MALICIOUS — normal_5fb6bd62cd94b.pdf
MALICIOUS — normal_5fb6bd62cd94b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
910a5399b12cdaf488f08809c16094698c431dbde8cbb3b6c15ddfa20350a19c - SHA-1:
82b2917ca01357982a286a8bf7b160c84516904b - MD5:
395373ee72cd8164d21d607fc65ac6f5 - ssdeep:
1536:uP0w1dIKeeH4ibOi+AIR0YjAK3D01QtlGwuTl7TAk8:F5Y4/iBU9AAD01M0lTE - TLSH:
T15A36E0F3615BCE84699AA743AAE64418681FE2C97032D6A008C4FB1C857D7BD7F10A61 - Submitted as: normal_5fb6bd62cd94b.pdf
- File type: pdf · Size: 68537 bytes
- Verdict: malicious (92/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafftec.ru/123?utm_term=ff4+ds+augment+guide, https://uploads.strikinglycdn.com/files/776cdae0-1aac-4f74-8be3-334ea748d2f1/30543288051.pdf, https://uploads.strikinglycdn.com/files/cc49f1c8-b570-44fc-92d7-9502cea5cf63/2827839264.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/123?utm_term=ff4+ds+augment+guide
- https://uploads.strikinglycdn.com/files/776cdae0-1aac-4f74-8be3-334ea748d2f1/30543288051.pdf
- https://uploads.strikinglycdn.com/files/cc49f1c8-b570-44fc-92d7-9502cea5cf63/2827839264.pdf
- https://cdn-cms.f-static.net/uploads/4371269/normal_5f8926d4b5141.pdf
- https://cdn-cms.f-static.net/uploads/4368751/normal_5f9ee7a6645f6.pdf
- https://nelugawoteraxum.weebly.com/uploads/1/3/4/7/134707069/zujonimokutot_wuponumuza_nowibove_pekajazip.pdf
- https://cdn-cms.f-static.net/uploads/4371508/normal_5f9fe21866b6b.pdf
- https://cdn-cms.f-static.net/uploads/4409814/normal_5f9e09aad4c09.pdf
- https://cdn-cms.f-static.net/uploads/4403563/normal_5f9713e12409d.pdf
- https://sewiwojura.weebly.com/uploads/1/3/4/3/134371681/2303939.pdf
- https://cdn-cms.f-static.net/uploads/4366319/normal_5f8787c320537.pdf
- https://uploads.strikinglycdn.com/files/e4d1a87c-a86f-4cf6-af36-9b7b29e31871/guxeduvegojog.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- nelugawoteraxum.weebly.com
- sewiwojura.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report