MALICIOUS — gopizapowiju.pdf
MALICIOUS — gopizapowiju.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
c231b76513e0a38d7c99c2246858abc12ca51bfcf7d5c6bad8d4cde8e0e03509 - SHA-1:
168dfb2d598cf71e55d84816273e789b2b056a8e - MD5:
4c2acb0a55ac048895a29d13c45b134b - ssdeep:
1536:USkrWoeZr+gpS77qnPeXtRFHSf/HqjEZHOOtLgih44goPa:RkrY+1nqnPWFY/HqG5U4q - TLSH:
T1F336C0F3526BDE8C3E8E6B47A8FA0558A14FE34560239B904448769D84746FD3F30DA1 - Submitted as: gopizapowiju.pdf
- File type: pdf · Size: 69432 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!4C2ACB0A55AC
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffmen.ru/wb?keyword=dragonvale%20sandbox%20quests, https://uploads.strikinglycdn.com/files/156bee5f-cd21-4c4c-bbfa-50acd6f7e78c/mavizomozixewurijesifaki.pdf, https://uploads.strikinglycdn.com/files/00a20494-1977-4196-aeea-ccd22a515068/vawurutisapapip.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffmen.ru/wb?keyword=dragonvale%20sandbox%20quests
- https://s3.amazonaws.com/vipinib/40032801335.pdf
- https://uploads.strikinglycdn.com/files/156bee5f-cd21-4c4c-bbfa-50acd6f7e78c/mavizomozixewurijesifaki.pdf
- https://s3.amazonaws.com/bisiku/executive_summary_cv_template.pdf
- https://uploads.strikinglycdn.com/files/00a20494-1977-4196-aeea-ccd22a515068/vawurutisapapip.pdf
- https://s3.amazonaws.com/vonuxagupeduze/vutilakanapokaxunodar.pdf
- https://uploads.strikinglycdn.com/files/32ba6456-4ce0-44bc-bc55-2f5403c3c2c2/diccionario_de_la_lengua_espaola_en.pdf
- https://s3.amazonaws.com/janodojivi/western_blot_test_procedure.pdf
- https://uploads.strikinglycdn.com/files/cb838ed4-2277-41de-a4d8-6382ab481839/logobapudanakiteri.pdf
- https://uploads.strikinglycdn.com/files/6e5bf902-cc17-40b4-a65f-ef03e9c77361/zujarokizos.pdf
- https://uploads.strikinglycdn.com/files/06d1870a-18f7-4e3d-9e58-af7a4a9433b1/union_hill_school_phone_number.pdf
- https://uploads.strikinglycdn.com/files/b5eb5253-ad34-4028-b776-72a2a20dd369/48075638649.pdf
- https://uploads.strikinglycdn.com/files/ea8bc65c-6ea4-43c5-9218-05563ee141f2/best_pixel_art_software_for_games.pdf
- https://uploads.strikinglycdn.com/files/419e03f4-3511-4544-8324-ba5e646318fe/siperafak.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffmen.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- 8.it
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report