MALICIOUS — normal_5fd1603021038.pdf
MALICIOUS — normal_5fd1603021038.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5ee979a2ccb3362d077a0bba830e8470cd8dbe14608072438eb1eecec07c24e1 - SHA-1:
5c58f5c479d0403ee6ec9c58731ef43cd4ec9990 - MD5:
681d6216c2f869fda5ac8e9002c027af - ssdeep:
1536:sYj7ROitAwdHV4FP1ZoaUTvbzNrikrCTpfG/+jv1vlmZG+Y8loq3mgR6kwep:ZjljtAa4t1ZoaQXsZloYXqWgHv - TLSH:
T16736CFF366A7ED4DAA496B433EF6011CB58AD68C3536DB64088C3A6CC57C2FD2E11940 - Submitted as: normal_5fd1603021038.pdf
- File type: pdf · Size: 68167 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5a8ce6d49a06bb893242/1606376086774/bully_download_apk_mirror.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafficel.ru/123?utm_term=kuaiyong+ios+8.3.1, https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5a8ce6d49a06bb893242/1606376086774/bully_download_apk_mirror.pdf, https://static1.squarespace.com/static/5fce6b3bc6682d375c9096f4/t/5fd14f645843de79208e2cca/1607552868842/13648355005.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/123?utm_term=kuaiyong+ios+8.3.1
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5a8ce6d49a06bb893242/1606376086774/bully_download_apk_mirror.pdf
- https://s3.amazonaws.com/ropuba/heathcote_secondary_school_ofsted_report.pdf
- https://static1.squarespace.com/static/5fce6b3bc6682d375c9096f4/t/5fd14f645843de79208e2cca/1607552868842/13648355005.pdf
- https://static1.squarespace.com/static/5fc0e7ad6609fd0ee79153f2/t/5fc1645df8cdb769c617e036/1606509661650/persona_4_emperor_arcana_chance.pdf
- https://cdn-cms.f-static.net/uploads/4366647/normal_5f9f02f7f0105.pdf
- https://static1.squarespace.com/static/5fc28838abaecd33182c940e/t/5fc36eabfa04221c718bf35e/1606643372331/what_is_next_of_kin_in_australia.pdf
- https://static1.squarespace.com/static/5fc2a60b1c8c7413143d24fc/t/5fc681e03c02f22b9dee7d07/1606844897788/green_pepper_nutritional_information.pdf
- https://static1.squarespace.com/static/5fc0e9e3bda9c57a97be47bf/t/5fd0839bc0a29916a56d59f6/1607500702658/pinitipukanes.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f8b269bb7b7b.pdf
- https://static1.squarespace.com/static/5fc0ba3b0a2757459be1f9cb/t/5fc0ebdb5147b14804551ef4/1606478815724/ps_16_jersey_city_pre_k.pdf
- https://static1.squarespace.com/static/5fc38ff18787e879897cb51b/t/5fc5baf2bc819f1cf49f0c71/1606793971508/fefoxowawowusa.pdf
- https://static1.squarespace.com/static/5fc0e2c57848ba205d187778/t/5fc1525e9b1ed035380d0816/1606505059435/discipline_with_dignity_in_the_classroom.pdf
- https://static1.squarespace.com/static/5fc5b2462cf09257bd8c4d90/t/5fced10c57846c5b834411d9/1607389452392/welewubuzozusafazenozo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- static1.squarespace.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report