MALICIOUS — normal_5fad6f4910540.pdf
MALICIOUS — normal_5fad6f4910540.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
645c8713e0691f2bdbcdae1648bfb6086a1a12e28c21d38a5a7a9f2f01f459ad - SHA-1:
e1637d7d9928230abcef27853e709e86374b1424 - MD5:
f5adc4ff1810c05b847a53abced20aae - ssdeep:
1536:s0eWY3g6iImZJOCq/R1NqAoSEMR6loSDtkD4AywFAUN+cYeBO2SEod3n:MWY3g6Z2J1q/7kxqR6FtanbFD+jGO2qF - TLSH:
T13836D0F772DBDD98BA966B8374B924682488D34CB02256A0148CBB6DC5747FF7E00D80 - Submitted as: normal_5fad6f4910540.pdf
- File type: pdf · Size: 67426 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://ggtraff.ru/123?utm_term=solicitud+de+empleo+econo, https://uploads.strikinglycdn.com/files/4f8a801e-301e-45e2-ba80-264e82dd77e6/acer_aspire_7551_specs.pdf, https://cdn-cms.f-static.net/uploads/4427293/normal_5fa455f5373c5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?utm_term=solicitud+de+empleo+econo
- https://uploads.strikinglycdn.com/files/4f8a801e-301e-45e2-ba80-264e82dd77e6/acer_aspire_7551_specs.pdf
- https://cdn-cms.f-static.net/uploads/4427293/normal_5fa455f5373c5.pdf
- https://s3.amazonaws.com/tadovu/22542770749.pdf
- https://uploads.strikinglycdn.com/files/34dbd13e-2ddd-4f5d-af0b-95f4e5f7ad6c/99244984745.pdf
- https://s3.amazonaws.com/lixasifasi/37846265604.pdf
- https://uploads.strikinglycdn.com/files/50661ffb-6877-4b3f-b684-855536d4119f/denedezid.pdf
- https://s3.amazonaws.com/jotizifime/spiderman_future_foundation_suit_ps4.pdf
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f8a5c79902e6.pdf
- https://s3.amazonaws.com/xeroguru/bajimezowugizojefupok.pdf
- https://s3.amazonaws.com/nijudow/manual_update_2019_turbotax_business.pdf
- https://s3.amazonaws.com/fekaduvopigab/porque_existe_dia_y_noche.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f875f7c10e00.pdf
- https://cdn-cms.f-static.net/uploads/4464732/normal_5fa50fa1ab6e0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report