MALICIOUS — 677001.pdf
MALICIOUS — 677001.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
bb11ffc2a89c9fba8c47444c6b557f0a7d242e2f71c871e0c23936d3a04d5b7d - SHA-1:
9d77c55d449dda52afe02d21d4cd1c82eb195202 - MD5:
dfb2d790fb8601e1064e499430f44b3b - ssdeep:
1536:HNG6kKgX1lR8ayEvK3eSyxuV0QX+G5yx7kkBPqvSfinrKzekzyk+z:thB8lR8aSeofX3kVq8crKznzyf - TLSH:
T19E36D0F7524FDD8DB3952F5393EA1429A08AD78C3631AF6454857A2CC4349BD7E00D90 - Submitted as: 677001.pdf
- File type: pdf · Size: 66466 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafficel.ru/wb?keyword=email%20writing%20format%20for%20class%2010, https://uploads.strikinglycdn.com/files/fb24604f-d819-4ae1-9d9d-08a74acf417a/59625774014.pdf, https://uploads.strikinglycdn.com/files/11c79c45-60d9-48ed-951e-0e7666a1e604/google_earth_moon_view.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/wb?keyword=email%20writing%20format%20for%20class%2010
- https://uploads.strikinglycdn.com/files/fb24604f-d819-4ae1-9d9d-08a74acf417a/59625774014.pdf
- https://s3.amazonaws.com/bawalidamovidud/wifi_adapter_free_for_windows_8._1.pdf
- https://uploads.strikinglycdn.com/files/11c79c45-60d9-48ed-951e-0e7666a1e604/google_earth_moon_view.pdf
- https://cdn-cms.f-static.net/uploads/4416318/normal_5fd92fb5adf8b.pdf
- https://uploads.strikinglycdn.com/files/82f10e41-3b92-41f9-a3cf-f1ce213c3ae5/74222881796.pdf
- https://uploads.strikinglycdn.com/files/157ab86c-884e-40df-90c0-e1abee223c41/official_letter_to_transfer_money_to_my_account.pdf
- https://uploads.strikinglycdn.com/files/1399408d-158c-4196-b1a3-09602559c8fb/nilivesexotufeb.pdf
- https://uploads.strikinglycdn.com/files/53dc44e0-4d60-4d3d-88c7-46486fe6558c/vadazadoditovimitojepa.pdf
- https://s3.amazonaws.com/jivala/spanish_comparatives_and_superlatives_worksheets.pdf
- https://s3.amazonaws.com/kujapomib/bifurariretagukid.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report