MALICIOUS — normal_60034cddadd25.pdf
MALICIOUS — normal_60034cddadd25.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 6 of 50 detection engines flagged it.
Identification
- SHA-256:
b1eb533d1f64bdf70e03bfb4589ed486b0cee1598a44e5531862ac7ef0993b72 - SHA-1:
c0fec8d9dc6096ee93fdf0a7710f6d12d859f966 - MD5:
9d4dacbbaa53954c09c40c7139ff286c - ssdeep:
1536:kTqX1OGAot062gwpQtVka5oZTAGXodNIcjvOqZ4lA:H1OWi6LEaGZsGXodl7TZV - TLSH:
T14236D0F3201BDD8DB6C59FD7AFF2109CB059C3486122D6A055C9B65C88B86BC3E11A61 - Submitted as: normal_60034cddadd25.pdf
- File type: pdf · Size: 68987 bytes
- Verdict: malicious (92/100)
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!9D4DACBBAA53
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://cctraff.ru/123?utm_term=social+security+office+fremont+appointment, https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/tarewulemiretuze.pdf, https://site-1172801.mozfiles.com/files/1172801/merge_rush_z_hack_yeuapk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?utm_term=social+security+office+fremont+appointment
- https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/tarewulemiretuze.pdf
- https://site-1172801.mozfiles.com/files/1172801/merge_rush_z_hack_yeuapk.pdf
- https://cdn-cms.f-static.net/uploads/4450151/normal_5fe6f7ebbdc5c.pdf
- https://site-1168207.mozfiles.com/files/1168207/final_fantasy_2_walkthrough_arcane_labyrinth.pdf
- https://vawavujak.weebly.com/uploads/1/3/4/3/134350312/suvilenaxiwamafajag.pdf
- https://kepupumi.weebly.com/uploads/1/3/4/6/134616340/sazakap_gilubugenaw_ximuse.pdf
- https://site-1168131.mozfiles.com/files/1168131/killer_bean_unleashed_hack_apk_free_download.pdf
- https://kutumamam.weebly.com/uploads/1/3/4/8/134893394/19d9f832bd3e.pdf
- https://cdn-cms.f-static.net/uploads/4418383/normal_5fa48eec1a5c4.pdf
- https://site-1173610.mozfiles.com/files/1173610/94964317202.pdf
- https://site-1166603.mozfiles.com/files/1166603/vuvidefebelufulupore.pdf
- https://s3.amazonaws.com/sisaxu/kms_activator_office_2013_windows_8.pdf
- https://site-1168250.mozfiles.com/files/1168250/courage_the_cowardly_dog_dome_of_doom.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- mefemanodi.weebly.com
- site-1172801.mozfiles.com
- cdn-cms.f-static.net
- site-1168207.mozfiles.com
- vawavujak.weebly.com
- kepupumi.weebly.com
- site-1168131.mozfiles.com
- kutumamam.weebly.com
- site-1173610.mozfiles.com
- site-1166603.mozfiles.com
- s3.amazonaws.com
- site-1168250.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report