MALICIOUS — normal_5fc7a49984c20.pdf
MALICIOUS — normal_5fc7a49984c20.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
90bdbf8d4320b6cfe2425c89a06dc5f5d6f73501a59632aace4ce9c3752e80ae - SHA-1:
4e2ebdccf049c841d733158fc7fd3511c50d3fc8 - MD5:
b94f38563d3a521304fa21863bc971e1 - ssdeep:
1536:dbMc4xVzUPsdKEHGBUgiRkkezvRlfgu9J3Cszuk8H578LmHRGAVK8q:6ZPJd2qRkkezRlfg6rzOJ8yHRGAjq - TLSH:
T14037E1F3B25FDC9C66C39B432AE9384C7515D7885163AA2884C4772CC9B46BE3E20591 - Submitted as: normal_5fc7a49984c20.pdf
- File type: pdf · Size: 73158 bytes
- Verdict: malicious (97/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/e653cfa3-20da-4687-a95c-de114ba51489/tezagerejilonixipijevow.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafffe.ru/123?utm_term=lego+minifigures+series+11+welder, https://uploads.strikinglycdn.com/files/e653cfa3-20da-4687-a95c-de114ba51489/tezagerejilonixipijevow.pdf, https://uploads.strikinglycdn.com/files/b58ff779-904c-4971-bc79-24c3cc9a6aed/2470711406.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/123?utm_term=lego+minifigures+series+11+welder
- https://s3.amazonaws.com/pujinit/bosch_router_guide_bushing.pdf
- https://s3.amazonaws.com/zewimu/vusekedoxafijijejigubuji.pdf
- https://uploads.strikinglycdn.com/files/e653cfa3-20da-4687-a95c-de114ba51489/tezagerejilonixipijevow.pdf
- https://uploads.strikinglycdn.com/files/b58ff779-904c-4971-bc79-24c3cc9a6aed/2470711406.pdf
- https://cdn-cms.f-static.net/uploads/4413845/normal_5fb982cfa4616.pdf
- https://uploads.strikinglycdn.com/files/daf7ca1d-8dff-450e-95b4-5e835490a10b/78628484541.pdf
- https://uploads.strikinglycdn.com/files/2895b7f7-4882-4f20-96d7-015918f49fa9/83621871708.pdf
- https://s3.amazonaws.com/nilititonawafim/80460493275.pdf
- https://s3.amazonaws.com/fosalizuzu/call_of_duty_mobile_apk_obb_uptodown.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report