MALICIOUS — aa36089ecc23f6.pdf
MALICIOUS — aa36089ecc23f6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
e28a9bb6a64b7ff5831a0042f53a9073933838e17cb8974c508d4dd23a845a2a - SHA-1:
d68e5d7d40ee3e243ba5527f10d58d713b43e308 - MD5:
f279184bc53c007ed66cc2f5d94dde03 - ssdeep:
1536:vv973OBylCmihWGzan0cD76n9SesJm14BksBnBTeqpgM:t73OByl3ihWGdcD760esrJeq9 - TLSH:
T15B36E0FBA20BDDA8A59697835CF7106D7456838D6233A27024C9763CC9B83AD6F14E00 - Submitted as: aa36089ecc23f6.pdf
- File type: pdf · Size: 68922 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffnew.ru/wb?keyword=bodyguard%20movie%20full%20hd%20video%20songs, https://uploads.strikinglycdn.com/files/f5b17e3d-fa99-43aa-aed5-af6f93539667/21804357247.pdf, https://uploads.strikinglycdn.com/files/c84f8807-069b-4494-bc7b-68ce25b95ee4/linksys_wireless-g_wusb54g_driver_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffnew.ru/wb?keyword=bodyguard%20movie%20full%20hd%20video%20songs
- https://uploads.strikinglycdn.com/files/f5b17e3d-fa99-43aa-aed5-af6f93539667/21804357247.pdf
- https://uploads.strikinglycdn.com/files/c84f8807-069b-4494-bc7b-68ce25b95ee4/linksys_wireless-g_wusb54g_driver_download.pdf
- https://uploads.strikinglycdn.com/files/9fc54ac8-ba31-4821-9582-3783cf03d1f7/mavezitexazix.pdf
- https://s3.amazonaws.com/dikobepibelun/digital_signature_slide_template.pdf
- https://uploads.strikinglycdn.com/files/dbbfe870-7d1f-489e-bd85-fb4887ced22f/11517897066.pdf
- https://s3.amazonaws.com/petuzutemixuvod/18490720630.pdf
- https://uploads.strikinglycdn.com/files/30122680-7c23-4e2a-a285-a2889e6acd60/dr._guadalupe_mercedes_rodriguez_palacios.pdf
- https://uploads.strikinglycdn.com/files/b23eba97-ecc7-4c4a-a5b8-920c41778934/como_separar_palabras_en_excel.pdf
- https://uploads.strikinglycdn.com/files/7462f3ea-a7d7-458b-8b24-5c6853d656ec/brunnstrom_stages_of_motor_recovery.pdf
- https://uploads.strikinglycdn.com/files/f9dcaa4e-d773-4569-9e54-62fd7ac95294/32107485325.pdf
- https://s3.amazonaws.com/fadadedezeker/9897653001.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffnew.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- J:\/y8
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report