MALICIOUS — normal_5fd1635a8364b.pdf
MALICIOUS — normal_5fd1635a8364b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
a245cefba1c6a63913409c49de93a089940f0f7b559a7cae83baed39b74a9aa0 - SHA-1:
962a22389d3e4ab250c60dcc70db6acd2232830e - MD5:
71c1413515fca48e76b63284ef2d8ac7 - ssdeep:
3072:2WcjPL7GWjdkbRelxzWX7imNcMMj7Uv6Vl+gO2M1mf8kNJMS3E7BxeQ3lvcAB:2WcjPHGSxCrTcj7YCRxf8c3E7BxbJ - TLSH:
T1DE4002F39547CD8D234767637BE6A4A8E269E2C42472EA9568C023DCC4B8FDD2C04D51 - Submitted as: normal_5fd1635a8364b.pdf
- File type: pdf · Size: 165386 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://gettraff.ru/123?utm_term=spoils+system+apush+gilded+age, https://cdn-cms.f-static.net/uploads/4383340/normal_5f932788cdd93.pdf, https://uploads.strikinglycdn.com/files/03eca7cf-8f13-4713-b874-6f22364d9f37/lawamilixadiwagodoru.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?utm_term=spoils+system+apush+gilded+age
- https://cdn-cms.f-static.net/uploads/4383340/normal_5f932788cdd93.pdf
- https://s3.amazonaws.com/jemazejodep/payroll_error_correction_letter_sample.pdf
- https://uploads.strikinglycdn.com/files/03eca7cf-8f13-4713-b874-6f22364d9f37/lawamilixadiwagodoru.pdf
- https://cdn-cms.f-static.net/uploads/4377905/normal_5faf8d2ab8990.pdf
- https://static1.squarespace.com/static/5fc06b0d2e537a05ef0695ba/t/5fc0e93164571256545ccf6d/1606478129464/xudujazu.pdf
- https://static1.squarespace.com/static/5fc699d1e2fce462bcb38289/t/5fc958f06bd95f39dfcd0185/1607031026469/wwe_universe_mod_unlimited_money.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf4b01145a8629dca72e26/1606372097937/out_out_robert_frost_macbeth.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/c7d1b7627f.pdf
- https://zunivagakasati.weebly.com/uploads/1/3/4/3/134340202/jiwus.pdf
- https://static1.squarespace.com/static/5fc0c9b1a5bc066edfa528b7/t/5fc528596457125654e1f2ee/1606756443617/forward_co_discarded_a_machine_that_cost_5000.pdf
- https://uploads.strikinglycdn.com/files/ef4843ad-4542-4a17-a476-9736c7a6fc75/tetaw.pdf
- https://static1.squarespace.com/static/5fc7828bd8e4f44799675b34/t/5fcafc921df7590d80d79551/1607138451718/41659871568.pdf
- https://uploads.strikinglycdn.com/files/d9b6c7ec-cf7a-4476-acc0-5a2282d6a41d/dedujapuzokodapodo.pdf
- https://uploads.strikinglycdn.com/files/f1c71918-72a1-429e-b054-3b09cc65f832/80135719791.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- static1.squarespace.com
- wetuxabo.weebly.com
- zunivagakasati.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report