MALICIOUS — e0792e779fb76d83b3ce23677901457f02fd21932dc9dcab4739ba82d8e9b518
MALICIOUS — e0792e779fb76d83b3ce23677901457f02fd21932dc9dcab4739ba82d8e9b518 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 6 of 50 detection engines flagged it.
Identification
- SHA-256:
e0792e779fb76d83b3ce23677901457f02fd21932dc9dcab4739ba82d8e9b518 - SHA-1:
5862be4cd594ca7969eceeeaf1745aa0ed68bd57 - MD5:
2bb935e2681c0474965878c54f305bca - ssdeep:
1536:s06QSfOweo/AIf1LY+1uA4RaJMsadNZIqa4KXNrIIWYuYdLeZWN:8V5/5f1LY+VSsWvOrIzYuQLeO - TLSH:
T1FB37B0F350DBED8C754B7B433EAA16596589D7C8B1728B604044BA3CE8FC6ADAD00D11 - Submitted as: e0792e779fb76d83b3ce23677901457f02fd21932dc9dcab4739ba82d8e9b518
- File type: pdf · Size: 75239 bytes
- Verdict: malicious (92/100)
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!2BB935E2681C
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://ketchas.ru/pbw?utm_term=stacey+lloyd+2014+answer+key+using+ethos+pathos+logos, http://gajufabeke.pbworks.com/f/present_simple_and_present_continuous_exercises_worksheets.pdf, https://uploads.strikinglycdn.com/files/44432064-886a-456c-b570-3f1065293c87/i_itouch_curve_smartwatch_instructions.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ketchas.ru/pbw?utm_term=stacey+lloyd+2014+answer+key+using+ethos+pathos+logos
- http://gajufabeke.pbworks.com/f/present_simple_and_present_continuous_exercises_worksheets.pdf
- https://uploads.strikinglycdn.com/files/44432064-886a-456c-b570-3f1065293c87/i_itouch_curve_smartwatch_instructions.pdf
- https://tufizesux.weebly.com/uploads/1/3/4/5/134596030/kuzijilezugeku_sevotig_nofeki.pdf
- https://zomanuvid.weebly.com/uploads/1/3/4/4/134477829/911be23856cf.pdf
- https://uploads.strikinglycdn.com/files/ef729cbd-7e82-4b7b-9d46-bf1bbd69b1a7/porter_cable_c2002_pressure_relief_valve.pdf
- https://rewoseluvepe.weebly.com/uploads/1/3/4/6/134683186/1afe0d27a7e659.pdf
- http://xuruzinijub.pbworks.com/f/gevefawugijedivusasub.pdf
- https://cdn-cms.f-static.net/uploads/4406166/normal_603383c2dbba8.pdf
- https://uploads.strikinglycdn.com/files/ad08712b-e8fe-47a0-af12-b58fafedb0b5/eventide_h9_harmonizer_plugin.pdf
- https://mafinejolid.weebly.com/uploads/1/3/2/6/132683008/2295669.pdf
- https://uploads.strikinglycdn.com/files/04065677-0752-4170-9b8c-5d9eb31bfaa7/how_to_think_like_leonardo_da_vinci_by_michael_gelb.pdf
- https://static.s123-cdn-static.com/uploads/4409417/normal_5feb6d276fb36.pdf
- https://fuxopejebema.weebly.com/uploads/1/3/4/0/134018858/wisubit.pdf
- https://jibametugo.weebly.com/uploads/1/3/4/4/134486067/runujizajenutog-ketub.pdf
- https://uploads.strikinglycdn.com/files/b00adf16-7604-4fe9-8e61-a27d4cbbe254/tezarufesanup.pdf
- https://ratewanevunexem.weebly.com/uploads/1/3/2/6/132681210/4534590.pdf
- https://cdn-cms.f-static.net/uploads/4390057/normal_60177698861d9.pdf
- http://mudowomuxexo.pbworks.com/w/file/fetch/144422955/benvolio_and_mercutio_relationship.pdf
- https://daguvosiliwu.weebly.com/uploads/1/3/1/4/131406153/zimeporejomedaxalavi.pdf
- https://uploads.strikinglycdn.com/files/586637d3-b923-4286-9fd8-4b9b11fe6f1e/calendario_tintin_2020_fnac.pdf
- https://fudisilutopunus.weebly.com/uploads/1/3/1/4/131438012/4274886.pdf
- https://uploads.strikinglycdn.com/files/862cba3b-4dee-4ac9-bc70-89a17c1b30c5/cabelas_gun_dog_gs-8000_training_collar.pdf
- https://cdn-cms.f-static.net/uploads/4471234/normal_602d8e169509b.pdf
- https://cdn-cms.f-static.net/uploads/4387419/normal_60b9cd1ea1e62.pdf
Embedded domains
- ketchas.ru
- gajufabeke.pbworks.com
- uploads.strikinglycdn.com
- tufizesux.weebly.com
- zomanuvid.weebly.com
- rewoseluvepe.weebly.com
- xuruzinijub.pbworks.com
- cdn-cms.f-static.net
- mafinejolid.weebly.com
- static.s123-cdn-static.com
- fuxopejebema.weebly.com
- jibametugo.weebly.com
- ratewanevunexem.weebly.com
- mudowomuxexo.pbworks.com
- daguvosiliwu.weebly.com
- fudisilutopunus.weebly.com
- resewirebibabap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report