MALICIOUS — fefifafekap.pdf
MALICIOUS — fefifafekap.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
da6ee9656ffb766eba145deb98477ad7cad26a75356aa12813d4320fb5d437c9 - SHA-1:
50b9323eb9e309bf9b384fe9f721f7cbd3ea3612 - MD5:
7efd417913900c22c3e3c9dc495ed159 - ssdeep:
1536:KQpH2P/RDcMZNIcT0cpljCBcydFg9Q27di6VG2tmY0MpMUoitxqb:vpHsoyNIcdlOeGFg9QOppZ0soitg - TLSH:
T15237C0F370A3DD4C7A839B936EEB224C308EC58437769A9105C4753C80786BE6F10966 - Submitted as: fefifafekap.pdf
- File type: pdf · Size: 71617 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffnew.ru/strik?utm_term=rio+grande+do+norte+petrobras, https://uploads.strikinglycdn.com/files/59f9c07f-b805-466b-bca0-a817972db413/96256452438.pdf, https://uploads.strikinglycdn.com/files/1f462640-1efc-42e8-af49-c6fc5e550178/persona_4_golden_cant_start_kanjis_social_link.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffnew.ru/strik?utm_term=rio+grande+do+norte+petrobras
- https://uploads.strikinglycdn.com/files/59f9c07f-b805-466b-bca0-a817972db413/96256452438.pdf
- https://s3.amazonaws.com/juvosi/moviwexokufagevivuzure.pdf
- https://uploads.strikinglycdn.com/files/1f462640-1efc-42e8-af49-c6fc5e550178/persona_4_golden_cant_start_kanjis_social_link.pdf
- https://kazigujexumakul.weebly.com/uploads/1/3/4/3/134320364/8212359.pdf
- https://gifidutuv.weebly.com/uploads/1/3/4/6/134666467/poxuxunidudisi.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/7729626.pdf
- https://notutevetalopi.weebly.com/uploads/1/3/4/7/134715305/c07199a.pdf
- https://buluzuzumaz.weebly.com/uploads/1/3/1/6/131636727/sijuzajavufote.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/5413437.pdf
- https://virukuzababije.weebly.com/uploads/1/3/4/3/134350100/9411592.pdf
- https://wanovupejofo.weebly.com/uploads/1/3/4/5/134580977/gofinopodazuwibutoso.pdf
- https://uploads.strikinglycdn.com/files/612c1b96-2413-4840-8577-68ddcfb682b7/pillow_talk_mp3_direct_download.pdf
- https://gogesatita.weebly.com/uploads/1/3/4/3/134321397/8c7d2936d7acd6.pdf
- https://bemazinava.weebly.com/uploads/1/3/4/8/134890863/1934469.pdf
- https://uploads.strikinglycdn.com/files/ac07ad52-4ff0-45eb-a7ed-73089b218510/21826393188.pdf
- https://uploads.strikinglycdn.com/files/5294c4bb-93e7-43db-80f8-41e744a0f7f6/world_conqueror_3_unlimited_medals_pc.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffnew.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- kazigujexumakul.weebly.com
- gifidutuv.weebly.com
- mupibidegupek.weebly.com
- notutevetalopi.weebly.com
- buluzuzumaz.weebly.com
- viweposedijul.weebly.com
- virukuzababije.weebly.com
- wanovupejofo.weebly.com
- gogesatita.weebly.com
- bemazinava.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report