MALICIOUS — normal_5feff91b24a9a.pdf
MALICIOUS — normal_5feff91b24a9a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 6 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
82cf2c83d9fdeecdf3b5acd19acedb00bacd63fabd707dfccd42b3aaf6445c8b - SHA-1:
71b6aabf978efe7c431a7ff316c6710992b679ff - MD5:
44e6dc5d6937d9db2ada9e9c17dd44e7 - ssdeep:
1536:iVlnpgREyKz9rx+ZbkbhIW6Wf1A+7Ie91fQMsmeGQnW+64:SgayI9l+6aW6sA+71fs+Sy4 - TLSH:
T1AB38D0F364DBEC8C6687A7436A9A9548B49AC5CD7433C5B0048477ACC8BC26D3F22871 - Submitted as: normal_5feff91b24a9a.pdf
- File type: pdf · Size: 77381 bytes
- Verdict: malicious (96/100)
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!44E6DC5D6937
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4469375/normal_5fc8b5aae2254.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafffe.ru/123?utm_term=poulan+pro+p46zx+briggs+v-twin, https://uploads.strikinglycdn.com/files/6bd7b0ea-65fb-418d-8750-c21a152d8c25/geluxivoj.pdf, https://cdn-cms.f-static.net/uploads/4387925/normal_5fbc773f5e4fa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/123?utm_term=poulan+pro+p46zx+briggs+v-twin
- https://uploads.strikinglycdn.com/files/6bd7b0ea-65fb-418d-8750-c21a152d8c25/geluxivoj.pdf
- https://cdn-cms.f-static.net/uploads/4387925/normal_5fbc773f5e4fa.pdf
- https://cdn.sqhk.co/kuzosexiwugu/Le6gcii/xuwasize.pdf
- https://cdn.sqhk.co/mibajufaneja/Ljho0gj/clever_keyboard_abc_learning.pdf
- https://s3.amazonaws.com/bokofapig/pukazesu.pdf
- https://static.s123-cdn-static.com/uploads/4469375/normal_5fc8b5aae2254.pdf
- https://cdn.sqhk.co/jawutuwek/WYIpfIP/sniper_3d_assassin_pvp_guide.pdf
- https://cdn-cms.f-static.net/uploads/4495402/normal_5fb3ce5489376.pdf
- https://cdn.sqhk.co/ginijetemepa/jiEOgeQ/vefukegaz.pdf
- https://cdn.sqhk.co/bufutoje/UOhdgjy/21976444711.pdf
- https://s3.amazonaws.com/sabobenuwe/aviation_english.pdf
- https://cdn-cms.f-static.net/uploads/4460045/normal_5fa8e87cc4912.pdf
- https://s3.amazonaws.com/pusolefosex/merekokideruzofevurimak.pdf
- https://cdn-cms.f-static.net/uploads/4409246/normal_5fb4cd58e09b3.pdf
- https://uploads.strikinglycdn.com/files/0442ea00-bb92-4ac8-8281-0b9332abdafd/gebugubemosatabokageva.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.sqhk.co
- s3.amazonaws.com
- static.s123-cdn-static.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report