MALICIOUS — b94b23fbb31279d5e3d1f36a167ea7d3d3877f823e921b5e0ef28b6a7c8129dc
MALICIOUS — b94b23fbb31279d5e3d1f36a167ea7d3d3877f823e921b5e0ef28b6a7c8129dc is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
b94b23fbb31279d5e3d1f36a167ea7d3d3877f823e921b5e0ef28b6a7c8129dc - SHA-1:
68d62a9405d0b96225ba152792341f12b1209097 - MD5:
8041f29f53f9b93dc960bc97fd29e282 - ssdeep:
1536:ye7x5Cpo/zeFrZTdGPUfPIsDb2lL3sy5LpfAMpCSdmXJJP0PSADa:v7j4obyrXGMnIaylLVAFX4PSh - TLSH:
T1C638D0F3519BDD4C3B9B6B07EE9312AC648EC78562318B500088BB7EC0AC67D7E51A50 - Submitted as: b94b23fbb31279d5e3d1f36a167ea7d3d3877f823e921b5e0ef28b6a7c8129dc
- File type: pdf · Size: 79620 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!8041F29F53F9
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://nomylo.ru/pbw?utm_term=let+it+go+piano+with+letters, https://xotinibawilufo.weebly.com/uploads/1/3/1/4/131437660/maripasi_lojozowofesog_lepemiwupudixa.pdf, https://uploads.strikinglycdn.com/files/bb3cf5c3-0748-4375-84b9-a06d050ea28b/hot_blast_wood_furnace_1557m_parts.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nomylo.ru/pbw?utm_term=let+it+go+piano+with+letters
- https://xotinibawilufo.weebly.com/uploads/1/3/1/4/131437660/maripasi_lojozowofesog_lepemiwupudixa.pdf
- https://uploads.strikinglycdn.com/files/bb3cf5c3-0748-4375-84b9-a06d050ea28b/hot_blast_wood_furnace_1557m_parts.pdf
- https://cdn-cms.f-static.net/uploads/4457279/normal_6065ac0608681.pdf
- https://uploads.strikinglycdn.com/files/e4719140-b145-4ea0-8374-b4a02ca3dc3a/nowajajakeje.pdf
- https://uploads.strikinglycdn.com/files/a6edf329-7bfb-4b50-9348-b72fe2bbad56/napudojekaril.pdf
- https://cdn-cms.f-static.net/uploads/4377931/normal_60ba5971b7a54.pdf
- http://vesusezipuwe.pbworks.com/f/lenovo_g50-70_touchpad_driver_windows_8.pdf
- https://cdn-cms.f-static.net/uploads/4403959/normal_603c7e122904b.pdf
- http://risanafupek.pbworks.com/w/file/fetch/145091178/avatar_the_promise_online.pdf
- https://lotuliwupufak.weebly.com/uploads/1/3/4/8/134873452/8695177.pdf
- http://rupuker.pbworks.com/f/pidagebopekodebidaz.pdf
- https://cdn-cms.f-static.net/uploads/4420939/normal_60489088420ae.pdf
- https://rafafokisot.weebly.com/uploads/1/3/4/7/134738004/9732a3b2.pdf
- http://risoxef.pbworks.com/w/file/fetch/144466761/numupujawugotoson.pdf
- http://gatasulupu.pbworks.com/w/file/fetch/144758343/acls_provider_manual_2020.pdf
- https://uploads.strikinglycdn.com/files/191a2b18-08e3-478d-8d18-cb5246fe021a/what_is_enthalpy_meaning.pdf
- https://uploads.strikinglycdn.com/files/2894309a-fc4f-4703-85fe-9383f3c67433/sovusokowuma.pdf
- https://zurowovilotupe.weebly.com/uploads/1/3/4/3/134329893/56b8e64ddc13.pdf
- http://tazijebep.pbworks.com/f/91587205795.pdf
- https://cdn-cms.f-static.net/uploads/4368504/normal_602105897fb2b.pdf
- https://losulojer.weebly.com/uploads/1/3/0/7/130739206/3370782.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- nomylo.ru
- xotinibawilufo.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- vesusezipuwe.pbworks.com
- risanafupek.pbworks.com
- lotuliwupufak.weebly.com
- rupuker.pbworks.com
- rafafokisot.weebly.com
- risoxef.pbworks.com
- gatasulupu.pbworks.com
- zurowovilotupe.weebly.com
- tazijebep.pbworks.com
- losulojer.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report