MALICIOUS — normal_5faa73f0102f2.pdf
MALICIOUS — normal_5faa73f0102f2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
4545bd30ea74cdaabc157c1076b257628afead17409697a00858c1aac9e14b35 - SHA-1:
a779363911ede0fb1ceb8fc3adfa1f389066b4e7 - MD5:
425316ef6568516e0b7c0f2e02998bbd - ssdeep:
1536:e6V2BB1Cdor4BdKAWhhS0l0gw7RqXRztG2AdTj6l9g6XU:nGUdoMBGhS0BUqfG2Ady0B - TLSH:
T13F37D0F352A3DE4D7AD78F073BE6099860C6D74C6633C9A08184B72DC97426EAF11981 - Submitted as: normal_5faa73f0102f2.pdf
- File type: pdf · Size: 74258 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffking.ru/123?keyword=dress+you+up+in+my+love+song, https://uploads.strikinglycdn.com/files/5f052af0-d33d-419a-b55e-3a8eee94e83e/50_shades_darker_full_movie_download.pdf, https://cdn-cms.f-static.net/uploads/4371509/normal_5fa161f3653c4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/123?keyword=dress+you+up+in+my+love+song
- https://uploads.strikinglycdn.com/files/5f052af0-d33d-419a-b55e-3a8eee94e83e/50_shades_darker_full_movie_download.pdf
- https://cdn-cms.f-static.net/uploads/4371509/normal_5fa161f3653c4.pdf
- https://s3.amazonaws.com/xakajoziwibi/sudan_iv_test_for_lipids.pdf
- https://uploads.strikinglycdn.com/files/7349511b-d818-4e86-96f2-07d23bf15e3b/statistics_for_veterinary_and_animal_science_online.pdf
- https://s3.amazonaws.com/xunilukegez/resume_examples_for_virtual_assistant.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f8b1732782dd.pdf
- https://cdn-cms.f-static.net/uploads/4368982/normal_5fa84dfa9bef2.pdf
- https://cdn-cms.f-static.net/uploads/4402711/normal_5f90cc554506c.pdf
- https://s3.amazonaws.com/polojuliragam/51582457667.pdf
- https://s3.amazonaws.com/datarofapakil/58394014900.pdf
- https://s3.amazonaws.com/memul/94408758953.pdf
- https://s3.amazonaws.com/xanebavifamopez/15486035404.pdf
- https://cdn-cms.f-static.net/uploads/4466386/normal_5fa28bfd3dcb7.pdf
- https://cdn-cms.f-static.net/uploads/4374835/normal_5fa6aecb433c6.pdf
- https://cdn-cms.f-static.net/uploads/4403127/normal_5fa3cc2b0c049.pdf
- https://cdn-cms.f-static.net/uploads/4377678/normal_5f93c0ae4d5d9.pdf
- https://cdn-cms.f-static.net/uploads/4366316/normal_5fa3233b796d1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report