MALICIOUS — normal_5fec525fb5ca9.pdf
MALICIOUS — normal_5fec525fb5ca9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
b0b1c5c4e9a9ed30a79a16870aa8ffca4d020c42b31062fa56f790d268b447f8 - SHA-1:
bd5a0d3bb6e43a9e9da123a4e669a9c3490563fd - MD5:
b930e98f6ea4f191ee4ea477e29ee060 - ssdeep:
1536:9sblRwSNOaeXxDGzXdqr2Y0WdEElg3WLHMRiQLr2iYkosgIaQr1:KlRwSZeXxDQsrHl7XQmyJ - TLSH:
T14E38D0F7628BCCCC66D6AF9769B9201A504ED78970728A64458CB62CF9783AD7F00D00 - Submitted as: normal_5fec525fb5ca9.pdf
- File type: pdf · Size: 77425 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://ggtraff.ru/123?utm_term=viking+epic+1706+owners+manual, https://uploads.strikinglycdn.com/files/b72dc4a6-b43d-419f-8682-01ecb2b0e4bc/portafolio_de_evidencias_ejemplo.pdf, https://uploads.strikinglycdn.com/files/b9f7896f-8cac-4bac-b89a-e97450513265/kuwexalagapel.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?utm_term=viking+epic+1706+owners+manual
- https://uploads.strikinglycdn.com/files/b72dc4a6-b43d-419f-8682-01ecb2b0e4bc/portafolio_de_evidencias_ejemplo.pdf
- https://uploads.strikinglycdn.com/files/b9f7896f-8cac-4bac-b89a-e97450513265/kuwexalagapel.pdf
- https://uploads.strikinglycdn.com/files/6e1bcfe2-7fb5-4d5a-9a6d-96509300cf7a/65040939439.pdf
- https://uploads.strikinglycdn.com/files/b8455c36-3216-4a84-833e-76780fab2e1b/is_hot_tea_a_homogeneous_mixture.pdf
- https://nifirasevaxo.weebly.com/uploads/1/3/4/7/134756957/c2c10.pdf
- https://uploads.strikinglycdn.com/files/c97d0af8-ff3b-4552-8875-598da183ca01/41476006975.pdf
- https://uploads.strikinglycdn.com/files/c05daece-6dce-476d-b275-b3a607840131/49440472138.pdf
- https://uploads.strikinglycdn.com/files/d0672310-d020-4f45-ba73-d60d7757098b/impossible_quiz_3_answers.pdf
- https://selokifasafu.weebly.com/uploads/1/3/4/3/134383977/5208005.pdf
- https://jadomurujamum.weebly.com/uploads/1/3/5/3/135326923/momoliri.pdf
- https://uploads.strikinglycdn.com/files/d763868f-4c79-419c-9d2d-2a1b3f7a0ba0/gidafuririzofetabovozi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- nifirasevaxo.weebly.com
- selokifasafu.weebly.com
- jadomurujamum.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report