MALICIOUS — normal_5fd915a83bb0e.pdf
MALICIOUS — normal_5fd915a83bb0e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4504fa91c3545e2eb9b75d40f4a26edb81d6949bd17a05a3ef27808828331cb0 - SHA-1:
98bd2b707180793fb9d5f034e791e520ce9100ff - MD5:
3553097201aafed891770105948dcf76 - ssdeep:
1536:DAHzv/V7Bjo5QSSdFHsiBfD9FiaBuhvu30izh2DT8JGY:izv/V9K6jBicuNu300hQT8L - TLSH:
T16F37C0F7918BEDCC7A839B53BEB712AD554AC2886122D2E0414CB57CD0BC17DBE04A49 - Submitted as: normal_5fd915a83bb0e.pdf
- File type: pdf · Size: 71507 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/ee3151f7-e190-40d8-8d93-fcaaf1e3c505/what_is_a_lewis_acid-lewis_base_adduct.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafftec.ru/123?utm_term=how+are+all+living+things+connected, https://cdn-cms.f-static.net/uploads/4366029/normal_5fa5679473c83.pdf, https://uploads.strikinglycdn.com/files/187d8a15-c0f6-4470-8a14-1f073c58024e/tae_kims_guide_to_japanese_apk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: additional-actions, uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/123?utm_term=how+are+all+living+things+connected
- https://cdn-cms.f-static.net/uploads/4366029/normal_5fa5679473c83.pdf
- https://uploads.strikinglycdn.com/files/187d8a15-c0f6-4470-8a14-1f073c58024e/tae_kims_guide_to_japanese_apk.pdf
- https://static1.squarespace.com/static/5fc55a1324b06a7eb31d25e2/t/5fc9fb5efedaa13a48671295/1607072606678/alone_status_in_english_text.pdf
- https://uploads.strikinglycdn.com/files/89c7ab1f-23ac-4d4e-a48f-c2af2f548ce3/sixexovutefofirunupol.pdf
- https://cdn-cms.f-static.net/uploads/4385848/normal_5f91dd78c9542.pdf
- https://uploads.strikinglycdn.com/files/0aaea77c-35f8-449b-8271-e47cf9edc0b5/the_real_mccoys_tv_show_cast.pdf
- https://cdn-cms.f-static.net/uploads/4415740/normal_5fb9c939f1f52.pdf
- https://static1.squarespace.com/static/5fc0f5b088c99b6d37a76c18/t/5fc24b53bc819f1cf423b0e2/1606568788218/cake_mania_3.pdf
- https://nopubogap.weebly.com/uploads/1/3/4/6/134667077/xipepobuwepudirag.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5561eaf37e3b6492b631/1606374753592/dotuzedugubed.pdf
- https://static1.squarespace.com/static/5fc7855e1a9b7f6479380a92/t/5fcae370bce7087d1ad22195/1607132024479/forabojuz.pdf
- https://uploads.strikinglycdn.com/files/ee3151f7-e190-40d8-8d93-fcaaf1e3c505/what_is_a_lewis_acid-lewis_base_adduct.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/pofexotokonadu.pdf
- https://cdn-cms.f-static.net/uploads/4453907/normal_5faa7d032a459.pdf
- https://static1.squarespace.com/static/5fc5a77d116eb00e3c6c6a61/t/5fca64be669a3166a709d173/1607099584546/voice_assistant_for_android_4._4._2.pdf
- https://uploads.strikinglycdn.com/files/5452a407-e9fe-48c6-99f7-e0fa4538f280/escape_the_phone_booth_hooda_math.pdf
- https://cdn-cms.f-static.net/uploads/4372702/normal_5fd28f9926caf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- static1.squarespace.com
- nopubogap.weebly.com
- sibakixode.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report