MALICIOUS — normal_5feeb1a9f3c79.pdf
MALICIOUS — normal_5feeb1a9f3c79.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
1bc3c71200e606935b97c445f06973a6b0618b3cd2b367480ca96d9882c86fdb - SHA-1:
6b9f438ffea2fb59a5267862eb850b740337225f - MD5:
adabeac4b67e5773380cf883d875676e - ssdeep:
3072:FTzRMFxXoXX8lKS0yt4Z22VsCcYBw2LfQ6HnrKXcrI9M:FTWmWKSnzXYuQnKX/y - TLSH:
T1393EF1F7019BCC5DB19B5F13AAB63838749FC24A3522DB4108A42A2CD83D7BD6D16D60 - Submitted as: normal_5feeb1a9f3c79.pdf
- File type: pdf · Size: 138880 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafftec.ru/123?utm_term=new+hope+elementary+school, https://uploads.strikinglycdn.com/files/5c6b6861-8b52-4ea8-bd4c-ab3ed6f31671/42936472963.pdf, https://uploads.strikinglycdn.com/files/828e36b5-82b4-482a-af9c-9109dfcfae8b/44952396788.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/123?utm_term=new+hope+elementary+school
- https://uploads.strikinglycdn.com/files/5c6b6861-8b52-4ea8-bd4c-ab3ed6f31671/42936472963.pdf
- https://s3.amazonaws.com/kizugokofo/naxivifelerola.pdf
- https://s3.amazonaws.com/vavale/jisimopatekuzopoxupuxir.pdf
- https://s3.amazonaws.com/dazutun/83758414334.pdf
- https://uploads.strikinglycdn.com/files/828e36b5-82b4-482a-af9c-9109dfcfae8b/44952396788.pdf
- https://cdn.sqhk.co/walumupo/hihjdgg/creative_destruction_definition_psychology.pdf
- https://cdn.sqhk.co/sejixikerut/Qi6hclV/castle_clicker_chest.pdf
- https://uploads.strikinglycdn.com/files/738080d5-11c7-497f-8e43-91df723ebc0e/rajedotokalikunetewadume.pdf
- https://cdn.sqhk.co/wemonamo/ihajjja/kodomoziri.pdf
- https://s3.amazonaws.com/sodoxi/77094609612.pdf
- https://cdn-cms.f-static.net/uploads/4408352/normal_5f92a8152df5c.pdf
- https://uploads.strikinglycdn.com/files/9be4654a-ebfb-4f52-ada8-6f469f301fd5/personal_portfolio_template.pdf
- https://cdn-cms.f-static.net/uploads/4367621/normal_5f88ba0258e35.pdf
- https://uploads.strikinglycdn.com/files/261995b2-42bc-48dc-bc8d-776877ecd2db/essentials_of_human_anatomy_and_physiology_12th_edition_answers.pdf
- https://s3.amazonaws.com/tevigotu/21570613488.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.sqhk.co
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report