MALICIOUS — 6074988.pdf
MALICIOUS — 6074988.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
d421ddd99fbc0b5dd18378215b16d6b7c2f7d67cd1572490331a8f7c4603d18f - SHA-1:
0ab7649b1b2b8333abff1fbe893bea341b5cc9e7 - MD5:
c67ac705ab8cf80a37df2a8a42308061 - ssdeep:
1536:2Y+l8H1NX7wcbBAHrElFJD6AKzLwvA8ojSolw8iJus5a:ycBwxIl/+H0ojS98iJuT - TLSH:
T18938D1B761CFCD4CA596974369F215A4314BF6CCB225D7A104CC2A6CC9B83BE3E60A11 - Submitted as: 6074988.pdf
- File type: pdf · Size: 80301 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20abominable%20bride%20movie%20%20in%20tamil, https://uploads.strikinglycdn.com/files/b0a6bdcc-d472-4c6c-8096-c65129df955b/tozufagogi.pdf, https://uploads.strikinglycdn.com/files/53dfef3a-87b7-453d-bfe1-88a5ce274d80/72607683569.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20abominable%20bride%20movie%20%20in%20tamil
- https://uploads.strikinglycdn.com/files/b0a6bdcc-d472-4c6c-8096-c65129df955b/tozufagogi.pdf
- https://uploads.strikinglycdn.com/files/53dfef3a-87b7-453d-bfe1-88a5ce274d80/72607683569.pdf
- https://uploads.strikinglycdn.com/files/1be04e8c-895e-444f-aee0-123bb9c1fa61/zunakutijizujijaranavopu.pdf
- https://uploads.strikinglycdn.com/files/a879450e-b3a6-4767-a6df-b9a1a8c3f0d9/lumexode.pdf
- https://uploads.strikinglycdn.com/files/b09a04c1-add0-43ee-a162-3a77130b5fd2/32832730160.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8925184.pdf
- https://uploads.strikinglycdn.com/files/3258c587-9e86-4210-b3c4-8b5ba17985f7/stabilus_lift_o_mat_cross_reference.pdf
- https://s3.amazonaws.com/tedowafomaru/barbie_games_unblocked_game.pdf
- https://uploads.strikinglycdn.com/files/71747c99-fbdd-403b-9ad5-25b271acdbfc/fox_17_schedule.pdf
- https://uploads.strikinglycdn.com/files/8adae434-eabf-40a6-a636-7a2d7f860b61/zumalavuxunijusifame.pdf
- https://uploads.strikinglycdn.com/files/26bba316-21f6-44ef-9448-cbcd7ee3e37c/kroger_application.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- vuxozajuje.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report