MALICIOUS — normal_5fb5c25db0c55.pdf
MALICIOUS — normal_5fb5c25db0c55.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
5b6178aefe918d3c28f62e7e684bc69b9ee8938d39fe18754ddf826d1c42cb59 - SHA-1:
ef1246b17ce2910e9e83e51c65f3d2061db26ccd - MD5:
025615858abd7d5f05886d6ddcec10d1 - ssdeep:
1536:Yu1qs/B06o9MZfNflJNNt938v7JnMNagzbv80GWhXBOgrs0/Yh3:PFO62MftlJntiv7qNag/UpgIgo0/M - TLSH:
T1C237D1F331D7CDCD7A469B136DF615A4600AC5892522E9A018CDBA7CC4B86FD3F20A90 - Submitted as: normal_5fb5c25db0c55.pdf
- File type: pdf · Size: 69758 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffking.ru/123?utm_term=citra+emulator+apk+download+android, https://cdn-cms.f-static.net/uploads/4393624/normal_5f99ef964ab16.pdf, https://uploads.strikinglycdn.com/files/7de3fcc1-3244-4932-9e4b-fe30cd1faa29/crafting_guide_osrs.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/123?utm_term=citra+emulator+apk+download+android
- https://cdn-cms.f-static.net/uploads/4393624/normal_5f99ef964ab16.pdf
- https://uploads.strikinglycdn.com/files/7de3fcc1-3244-4932-9e4b-fe30cd1faa29/crafting_guide_osrs.pdf
- https://cdn-cms.f-static.net/uploads/4369774/normal_5f88869a6d2ea.pdf
- https://cdn-cms.f-static.net/uploads/4368736/normal_5fa2e2ca72fb5.pdf
- https://uploads.strikinglycdn.com/files/d1991d56-bb8b-44a7-95c2-7b2e69920f80/acer_aspire_e5_522_82cx.pdf
- https://cdn-cms.f-static.net/uploads/4494673/normal_5fb35e9006a1a.pdf
- https://cdn-cms.f-static.net/uploads/4465685/normal_5fab9f3f81b62.pdf
- https://cdn-cms.f-static.net/uploads/4409628/normal_5fa8b7371cd8b.pdf
- https://uploads.strikinglycdn.com/files/cc978004-c310-4923-b507-3b88938d6cec/fixak.pdf
- https://cdn-cms.f-static.net/uploads/4368222/normal_5f8bcd7ea87ff.pdf
- https://cdn-cms.f-static.net/uploads/4445735/normal_5fb35a6d7d7c9.pdf
- https://cdn-cms.f-static.net/uploads/4380209/normal_5f9828d8df8a7.pdf
- https://cdn-cms.f-static.net/uploads/4373770/normal_5f895dbde69cb.pdf
- https://uploads.strikinglycdn.com/files/256a0a3d-ed7c-4041-90f1-abbb8c890ffb/oriental_adventures_3.5_errata.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report