MALICIOUS — normal_5fc4a79d29132.pdf
MALICIOUS — normal_5fc4a79d29132.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0c611303e124b8eea1faa236f5a0fc4c59dc6217a54c5855e608f79eb3770cfa - SHA-1:
ceb0610e3921df8a895b6c56e9fa55422ec281bb - MD5:
50f84c99b2efa0e0c315f92d5190bc28 - ssdeep:
1536:R5i++fZy19raKMP/P6pVw7fEda2CBIhcgffghgTx65rOIsB/y6BLQ/:a1hGaKw6nw7fByxgg+sBaY8 - TLSH:
T18136D0F37457DD4C7E9A0F43BEBA00AC2549E68C2272A7B01488672DC8B417C6F54EA1 - Submitted as: normal_5fc4a79d29132.pdf
- File type: pdf · Size: 69622 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fc10afc403f5353fd968892/t/5fc1d6ffcb3e0f5771936ce9/1606539008114/tinopugadukanaresolo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffmen.ru/123?utm_term=sanyo+microwave+manual+guide, https://cdn-cms.f-static.net/uploads/4380382/normal_5f9484946eb6a.pdf, https://cdn-cms.f-static.net/uploads/4488330/normal_5fbdd0a012c8e.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffmen.ru/123?utm_term=sanyo+microwave+manual+guide
- https://cdn-cms.f-static.net/uploads/4380382/normal_5f9484946eb6a.pdf
- https://cdn-cms.f-static.net/uploads/4488330/normal_5fbdd0a012c8e.pdf
- https://uploads.strikinglycdn.com/files/fb6d3580-88ad-49f6-8101-a33756f93a51/wakajezabadutijutopuz.pdf
- https://static1.squarespace.com/static/5fc10afc403f5353fd968892/t/5fc1d6ffcb3e0f5771936ce9/1606539008114/tinopugadukanaresolo.pdf
- https://sazagirisama.weebly.com/uploads/1/3/4/5/134585928/jekufodakeponorafab.pdf
- https://cdn-cms.f-static.net/uploads/4403531/normal_5fb9ce203a9af.pdf
- https://cdn-cms.f-static.net/uploads/4449178/normal_5fb8d5f75391e.pdf
- https://static1.squarespace.com/static/5fc29dd524b06a7eb30a4ada/t/5fc3d0c52dd96f591862c211/1606668485859/the_secret_garden_summary.pdf
- https://uploads.strikinglycdn.com/files/2d7de4d7-8212-47f0-a019-0c5f92646ffb/hp_laserjet_m1217_driver.pdf
- https://mibaxezaju.weebly.com/uploads/1/3/4/6/134641270/kisirisefe-jekowi-kukaxogavaf.pdf
- https://uploads.strikinglycdn.com/files/48d45585-2466-4ff9-a4f1-85e0acac12c7/naduwupeje.pdf
- https://cdn-cms.f-static.net/uploads/4418587/normal_5f9c7c63e8c14.pdf
- https://static1.squarespace.com/static/5fc3426faffbf90a66f9ae2f/t/5fc413c73485235c8645e9eb/1606685639860/dakuzejenasunokasuvefik.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffmen.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- static1.squarespace.com
- sazagirisama.weebly.com
- mibaxezaju.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report