MALICIOUS — xubowotapoj.pdf
MALICIOUS — xubowotapoj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
e35be0bf1bca4dbd7d866c6efa819c77775842f4c77444120e6f69b21d75a0ba - SHA-1:
28a41413b9d581bb2d1c0cb0f329412c349af6fa - MD5:
0b60737962cf539f672051fca38a7fad - ssdeep:
1536:J2P5mo0ut5s49GLJZ08ri1dVlfaJYmoepHj7Vxq61s5:RjHlZzrilNIF5pD7q6o - TLSH:
T10635C0F362CBDC4C7A81E757A9E60964648DC6C96632D7F08488B72CD87CABD2E11940 - Submitted as: xubowotapoj.pdf
- File type: pdf · Size: 62158 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://cctraff.ru/strik?keyword=apple+smart+battery+case+iphone+6s, https://uploads.strikinglycdn.com/files/e872d8fc-a1f4-4185-8336-ab45315d2dce/yamaha_rx_v681bl.pdf, https://uploads.strikinglycdn.com/files/d3cb5741-9cda-43e5-8e40-05d8c1b6f79c/96082834962.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=apple+smart+battery+case+iphone+6s
- https://uploads.strikinglycdn.com/files/e872d8fc-a1f4-4185-8336-ab45315d2dce/yamaha_rx_v681bl.pdf
- https://uploads.strikinglycdn.com/files/d3cb5741-9cda-43e5-8e40-05d8c1b6f79c/96082834962.pdf
- https://s3.amazonaws.com/rerinago/kixugokabexamulinuro.pdf
- https://cdn-cms.f-static.net/uploads/4413567/normal_5f942ad1cb9b4.pdf
- https://uploads.strikinglycdn.com/files/710621ef-5159-4e8d-a537-f4d7ca4471fa/51963630891.pdf
- https://cdn-cms.f-static.net/uploads/4368228/normal_5f9a1506c9abe.pdf
- https://uploads.strikinglycdn.com/files/caee1f2e-458f-4cf3-b707-6694236f1266/32636931171.pdf
- https://uploads.strikinglycdn.com/files/23ebc6f7-e459-4b6e-9a96-ad609d1ea855/camex_2020_show_hours.pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f90904b49e70.pdf
- https://uploads.strikinglycdn.com/files/70b86a22-56db-4fe9-9421-b39927460e05/supreme_commander_2_revamp_mod.pdf
- https://s3.amazonaws.com/sugosubexez/deborah_gail_stone_cause_of_death.pdf
- https://uploads.strikinglycdn.com/files/2dd1ac40-b08d-4cc1-aa3d-9cfc8d0fa9aa/zaximibudovi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report