MALICIOUS — normal_60b60feef3fd8.pdf
MALICIOUS — normal_60b60feef3fd8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3adb850c350e32e969cc3782ffd494506e8c447759a3eaf217ca1137bf074831 - SHA-1:
9fac1deffbe59bcf11d9512f9e2be7512b99f9a9 - MD5:
7d43ca93dd5ed0a46721500f374aea51 - ssdeep:
1536:jkdZIaA3B3h8BSQpHjiLDngtsIb7yaX0rZg/7iH5PqPKi8Ay/LmbyGf/b4:3agB3qBSQAz6sIvyaKZUm1qPKi8Ay/LR - TLSH:
T14639C0F32293DD8CBA8B9B47ADB7251D5148D3C8A422D76050C8B23DC8BC2BE3D10952 - Submitted as: normal_60b60feef3fd8.pdf
- File type: pdf · Size: 85336 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!7D43CA93DD5E
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/20c4d21e-b5bf-4ff1-a94e-2f8ee6ac392c/the_book_of_life_toro_song_lyrics.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://botokaw.ru/123?utm_term=activesync+email+app+android, https://uploads.strikinglycdn.com/files/20c4d21e-b5bf-4ff1-a94e-2f8ee6ac392c/the_book_of_life_toro_song_lyrics.pdf, https://uploads.strikinglycdn.com/files/54dfcfa3-283a-4fde-b936-031c68cf11a5/81869104851.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://botokaw.ru/123?utm_term=activesync+email+app+android
- https://uploads.strikinglycdn.com/files/20c4d21e-b5bf-4ff1-a94e-2f8ee6ac392c/the_book_of_life_toro_song_lyrics.pdf
- https://uploads.strikinglycdn.com/files/54dfcfa3-283a-4fde-b936-031c68cf11a5/81869104851.pdf
- http://jesababa.pbworks.com/f/52294456850.pdf
- http://kedetuwi.pbworks.com/f/gewuxebememebo.pdf
- http://sodopateduke.pbworks.com/w/file/fetch/144424761/descargar_libro_diario_contabilidad_excel.pdf
- http://zikupuzajix.pbworks.com/w/file/fetch/144434454/fe_mechanical_review_manual_lindeburg_free_download.pdf
- https://uploads.strikinglycdn.com/files/70a42119-bec9-43ed-8b05-0aee37737527/difference_between_powershell_and_command_prompt_in_tabular_form.pdf
- http://mapijakemifo.pbworks.com/w/file/fetch/144442167/sophocles_oedipus_the_king_sparknotes.pdf
- https://uploads.strikinglycdn.com/files/ef370498-fb03-4e17-94e7-f657ae2ea665/bk_sumitra_kannada_songs.pdf
- http://pamotekegopa.pbworks.com/f/42420776670.pdf
- http://godekazonigi.pbworks.com/f/geometry_two-column_proofs_worksheets_with_answers.pdf
- https://uploads.strikinglycdn.com/files/022b7b05-8525-4cd8-a531-0576fb5cc067/vadozavowilelibisuxoku.pdf
- http://pezeliv.pbworks.com/w/file/fetch/144424458/34289842141.pdf
- https://uploads.strikinglycdn.com/files/0090989a-66d6-42d4-8a1b-8808da07c334/jufavexoweretuvofeta.pdf
- https://uploads.strikinglycdn.com/files/03471d59-372a-4cb8-a905-bf324c6d4eac/procedimiento_para_la_recoleccion_de_datos_en_una_investigacion_cualitativa.pdf
- https://uploads.strikinglycdn.com/files/655e8502-5954-4984-b9c3-3946817b7563/historias_biblicas_para_nios_cristianos_evangelicos.pdf
- http://nagomax.pbworks.com/f/best_buy_san_antonio_forum.pdf
- https://uploads.strikinglycdn.com/files/fe1d5bd1-d8c9-4d1f-97f2-f8028b32b73e/napidetibo.pdf
- http://siruzosu.pbworks.com/f/85280879877.pdf
- http://bawamotijeku.pbworks.com/w/file/fetch/144446727/rakekabezo.pdf
- https://uploads.strikinglycdn.com/files/df8d3acf-c9d4-41fc-b7b1-decdf8cd33fc/interior_design_magazine_india_free_download.pdf
- https://uploads.strikinglycdn.com/files/abf5d63b-ce13-458d-b39e-d24f5b9ccf9c/atwood_rv_heater_parts.pdf
- https://uploads.strikinglycdn.com/files/c70dd7ee-9f09-4927-9747-01042958982e/45370219394.pdf
- https://uploads.strikinglycdn.com/files/c36d43dc-208a-4ab8-b52c-9a0879655399/what_are_the_catholic_symbols_of_christmas.pdf
Embedded domains
- gh.sh
- botokaw.ru
- uploads.strikinglycdn.com
- jesababa.pbworks.com
- kedetuwi.pbworks.com
- sodopateduke.pbworks.com
- zikupuzajix.pbworks.com
- mapijakemifo.pbworks.com
- pamotekegopa.pbworks.com
- godekazonigi.pbworks.com
- pezeliv.pbworks.com
- nagomax.pbworks.com
- siruzosu.pbworks.com
- bawamotijeku.pbworks.com
- tisowowuduwe.pbworks.com
- dekokos.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report