MALICIOUS — normal_5fc544e1947eb.pdf
MALICIOUS — normal_5fc544e1947eb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
3b50299c253af39ce052f3fe5e2ae367f9dd066b7f3abeb8045b6833d838e3f5 - SHA-1:
6ea702c35c86ebd8de185be5d0feda255c9fc6e4 - MD5:
1f8f9f9ffcb20b5dbd81b8e5ce628a55 - ssdeep:
1536:FNJow82nF/5vLrR3TKO2EWd+LviAzvtV7L0LEwOxTrWzYfVdd7xCPV8:dF/lLrpTKO2Fd+LviAzMUa4FCm - TLSH:
T1D537C0F3719BDD0CAB871B837AB52259604DC69D7032AF3844C83B6DE4A83BD6D14611 - Submitted as: normal_5fc544e1947eb.pdf
- File type: pdf · Size: 73076 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffine.ru/123?utm_term=popin+and+locking, https://cdn-cms.f-static.net/uploads/4445754/normal_5fc334bd77616.pdf, https://static1.squarespace.com/static/5fc11355ab79f442f22aa123/t/5fc2cad4645712565498ad73/1606601428372/minitab_anova_tutorial.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffine.ru/123?utm_term=popin+and+locking
- https://cdn-cms.f-static.net/uploads/4445754/normal_5fc334bd77616.pdf
- https://s3.amazonaws.com/kudefem/project_zero_gardner.pdf
- https://static1.squarespace.com/static/5fc11355ab79f442f22aa123/t/5fc2cad4645712565498ad73/1606601428372/minitab_anova_tutorial.pdf
- https://static1.squarespace.com/static/5fc3bf9f2e34347c70560205/t/5fc50e7718e72e5fdb77e947/1606749815108/23848316569.pdf
- https://cdn-cms.f-static.net/uploads/4380413/normal_5fbae0c9c67c1.pdf
- https://static1.squarespace.com/static/5fc0e2fd6b97992eb55c026f/t/5fc12a5a9b1ed03538059936/1606494810582/5661145389.pdf
- https://static1.squarespace.com/static/5fc069c17d0c8f249d3e4d8d/t/5fc0fe66173fb5383bc554b4/1606483559418/the_concentration_city.pdf
- https://cdn-cms.f-static.net/uploads/4385417/normal_5f9a8fef12425.pdf
- https://cdn-cms.f-static.net/uploads/4387713/normal_5fa21f7c85910.pdf
- https://static1.squarespace.com/static/5fc0eab716f6d44b07bedc8b/t/5fc353427acac6192a2aceda/1606636354650/dolare.pdf
- https://uploads.strikinglycdn.com/files/b988dd33-8ee5-46f0-8017-01597fc7bec2/pavotitasuvutiwexiwi.pdf
- https://static1.squarespace.com/static/5fc0de27085bf90c0efce9ba/t/5fc16b813c02f22b9d429c1d/1606511489875/pioneering_merit_badge_worksheet.pdf
- https://s3.amazonaws.com/jidosatikim/spring_resttemplate_content_type_json.pdf
- https://uploads.strikinglycdn.com/files/bdb0ecf2-16d4-44da-ba7e-cbc40a2c88c4/63551341097.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5001e18c5c478ef26854/1606373377981/reebop_genetics_answers.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffine.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- static1.squarespace.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report