MALICIOUS — normal_5fff32a8c105d.pdf
MALICIOUS — normal_5fff32a8c105d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 50 detection engines flagged it.
Identification
- SHA-256:
d402ceadc1834cc62978976e02e867c38e66a36e191e749967808f4c074929a5 - SHA-1:
0b099a81d84ae095e98b6a440b2e6ea3d2ed153b - MD5:
51f55dc59bb91662e54ed444fc9e4dd8 - ssdeep:
1536:HK1CKiArCmSQ5igSoytkaDdSt5ey6ag/DZzFLuHZqYvvLl5:jKi3motjtthSt5e9/DZzcHZqYvvL - TLSH:
T15938D0F37253DD8CAB4BAB4366B316A83016C69872318F14A488B77CD9BC6BD7D04911 - Submitted as: normal_5fff32a8c105d.pdf
- File type: pdf · Size: 77548 bytes
- Verdict: malicious (92/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!51F55DC59BB9
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://trafffi.ru/123?utm_term=cottage+cheese+dip, https://site-1190639.mozfiles.com/files/1190639/plants_versus_zombies_youtube_videos.pdf, https://site-1175129.mozfiles.com/files/1175129/2048_3d_plus_no_ads.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffi.ru/123?utm_term=cottage+cheese+dip
- https://site-1190639.mozfiles.com/files/1190639/plants_versus_zombies_youtube_videos.pdf
- https://site-1175129.mozfiles.com/files/1175129/2048_3d_plus_no_ads.pdf
- https://site-1174077.mozfiles.com/files/1174077/epic_seven_yuna_guide.pdf
- https://cdn.sqhk.co/videgogaf/pihgcje/juniwejavogam.pdf
- https://cdn.sqhk.co/nuzinipaz/DgfoVNe/konirej.pdf
- https://site-1172777.mozfiles.com/files/1172777/boost_mobile_call_watch_app.pdf
- https://cdn.sqhk.co/wifenepomojo/Qhf6giS/superhero_run_2019_malaysia.pdf
- https://cdn.sqhk.co/kepilujofeje/gh6M0yk/81766317107.pdf
- https://cdn.sqhk.co/nezusoxe/iabEPsO/draw_easy_baby_shark.pdf
- https://site-1168007.mozfiles.com/files/1168007/kairobotica_mod_apk.pdf
- https://site-1168348.mozfiles.com/files/1168348/roxax.pdf
- https://cdn.sqhk.co/jabakujivim/fgfjjhf/39722615292.pdf
- https://site-1172267.mozfiles.com/files/1172267/lucky_lottery_scratchers_app.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffi.ru
- site-1190639.mozfiles.com
- site-1175129.mozfiles.com
- site-1174077.mozfiles.com
- cdn.sqhk.co
- site-1172777.mozfiles.com
- site-1168007.mozfiles.com
- site-1168348.mozfiles.com
- site-1172267.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report