MALICIOUS — 6769158.pdf
MALICIOUS — 6769158.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
deb5504211a64648b362e86e60eafe4609b419e86c1262e3a43f0ed130075f43 - SHA-1:
f85fa6b312f89dfa5116980b88a9dea3ad0ce36a - MD5:
dd2a1800f94273fdf42a1c0c431a48e4 - ssdeep:
1536:bgARbshVxKqQA48eYcKESbEbvCeChNwzmUKV4P0yojuFj5b2Z68sGV:kA8KqQA4DTCxcC1V4PxUuJ1ex - TLSH:
T19337E1F37597CE8D36C757036AA701BD605ED34805269BB42488B77DD4B89EE3E20620 - Submitted as: 6769158.pdf
- File type: pdf · Size: 72623 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafftec.ru/wb?keyword=bjt%20pnp%20datasheet, https://uploads.strikinglycdn.com/files/16c73d25-b431-4108-b53e-3bdae56ccc67/123_movies_free_spider_man_far_from_home.pdf, https://cdn-cms.f-static.net/uploads/4409403/normal_5fb25ba8bdf3d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/wb?keyword=bjt%20pnp%20datasheet
- https://uploads.strikinglycdn.com/files/16c73d25-b431-4108-b53e-3bdae56ccc67/123_movies_free_spider_man_far_from_home.pdf
- https://cdn-cms.f-static.net/uploads/4409403/normal_5fb25ba8bdf3d.pdf
- https://uploads.strikinglycdn.com/files/458654fc-a482-4eca-958a-59bb67127795/21613180534.pdf
- https://uploads.strikinglycdn.com/files/ef8e67ab-adc0-4987-87c1-dfa1de833650/salman_khan_bodybuilder.pdf
- https://cdn-cms.f-static.net/uploads/4447271/normal_5fa19a8f90969.pdf
- https://cdn-cms.f-static.net/uploads/4374374/normal_5f9078e96a926.pdf
- https://uploads.strikinglycdn.com/files/0a1fae97-eaa1-4de0-8be1-ec10e05b73be/no_gba_emulator_download.pdf
- https://cdn-cms.f-static.net/uploads/4384035/normal_5fb330785bf92.pdf
- https://s3.amazonaws.com/xamapebonijos/free_lingala_and_congolese_gospel_music_s.pdf
- https://uploads.strikinglycdn.com/files/a2febf2e-28db-4843-b323-ac9cc7a373eb/xadawixisupuvase.pdf
- https://cdn-cms.f-static.net/uploads/4366336/normal_5f8b31ffdadb5.pdf
- https://cdn-cms.f-static.net/uploads/4497078/normal_5fabfba9b19d0.pdf
- https://cdn-cms.f-static.net/uploads/4372696/normal_5f8944fd2e25d.pdf
- https://uploads.strikinglycdn.com/files/6da94b5c-ab04-45ca-ba02-c41a4d9e4a15/gifidonunokit.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report