MALICIOUS — normal_5fcc07ea23acc.pdf
MALICIOUS — normal_5fcc07ea23acc.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
316618c4dbae15824ca76854b2b798fb8e0df63f0d61621b407796ddf37db9b9 - SHA-1:
0587c0a4eb21cba5a840e95d6fd20da542d4ede9 - MD5:
dfa048dadb4c5bc9187db9503c84ebf1 - ssdeep:
1536:SpNGNaTG5GD/uV95cmDdcypdDkqbMeh30ZF98fp3Essar/95pqqvRVfFt:wNGCOGADdDdcyptkqlqGNVz - TLSH:
T18138E1E3A10BCFCD6E8A5B03FDEB4169619BD29C6172C65004887B7DC8684FFAE11950 - Submitted as: normal_5fcc07ea23acc.pdf
- File type: pdf · Size: 81897 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/xuwevitogu-puloka.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?utm_term=gillette+seating+chart+with+rows, https://uploads.strikinglycdn.com/files/422946db-2fbd-42a4-8275-deaa7fbe14b3/71726058059.pdf, https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/9448bf1e6186b5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?utm_term=gillette+seating+chart+with+rows
- https://uploads.strikinglycdn.com/files/422946db-2fbd-42a4-8275-deaa7fbe14b3/71726058059.pdf
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/9448bf1e6186b5.pdf
- https://pixamowogiru.weebly.com/uploads/1/3/4/5/134590731/52b02.pdf
- https://nigafabap.weebly.com/uploads/1/3/4/3/134377596/8751783.pdf
- https://uploads.strikinglycdn.com/files/f06fd5f1-93c2-4ea3-a366-11f9c225832c/dewalt_4200_psi_pressure_washer_parts_manual.pdf
- https://cdn-cms.f-static.net/uploads/4404980/normal_5fae2449188e0.pdf
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/xuwevitogu-puloka.pdf
- https://xerirexu.weebly.com/uploads/1/3/4/5/134592073/pepadefubutizi-kifiwotimipos.pdf
- https://s3.amazonaws.com/jujadodedaruxix/rukopatomilu.pdf
- https://s3.amazonaws.com/tinezedu/rixuneburepor.pdf
- https://s3.amazonaws.com/loranoduzuja/42727630032.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- bizumoku.weebly.com
- pixamowogiru.weebly.com
- nigafabap.weebly.com
- cdn-cms.f-static.net
- digonowokeke.weebly.com
- xerirexu.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report