MALICIOUS — normal_5fc4e84e01150.pdf
MALICIOUS — normal_5fc4e84e01150.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
a7ae52ae0446a43420898f469d281b80ca83cdeca06b4c389b9128b6f8259d75 - SHA-1:
cb4c6044985f29ebef4f5d8b86cccf32455f6ac4 - MD5:
78adaa4ff32d7ba446c4675f09ad136c - ssdeep:
1536:Hs8HiKbHaZZCeJj2bRt0MRb8gNN/4PWpFQCANyzgB1GQ8iHcfk:MyiG6ZZCeJ6bRyAbJ/NpFQCANykjf8iz - TLSH:
T14937D0F37197ED4C6695AB936CB3007D6882E38C6136EBE11884776CC97CAAE1D20C50 - Submitted as: normal_5fc4e84e01150.pdf
- File type: pdf · Size: 71038 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffmen.ru/123?utm_term=church+bulletin+ideas+for+easter, https://bewapuvin.weebly.com/uploads/1/3/1/4/131453684/da194e45eee.pdf, https://uploads.strikinglycdn.com/files/3eb905a1-e473-40ab-91ed-f46b5ad35315/dobuv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffmen.ru/123?utm_term=church+bulletin+ideas+for+easter
- https://bewapuvin.weebly.com/uploads/1/3/1/4/131453684/da194e45eee.pdf
- https://uploads.strikinglycdn.com/files/3eb905a1-e473-40ab-91ed-f46b5ad35315/dobuv.pdf
- https://nulumekut.weebly.com/uploads/1/3/4/3/134373747/vibokewulafaxokozare.pdf
- https://bewimowijukoja.weebly.com/uploads/1/3/4/5/134584545/4622519.pdf
- https://s3.amazonaws.com/vuzufexarevima/wedotabodivufusadaf.pdf
- https://static1.squarespace.com/static/5fbfeb102bbd74065800e14d/t/5fc355b53f75b166433ed902/1606636981898/barge_all_purpose_cement_2_oz.pdf
- https://najunores.weebly.com/uploads/1/3/4/3/134381484/05bf6.pdf
- https://uploads.strikinglycdn.com/files/216d536d-062e-473c-8208-694d18ad133e/atls_2018_em_portugues.pdf
- https://s3.amazonaws.com/nuxepiduded/93122240394.pdf
- https://s3.amazonaws.com/rujabepifar/tapabojefewu.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf625beaf37e3b6493a839/1606378076121/kara_no_kyoukai_parents_guide.pdf
- https://uploads.strikinglycdn.com/files/9aaed5b8-5145-40b3-9d14-67fcb80855f0/historia_de_espaa_2o_bachillerato_esquemas.pdf
- https://uploads.strikinglycdn.com/files/a710f01a-a45a-46c4-b519-6c4d0e529c58/popavutedudusapel.pdf
- https://s3.amazonaws.com/xubifupi/aadhar_card_by_aadhaar_number_only.pdf
- https://uploads.strikinglycdn.com/files/e3341404-868b-42fc-ac8b-a1f546054fc4/watozaxisonag.pdf
- https://xisegebimir.weebly.com/uploads/1/3/4/3/134340076/e78c63c5.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffmen.ru
- bewapuvin.weebly.com
- uploads.strikinglycdn.com
- nulumekut.weebly.com
- bewimowijukoja.weebly.com
- s3.amazonaws.com
- static1.squarespace.com
- najunores.weebly.com
- xisegebimir.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report