MALICIOUS — normal_5fe2e7dcba711.pdf
MALICIOUS — normal_5fe2e7dcba711.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
72adc24c5e7b9aa38d1b9ce713ab9fb5401b98d124dd4e6d5ffb7f7e3caf0d3b - SHA-1:
78d4d7c85ffc9e2ef9fc5547c05f829d434dc1fa - MD5:
465ef8f3b760b11dfecb1b666cff655f - ssdeep:
1536:2dHdrAUUq1Hgmkn6JLhDQHAIqbapCb82d9f3p68RzpugVrXxN:QMggmQ6EHo2a8YBtucrH - TLSH:
T1EA37D1F3216BDD4CA788DF079AAB1948A449D7493131EA2409C8F37D89BC2BD6F10E51 - Submitted as: normal_5fe2e7dcba711.pdf
- File type: pdf · Size: 73582 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://valazasabo.weebly.com/uploads/1/3/1/3/131398294/24c454a6e26ac.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafffe.ru/123?utm_term=windows+change+password+shortcut, https://uploads.strikinglycdn.com/files/a332fd6b-c648-4475-a2c9-aff7e124b729/2019-2020_school_calendar.pdf, https://uploads.strikinglycdn.com/files/6be6ff12-6480-4f95-86aa-535166197399/52409076831.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/123?utm_term=windows+change+password+shortcut
- https://uploads.strikinglycdn.com/files/a332fd6b-c648-4475-a2c9-aff7e124b729/2019-2020_school_calendar.pdf
- https://s3.amazonaws.com/nalifij/11013144174.pdf
- https://s3.amazonaws.com/kuxuxemu/17371838293.pdf
- https://s3.amazonaws.com/libosokune/wepob.pdf
- https://uploads.strikinglycdn.com/files/6be6ff12-6480-4f95-86aa-535166197399/52409076831.pdf
- https://s3.amazonaws.com/satuja/bhojpuri_song_dj_hd_mp4.pdf
- https://valazasabo.weebly.com/uploads/1/3/1/3/131398294/24c454a6e26ac.pdf
- https://uploads.strikinglycdn.com/files/091dc4a8-8a53-4cf6-a79e-ef9ed253fb49/inventioneers_game_solutions.pdf
- https://s3.amazonaws.com/gotijejaj/btc_blockchain_price.pdf
- https://s3.amazonaws.com/zaxawetawupo/snubbing_meaning_in_urdu.pdf
- https://uploads.strikinglycdn.com/files/421a4abe-7fd7-42a9-a1a3-5ce7acb611ec/pelujumozuvamid.pdf
- https://rudarizegofuk.weebly.com/uploads/1/3/4/3/134355262/temefiwulukem-rinamavupa-jasupu.pdf
- https://s3.amazonaws.com/xonobijikivo/apertura_mail_formale_inglese.pdf
- https://uploads.strikinglycdn.com/files/b05764b6-d7d8-43c1-b53c-6a2cbafb7d51/56302589501.pdf
- https://tizukusijevawus.weebly.com/uploads/1/3/4/4/134454617/8102860.pdf
- https://tedumuwoke.weebly.com/uploads/1/3/1/3/131397970/sazejikixedova-dutuvuxafabe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- valazasabo.weebly.com
- rudarizegofuk.weebly.com
- tizukusijevawus.weebly.com
- tedumuwoke.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report