MALICIOUS — normal_5fc88f7c2650a.pdf
MALICIOUS — normal_5fc88f7c2650a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c92d61cc5ca19b93e9edc31204622c97237395cc1e9650a65535cf620640cd85 - SHA-1:
6ec192761e4624d6ddfb81dbceb8aa37fa02044a - MD5:
35638d53620cf66e4a4f9284fe9c1cff - ssdeep:
1536:Zj1CWXdb9izRcVQp3WvFEDIlq/9qXErTQTlzwS17GXVZWIP8fWHF2T:bCWXdRyGI3WjErTQTlzwS1a78eHU - TLSH:
T17238D0F36157CD8CB6C4DF63FEBB052DB09BD6C42162875058C46ABC94B82BE6E10A41 - Submitted as: normal_5fc88f7c2650a.pdf
- File type: pdf · Size: 78534 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4451752/normal_5fc8715fb06b5.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafffe.ru/123?utm_term=ohio+river+valley+elevation+map, https://static1.squarespace.com/static/5fc0e0febe9b6939510aa6a3/t/5fc144d33c6ccf69f38c9725/1606501587503/game_killer_no_root.pdf, https://static.s123-cdn-static.com/uploads/4451752/normal_5fc8715fb06b5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/123?utm_term=ohio+river+valley+elevation+map
- https://static1.squarespace.com/static/5fc0e0febe9b6939510aa6a3/t/5fc144d33c6ccf69f38c9725/1606501587503/game_killer_no_root.pdf
- https://static.s123-cdn-static.com/uploads/4451752/normal_5fc8715fb06b5.pdf
- https://static1.squarespace.com/static/5fc370cbcd1e280355e45738/t/5fc69397fa04221c7105fc70/1606849431933/jio_prime_recharge_99_paytm.pdf
- https://static1.squarespace.com/static/5fc0d9d540f1034a5ca886a6/t/5fc7566e56cd4459b3b6b983/1606899310790/zotuvekipofo.pdf
- https://niwejeru.weebly.com/uploads/1/3/4/3/134308800/nixitegilamije.pdf
- https://static1.squarespace.com/static/5fc14748c89e1c4b8fc0f61a/t/5fc7b7775060c93fcd880429/1606924159330/debonaledejap.pdf
- https://cdn-cms.f-static.net/uploads/4369769/normal_5faf4c6c3c970.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf4db31972c46e3c952b4e/1606372788530/fourth_grade_fsa_writing_practice_prompts_2018.pdf
- https://cdn-cms.f-static.net/uploads/4456134/normal_5fb779ba54803.pdf
- https://static1.squarespace.com/static/5fc00a5311f6a4198480ec6e/t/5fc1701e2dd96f5918258a80/1606512670706/bohr_model_worksheet_chemistry_answers.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5fa26bc3aef46.pdf
- https://static1.squarespace.com/static/5fc0e1846b97992eb55bfc03/t/5fc43643145a8629dc360f81/1606694468032/rilixovil.pdf
- https://cdn-cms.f-static.net/uploads/4380522/normal_5f8cb7f4ca97b.pdf
- https://static1.squarespace.com/static/5fc2a453cd1e280355df5d9e/t/5fc400103f75b16643502785/1606680592893/73984394258.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf4aaf1972c46e3c94e53f/1606372016224/gelen.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- static1.squarespace.com
- static.s123-cdn-static.com
- niwejeru.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report