MALICIOUS — normal_5fcbd591473f1.pdf
MALICIOUS — normal_5fcbd591473f1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b5e7b05e30252c19c62fbf29337f4f0681f33a844a42cd8ba255f97775891019 - SHA-1:
4cbb3807a6e72ecca0cd7224cea3e8c03b57879a - MD5:
03ccf9ffd234f5f96bb9e700390d471d - ssdeep:
1536:/4CNkEt50RStl1UQft6U0441bLMlVaouFv:PkeeQsul0r1boDajv - TLSH:
T12135CEF751EBDD5CBA95AB4768E71478A44DD28C2132EA6054CC362CC1F82BE3E15A40 - Submitted as: normal_5fcbd591473f1.pdf
- File type: pdf · Size: 59819 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://pafoxewov.weebly.com/uploads/1/3/4/4/134470920/5fca8fee.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?utm_term=engineering+drawing+tutorial+pdf+ioe, https://xewoweduvaji.weebly.com/uploads/1/3/4/6/134680405/6cfc750c9f5.pdf, https://uploads.strikinglycdn.com/files/a65260d8-ec6a-4b4a-a0eb-d824e51070fb/pathfinder_gray_maiden_class.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?utm_term=engineering+drawing+tutorial+pdf+ioe
- https://xewoweduvaji.weebly.com/uploads/1/3/4/6/134680405/6cfc750c9f5.pdf
- https://uploads.strikinglycdn.com/files/a65260d8-ec6a-4b4a-a0eb-d824e51070fb/pathfinder_gray_maiden_class.pdf
- https://uploads.strikinglycdn.com/files/70bddb27-b7af-4809-9a85-20e128300666/7634346929.pdf
- https://uploads.strikinglycdn.com/files/deb353c3-8ed1-4127-8bf6-f840a5acbec7/yahoo_email_log_into_my_account.pdf
- https://uploads.strikinglycdn.com/files/2d9ca0b7-8c08-4593-a9c4-71f1847ce8ca/vosumawas.pdf
- https://pafoxewov.weebly.com/uploads/1/3/4/4/134470920/5fca8fee.pdf
- https://uploads.strikinglycdn.com/files/b38724d7-9f65-494d-9011-65f37b58f8c8/mafafugop.pdf
- https://uploads.strikinglycdn.com/files/e3a139bd-adba-4db6-a280-076943730e3d/how_to_make_pennis_thicker_and_longer_naturally_at_home_in_hindi.pdf
- https://uploads.strikinglycdn.com/files/0f433e05-d5a7-480c-a824-df5b27324dce/xogubosexefidujulebumik.pdf
- https://uploads.strikinglycdn.com/files/e17f5f08-575c-47bf-a62b-92894de9aac5/summer_olympics_basketball.pdf
- https://uploads.strikinglycdn.com/files/fe6d69b7-3c60-4c44-946f-3aef0a2d7011/xonizatajetosafomik.pdf
- https://uploads.strikinglycdn.com/files/5263ab7f-f40f-4692-a569-34714173b2da/lisaravitezapamusa.pdf
- https://s3.amazonaws.com/bejikefowu/union_grievance_letter_template.pdf
- https://uploads.strikinglycdn.com/files/a622970a-2bc2-476a-9e71-e619fb366b21/modamegipod.pdf
- https://static1.squarespace.com/static/5fc0d0065e8e827d428d60b5/t/5fc714dc4f9413233b1955cd/1606882525338/pamugonalikod.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- xewoweduvaji.weebly.com
- uploads.strikinglycdn.com
- pafoxewov.weebly.com
- s3.amazonaws.com
- static1.squarespace.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report