MALICIOUS — normal_604b98206506d.pdf
MALICIOUS — normal_604b98206506d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9aa2309366f0c6f51ba3f560fa94b20f617f8e2cd6514e9ebb5c3469dab3bca6 - SHA-1:
3523561580ad8d2d96e8c6331f11f8522c2acf04 - MD5:
8ff467562e2c4d798215c4385813f988 - ssdeep:
1536:UovL4nGkCrA4nAfsylb5F9GfyWvbPTey8LiLuSPu1vh6V2yIv85V4h9:tvL4GvA4AfsMVFMP2hSPsvh8q85V6 - TLSH:
T11838D0F3B053EC8CBB9A6B17BCF6262C945AD2849133DE5115847B6CC5BC2AD7E10910 - Submitted as: normal_604b98206506d.pdf
- File type: pdf · Size: 81650 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!8FF467562E2C
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4479462/normal_5ff256ed88d6c.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://jacksth.ru/123?utm_term=bibliographic+information+chicago+style, https://static.s123-cdn-static.com/uploads/4479462/normal_5ff256ed88d6c.pdf, https://cdn.sqhk.co/xuwifoviwalo/jihaMc0/44165180435.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/123?utm_term=bibliographic+information+chicago+style
- https://static.s123-cdn-static.com/uploads/4479462/normal_5ff256ed88d6c.pdf
- https://cdn.sqhk.co/xuwifoviwalo/jihaMc0/44165180435.pdf
- https://cdn.sqhk.co/fetumamuv/jcibhe6/colony_brands_interview_questions.pdf
- http://bitugoxopezuwu.rf.gd/timeline_template_excel_2018.pdf
- https://7a48fde5-f9d1-4ce4-84a2-8b156d245d18.filesusr.com/ugd/8127dd_bb4ccdc475484f7b965ddf97355157dd.pdf?index=true
- https://cdn.sqhk.co/tatidukigag/glN9Ib2/naia_football_championship_2019.pdf
- https://cdn.sqhk.co/xemugugafot/BibVhfG/jisedenilu.pdf
- https://static.s123-cdn-static.com/uploads/4487622/normal_5fe2330a9c1f4.pdf
- http://potaberukogox.66ghz.com/90683075237.pdf
- http://lnstagram-office.com/alta_via_1_guide_bookzpsyc.pdf
- https://cdn.sqhk.co/pobijejok/AicdYjh/dobizotalarowezarefedu.pdf
- https://xotomunekezej.weebly.com/uploads/1/3/1/0/131070571/wemagapositeba_wuruzune_tuxobozegeb.pdf
- https://d71fc03c-aea6-48f7-a990-8afffb22108d.filesusr.com/ugd/3de8a6_b40e6568261c45a28767c1ca508849f4.pdf?index=true
- http://zuwaweno.iblogger.org/5377265506.pdf
- https://36fc1fe3-b646-4cc1-b6e9-de51469aea27.filesusr.com/ugd/3eb4bd_9cc5a2f6b5df4b16957588260a471504.pdf?index=true
- http://monongzhlh.space/kung_fu_techniques_bookwt11q.pdf
- https://cdn-cms.f-static.net/uploads/4448731/normal_6018506be9f09.pdf
- https://cdn-cms.f-static.net/uploads/4454811/normal_5fdc69187315e.pdf
- https://60f6da8c-824c-4163-aae9-6195f2ac7ed4.filesusr.com/ugd/7f16bd_54e2b744f50647bf8649daabdb7f438d.pdf?index=true
- https://bawezinanowele.weebly.com/uploads/1/3/4/3/134305895/pufeve_gukatafidimu_duwitasosasa_fajizusulu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- jacksth.ru
- static.s123-cdn-static.com
- cdn.sqhk.co
- 7a48fde5-f9d1-4ce4-84a2-8b156d245d18.filesusr.com
- potaberukogox.66ghz.com
- lnstagram-office.com
- xotomunekezej.weebly.com
- d71fc03c-aea6-48f7-a990-8afffb22108d.filesusr.com
- zuwaweno.iblogger.org
- 36fc1fe3-b646-4cc1-b6e9-de51469aea27.filesusr.com
- monongzhlh.space
- cdn-cms.f-static.net
- 60f6da8c-824c-4163-aae9-6195f2ac7ed4.filesusr.com
- bawezinanowele.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- bitugoxopezuwu.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report