MALICIOUS — normal_5fc9ebdd31c34.pdf
MALICIOUS — normal_5fc9ebdd31c34.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e9bbfc30e438583a1020d0c9e68725949099ee09ee4620b716b55eeb2e4c6aea - SHA-1:
5be2c20431be831d961106a886186f2af9a572c0 - MD5:
1994fbb4cb9b3f6cd529423dc44c38d0 - ssdeep:
1536:EmKnrPHexw7ddRz+kMEmo52NaKR6wJ49JGwSmGMFmmCgN0gnxsmycOg/ba8P8g8V:rsrmxw7XRznpg3R6w+9Yw/vNPKnwbz8h - TLSH:
T13338D1B3B25BDE6CBBC7BB037D771968A045D298213286552444B72CD8B97FC3E10A60 - Submitted as: normal_5fc9ebdd31c34.pdf
- File type: pdf · Size: 79809 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://jezitazosebizag.weebly.com/uploads/1/3/4/7/134700096/taxadifupesafutom.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafffi.ru/123?utm_term=good+times+theme+song+chords, https://cdn-cms.f-static.net/uploads/4391008/normal_5fa742189c773.pdf, https://jezitazosebizag.weebly.com/uploads/1/3/4/7/134700096/taxadifupesafutom.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffi.ru/123?utm_term=good+times+theme+song+chords
- https://cdn-cms.f-static.net/uploads/4391008/normal_5fa742189c773.pdf
- https://jezitazosebizag.weebly.com/uploads/1/3/4/7/134700096/taxadifupesafutom.pdf
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/ee5a0cbd9.pdf
- https://vajibudutoneraz.weebly.com/uploads/1/3/4/3/134345344/10818594d.pdf
- https://cdn-cms.f-static.net/uploads/4367903/normal_5f94cb9bc5224.pdf
- https://cdn-cms.f-static.net/uploads/4476123/normal_5fb3a538d945f.pdf
- https://cdn-cms.f-static.net/uploads/4379369/normal_5f925f1ca18cc.pdf
- https://xirovule.weebly.com/uploads/1/3/4/7/134749068/65ca6.pdf
- https://cdn-cms.f-static.net/uploads/4410717/normal_5fb4463a27504.pdf
- https://cdn-cms.f-static.net/uploads/4450747/normal_5fa8989b0e44d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffi.ru
- cdn-cms.f-static.net
- jezitazosebizag.weebly.com
- pavowojavujide.weebly.com
- vajibudutoneraz.weebly.com
- xirovule.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report