MALICIOUS — normal_5ff5eb62c5afb.pdf
MALICIOUS — normal_5ff5eb62c5afb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
8c6b8ca9c666bb5e39a2a5f891b646349a32299518d6c1e8e28d6540f19678ad - SHA-1:
936254abae13ef44a571366f28176ec24704ade8 - MD5:
1f39b46248444abc5c120d7d56917e84 - ssdeep:
1536:gD5/jGcqUTlUHsHX6xh8AmpUfdo6DybWb4h+A+Kt8:O5bGLU57Ye521pDL45+j - TLSH:
T10336E0F752A7DC9C62C66B437AA51829590BC28CB133A270448876BDCC7C3FD7E60964 - Submitted as: normal_5ff5eb62c5afb.pdf
- File type: pdf · Size: 65443 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffine.ru/123?utm_term=chasing+cars+lyrics+and+chords, https://uploads.strikinglycdn.com/files/c44b2851-6c8b-481d-b059-aa3e96bd036a/89716921324.pdf, https://cdn.sqhk.co/dajebala/VRjjgfp/begidiradakirurowatago.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://traffine.ru/123?utm_term=chasing+cars+lyrics+and+chords
- https://uploads.strikinglycdn.com/files/c44b2851-6c8b-481d-b059-aa3e96bd036a/89716921324.pdf
- https://cdn.sqhk.co/dajebala/VRjjgfp/begidiradakirurowatago.pdf
- https://s3.amazonaws.com/pukaridimupo/adventures_of_tintin_subtitles_english.pdf
- https://cdn-cms.f-static.net/uploads/4471484/normal_5fa83e493010e.pdf
- https://uploads.strikinglycdn.com/files/b36401ba-a930-4aa7-9044-a2eabbec9ac9/pakesunojazafegupijov.pdf
- https://static.s123-cdn-static.com/uploads/4420934/normal_5fcc2b2971c01.pdf
- https://uploads.strikinglycdn.com/files/6eae5f80-6a57-47e0-8290-8da55ed228ac/four_letter_words_using_these_letters_book.pdf
- https://uploads.strikinglycdn.com/files/88a303d5-bfaf-4479-b436-01d80f479cc3/56119278217.pdf
- https://uploads.strikinglycdn.com/files/2cddd4f9-e560-4c67-aa09-d2b1aabe9c50/79238014633.pdf
- https://s3.amazonaws.com/desenaz/dovibipopanesonuka.pdf
- https://cdn-cms.f-static.net/uploads/4372980/normal_5f9d1ccc4141c.pdf
- https://uploads.strikinglycdn.com/files/747fe597-f738-4f44-b119-47c229edd1ee/89468435080.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffine.ru
- uploads.strikinglycdn.com
- cdn.sqhk.co
- s3.amazonaws.com
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report