MALICIOUS — normal_5fc7cce4d6d24.pdf
MALICIOUS — normal_5fc7cce4d6d24.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
2a33cd1b30d73db9982cc5cacc6968f156fbc28eaa10862bf50791c890e396be - SHA-1:
f9e86f34d1ffcb13353f5bf30e2fa23462987eb7 - MD5:
e5e98d24131feec647a3e08290821f6c - ssdeep:
1536:MDaZ2NWRhhuxyk/fxDawvZVBeRv7OuOCaEMKYdnJzRMGu68fPq8l6:CFwRhhoyetXfBOOuzYtHMGu683V6 - TLSH:
T1AB37D0F3A24FCD4CA6DB9793ADD601687148E58C603A9BA06045FB6CC4B82FD7F10652 - Submitted as: normal_5fc7cce4d6d24.pdf
- File type: pdf · Size: 71835 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafficel.ru/123?utm_term=bike+race+mod+apk+all+bikes, https://cdn-cms.f-static.net/uploads/4450638/normal_5fb9510a0fdf3.pdf, https://cdn-cms.f-static.net/uploads/4366661/normal_5f872059ac5c3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/123?utm_term=bike+race+mod+apk+all+bikes
- https://cdn-cms.f-static.net/uploads/4450638/normal_5fb9510a0fdf3.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f872059ac5c3.pdf
- https://cdn-cms.f-static.net/uploads/4387046/normal_5f8e4851d1ce8.pdf
- https://uploads.strikinglycdn.com/files/3a7a03f5-444c-481e-b1a9-0a5c577e2503/98963592817.pdf
- https://s3.amazonaws.com/zetubakuz/nupirepagetov.pdf
- https://s3.amazonaws.com/wilugugo/wufazujibuxasukazokone.pdf
- https://uploads.strikinglycdn.com/files/56a5e2a8-a5e2-4f56-a529-df2647554496/kigegofukixamituvabi.pdf
- https://babinekisifuve.weebly.com/uploads/1/3/2/6/132696104/16ad1cfe0d5.pdf
- https://cdn-cms.f-static.net/uploads/4454556/normal_5fbd54825c164.pdf
- https://uploads.strikinglycdn.com/files/d4d7bf95-2fd3-49cd-801b-1e2132a4631f/mola_hidatiforme_power_point.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- babinekisifuve.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report