97dfe15fc50.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/strik?keyword=krunker+hacks+aimbot+no+download
- https://cdn-cms.f-static.net/uploads/4384029/normal_5f9996b4f1bd9.pdf
- https://s3.amazonaws.com/zirojopemup/sintrom_amann_girrbach.pdf
- https://s3.amazonaws.com/fadedosi/negolavevefebaj.pdf
- https://cdn-cms.f-static.net/uploads/4415544/normal_5f97dfe15fc50.pdf
- https://nabesoke.weebly.com/uploads/1/3/4/0/134042749/2960678.pdf
- https://s3.amazonaws.com/vufupu/wiledabemisisititafik.pdf
- https://s3.amazonaws.com/bewibiwat/melug.pdf
- https://s3.amazonaws.com/boxujetanonikuv/precalculus_final_study_guide.pdf
- https://uploads.strikinglycdn.com/files/c83729e1-150a-41d8-9f74-5194dc8cc1e3/37981561057.pdf
- https://s3.amazonaws.com/bubodeliza/zaroxip.pdf
- https://jujizifij.weebly.com/uploads/1/3/4/3/134309807/a9253.pdf
- https://s3.amazonaws.com/mexavofezoxi/human_body_systems_organs_and_functions.pdf
- https://s3.amazonaws.com/kabisebax/caron_simply_soft_party_yarn_royal_sparkle.pdf
- https://uploads.strikinglycdn.com/files/56d6213e-7aee-40fe-9e37-1744606fb6e0/27863410763.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- nabesoke.weebly.com
- uploads.strikinglycdn.com
- jujizifij.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report