MALICIOUS — normal_6007207086837.pdf
MALICIOUS — normal_6007207086837.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
5230bb40580475fd0fa5ee492076ae91ae688468ad31751c6c0125ee4ec5a6e8 - SHA-1:
1b0d7dc1f0985afa4df449ab360b6ede3bc004d2 - MD5:
a4abdbb5801721d5e4406dfa1b6014f4 - ssdeep:
1536:XWiaXoXlqKWQbIYC/ZAxl3AiwHT3S+7ulgWCMSEhBrLDk2Q7CN:mia4XYK3bIYW+PUHTZWCtErHDAQ - TLSH:
T1FB38E0F3E097DD1C26A99F936D7B1129A089E7DC20625BB15084AB6CC87C77E2D60E01 - Submitted as: normal_6007207086837.pdf
- File type: pdf · Size: 80080 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!A4ABDBB58017
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafffi.ru/123?utm_term=north+andover+high+school+graduation+2020, http://gadoxijumulop.epizy.com/monthly_income_expenditure_spreadsheet.pdf, http://surobufalinaxis.epizy.com/soul_music_album_free.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffi.ru/123?utm_term=north+andover+high+school+graduation+2020
- http://gadoxijumulop.epizy.com/monthly_income_expenditure_spreadsheet.pdf
- http://surobufalinaxis.epizy.com/soul_music_album_free.pdf
- http://norisufa.epizy.com/galuzadufapudawedutufisop.pdf
- http://nutejujaxi.66ghz.com/archery_apk_indir_android_oyun_club.pdf
- http://tujevudaxuxos.epizy.com/4_week_exercise_plan_template.pdf
- https://cdn.sqhk.co/pemanunid/mtgcZhj/kubiwemelovozobiwo.pdf
- https://cdn.sqhk.co/baxijaxazixi/7xJgjhe/dino_hunter_deadly_shores_apk_mod.pdf
- http://novosumagib.epizy.com/nikosuwexofukuxeruv.pdf
- http://memubalejegezur.66ghz.com/annexure_f_for_tatkal_passport.pdf
- http://mekamaxabojumoz.epizy.com/brazilian_blowout_zero_formaldehyde-_free.pdf
- http://nemunuj.rf.gd/22840836230.pdf
- https://kagilovudugavap.weebly.com/uploads/1/3/1/1/131164538/cb552f8c30cf9.pdf
- http://vefapiba.epizy.com/banjo_trance_song_dj.pdf
- https://gonotelavekufuf.weebly.com/uploads/1/3/4/6/134615299/ratak.pdf
- http://tuzotulerijenej.rf.gd/fofivijopesobigumipasit.pdf
- http://xonefepuvimami.epizy.com/36265182385.pdf
- http://zaxutakizet.epizy.com/rafikoritobasifijapide.pdf
- https://zofigaxukinepir.weebly.com/uploads/1/3/4/2/134235574/mobebati-vebokiz-laxowijaj-kijeri.pdf
- http://sizuxubotinukor.22web.org/alberta_works_cheque_reporting_line.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- trafffi.ru
- gadoxijumulop.epizy.com
- surobufalinaxis.epizy.com
- norisufa.epizy.com
- nutejujaxi.66ghz.com
- tujevudaxuxos.epizy.com
- cdn.sqhk.co
- novosumagib.epizy.com
- memubalejegezur.66ghz.com
- mekamaxabojumoz.epizy.com
- kagilovudugavap.weebly.com
- vefapiba.epizy.com
- gonotelavekufuf.weebly.com
- xonefepuvimami.epizy.com
- zaxutakizet.epizy.com
- zofigaxukinepir.weebly.com
- sizuxubotinukor.22web.org
- www.w3.org
- purl.org
- ns.adobe.com
- nemunuj.rf.gd
- tuzotulerijenej.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report