MALICIOUS — normal_5fb3511f614b7.pdf
MALICIOUS — normal_5fb3511f614b7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
7cfa5104e09f5528e257f4c13e99bb8723840c9e63e0cb068e2709c93ade9bd1 - SHA-1:
6d8bea07aff6faf4aa211a1144b9307b8bbcfae7 - MD5:
4979d215e284a6c28ed399fa80b48a1c - ssdeep:
1536:V5DRGLsL47+CsjCHzc+IMpeXQd1o1SPq6/ARg8J/yA3kB9uohCFUyR:tGYLSsjQc+IM121SARg8J/yA3hfFn - TLSH:
T1AB36D0F752D7CDDC66666B03FEEA211460DEEB45A231DD600488B72C88783BEBD20951 - Submitted as: normal_5fb3511f614b7.pdf
- File type: pdf · Size: 69453 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffset.ru/123?utm_term=zygor+guide+free+classic+wow, https://gepinizidewepi.weebly.com/uploads/1/3/4/3/134305752/rizukusubarufipab.pdf, https://lalusaguru.weebly.com/uploads/1/3/4/6/134611329/2677419.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://traffset.ru/123?utm_term=zygor+guide+free+classic+wow
- https://s3.amazonaws.com/labitajaxatufib/jawekev.pdf
- https://gepinizidewepi.weebly.com/uploads/1/3/4/3/134305752/rizukusubarufipab.pdf
- https://lalusaguru.weebly.com/uploads/1/3/4/6/134611329/2677419.pdf
- https://uploads.strikinglycdn.com/files/954e1422-c220-4677-a917-d481b519273b/ribewaloretexabumon.pdf
- https://uploads.strikinglycdn.com/files/a3da10b1-0c63-431a-bfbc-aa1a8c4ecda2/18501378046.pdf
- https://bizetuxerupa.weebly.com/uploads/1/3/0/8/130873791/672f0f26.pdf
- https://uploads.strikinglycdn.com/files/30df9d70-e30c-424f-8cc3-d3233dab4aa8/64131526359.pdf
- https://zelikozuka.weebly.com/uploads/1/3/4/5/134594864/972340260a.pdf
- https://uploads.strikinglycdn.com/files/f4b399d7-563d-451c-85b5-2c4a6155a1a8/rudofanuramevanadasotota.pdf
- https://s3.amazonaws.com/virumutipalis/debitex.pdf
- https://mumixopid.weebly.com/uploads/1/3/1/8/131872042/fuderibavu.pdf
- https://s3.amazonaws.com/rozebofukixus/82464378898.pdf
- https://xulajaxosu.weebly.com/uploads/1/3/4/3/134366267/6118974.pdf
- https://uploads.strikinglycdn.com/files/7e964bd0-02bc-469d-9824-e1ada96d9ca5/togerosiv.pdf
- https://xovatikawe.weebly.com/uploads/1/3/4/7/134726086/wafaribikova-xubotikomabana-zitanaxedaga-wukagogajuv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffset.ru
- s3.amazonaws.com
- gepinizidewepi.weebly.com
- lalusaguru.weebly.com
- uploads.strikinglycdn.com
- bizetuxerupa.weebly.com
- zelikozuka.weebly.com
- mumixopid.weebly.com
- xulajaxosu.weebly.com
- xovatikawe.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report