MALICIOUS — normal_5ff8621678716.pdf
MALICIOUS — normal_5ff8621678716.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
6c072ffb927fecf581cc36fdf40bd49498496984748511f2b12dc29c86a42f87 - SHA-1:
718406e273cedbb39a60d7049e9d891244b11a50 - MD5:
a734ac0aa6fcee278bac991917d7d84d - ssdeep:
1536:0EJm36Qzkg1mzZqzSrRM86UWACTeXl2glGlRBT+HewpOz9syx:hd1qzIRoUEUCRBT+HewpOnx - TLSH:
T16A39E1F3308BDEAC39975B53ADB72418118AC2C87033D56064D8A57CD5BD2AF7E10A22 - Submitted as: normal_5ff8621678716.pdf
- File type: pdf · Size: 84877 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!A734AC0AA6FC
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffnew.ru/123?utm_term=starbucks+caramel+brulee+latte+review, https://razivizufizide.weebly.com/uploads/1/3/4/5/134525322/039a42a.pdf, https://uploads.strikinglycdn.com/files/a861b513-265a-4aed-9544-05980e8165ae/zevorobodigimovijexuwawo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://traffnew.ru/123?utm_term=starbucks+caramel+brulee+latte+review
- https://razivizufizide.weebly.com/uploads/1/3/4/5/134525322/039a42a.pdf
- https://uploads.strikinglycdn.com/files/a861b513-265a-4aed-9544-05980e8165ae/zevorobodigimovijexuwawo.pdf
- https://uploads.strikinglycdn.com/files/4dcc8a3e-bda9-41a3-8086-75e03032547c/lopigib.pdf
- https://tumixivig.weebly.com/uploads/1/3/1/6/131636813/8045019.pdf
- https://s3.amazonaws.com/vexosafugunu/garbage_pickup_schedule_town_of_hempstead_ny.pdf
- https://uploads.strikinglycdn.com/files/dbbe7716-a503-44b0-bd6c-d45a7a00c3d4/5280900923.pdf
- https://s3.amazonaws.com/paxunu/free_check_register_excel.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/nolosejasawemafomiku.pdf
- https://ravidaxixow.weebly.com/uploads/1/3/4/3/134315840/vivegijafimob-zivinejuri-tegobaxunota-zigadopuj.pdf
- https://felekiki.weebly.com/uploads/1/3/4/6/134689652/17819f59e13d1.pdf
- https://melegejisud.weebly.com/uploads/1/3/1/3/131379421/dd69d725d98b71.pdf
- https://nipobajomofak.weebly.com/uploads/1/3/4/6/134641158/jugagapikaxepu.pdf
- https://s3.amazonaws.com/bezorito/55280228172.pdf
- https://s3.amazonaws.com/kovilowab/16544784802.pdf
- https://uploads.strikinglycdn.com/files/1cfab673-9dc4-4852-b965-7e6be7377ba2/planeaciones_telesecundaria_tercer_g.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffnew.ru
- razivizufizide.weebly.com
- uploads.strikinglycdn.com
- tumixivig.weebly.com
- s3.amazonaws.com
- jiwepurojal.weebly.com
- ravidaxixow.weebly.com
- felekiki.weebly.com
- melegejisud.weebly.com
- nipobajomofak.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report