MALICIOUS — normal_5fc8d4eea3bdd.pdf
MALICIOUS — normal_5fc8d4eea3bdd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e792810cf026a11c1f6843abca25dde311a29931277d8b55aaa8d98f893dd7bf - SHA-1:
1e8d946dbc04f8474555b5bd534ebdbfeb709fb1 - MD5:
f1031fa11fe3b673febab5cf9cdabb3a - ssdeep:
1536:Ctr8Y3p4UofvmTi/gUMksaVWOcTH0IcFxgZL8YcUpEye4I:oh2Vvmwg4HRIsxPUOz - TLSH:
T1FF37D0FB60EBCD9C7A5AEB177AE7595C348583852432936804A87B2CCC786BC6D10650 - Submitted as: normal_5fc8d4eea3bdd.pdf
- File type: pdf · Size: 70920 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/4383a4f8-1ece-46f2-ab7b-0bf05ac34339/warcraft_frozen_throne_guide.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafffi.ru/123?utm_term=artemis+greek+goddess+physical+appearance, https://uploads.strikinglycdn.com/files/4383a4f8-1ece-46f2-ab7b-0bf05ac34339/warcraft_frozen_throne_guide.pdf, https://uploads.strikinglycdn.com/files/8ab98526-4d52-4a8e-811a-1b33a757b1ef/91859603679.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffi.ru/123?utm_term=artemis+greek+goddess+physical+appearance
- https://uploads.strikinglycdn.com/files/4383a4f8-1ece-46f2-ab7b-0bf05ac34339/warcraft_frozen_throne_guide.pdf
- https://uploads.strikinglycdn.com/files/8ab98526-4d52-4a8e-811a-1b33a757b1ef/91859603679.pdf
- https://static1.squarespace.com/static/5fc00a5311f6a4198480ec6e/t/5fc1fdfe3485235c860d3041/1606548990883/15185018697.pdf
- https://uploads.strikinglycdn.com/files/2b308a08-241f-4bd3-9929-208b48c73b03/11405154952.pdf
- https://static1.squarespace.com/static/5fc0f83717e7202640ea8e04/t/5fc5c8ace6d49a06bb5bba33/1606797485242/617447688.pdf
- https://likerediweraj.weebly.com/uploads/1/3/4/6/134691167/loxotutokojatufib.pdf
- https://uploads.strikinglycdn.com/files/bd93f41f-03ae-4d19-ae5c-922d72b8a564/64654321398.pdf
- https://uploads.strikinglycdn.com/files/2f9596d2-c31d-40b8-a82b-70de2ebe9b50/conceptual_physical_science_5th_edition_download.pdf
- https://uploads.strikinglycdn.com/files/6d3d8f6c-efdb-4269-b3e7-ccba18c8be73/clash_of_clans_gem_hack_no_survey_no_download.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf568918e72e5fdbcebc18/1606375049609/favazevitab.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbd02f01491241adc46740f/1606222576953/physics_momentum_and_impulse_worksheet_answers.pdf
- https://uploads.strikinglycdn.com/files/c15c7cfc-a3ba-4b4b-9885-a06b605352a1/penizokixaxeseburidelutog.pdf
- https://uploads.strikinglycdn.com/files/c994af70-f03a-4faf-864d-c1adf62961c3/dizosezijitukokanoj.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf6a7f6457125654336849/1606380162263/rewriting_linear_equations_worksheet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffi.ru
- uploads.strikinglycdn.com
- static1.squarespace.com
- likerediweraj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report