MALICIOUS — normal_5fe7c24641b47.pdf
MALICIOUS — normal_5fe7c24641b47.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ea87b99322398bffd72cad832dc901e5659efb85c0718d4fcb4ba79285a83ee5 - SHA-1:
e5f738b80ece51bc286bb46129ce8dd6f2ac0183 - MD5:
92c3d792a3f56d8a522b9f5d4f4ba4e6 - ssdeep:
1536:vFBshk4Ogn8wwpixi+pOhNxCzyuir+I+fBv4VKvCRjCIAwO:hRRwwpgiqOhN0z0r+IC4V+geIe - TLSH:
T17E37E0F3A1A7CD8CA6B167133DF75918109989C87522DA3804CCBB7CC5F8AAD6F00941 - Submitted as: normal_5fe7c24641b47.pdf
- File type: pdf · Size: 70448 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://fekugutupufug.weebly.com/uploads/1/3/4/8/134876907/d1ba6.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?utm_term=molten+core+loot+drops, https://nusutena.weebly.com/uploads/1/3/0/7/130739474/5723685.pdf, https://uploads.strikinglycdn.com/files/85b749ae-d473-4d85-b06a-9e5cdc0c112b/resume_job_skills_checklist.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?utm_term=molten+core+loot+drops
- https://nusutena.weebly.com/uploads/1/3/0/7/130739474/5723685.pdf
- https://uploads.strikinglycdn.com/files/85b749ae-d473-4d85-b06a-9e5cdc0c112b/resume_job_skills_checklist.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/pulatoj.pdf
- https://s3.amazonaws.com/fotepopunaj/zaxuv.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/lekov.pdf
- https://pasezarovatif.weebly.com/uploads/1/3/4/8/134858127/7178877.pdf
- https://cdn.sqhk.co/sekigozujeme/Ehenn3E/world_war_rising_hannibal.pdf
- https://s3.amazonaws.com/taturi/antiarrhythmic_drugs_classification_and_mechanism.pdf
- https://cdn.sqhk.co/femaxozimom/WifhdEz/spotlight_room_escape_hope_safe_code.pdf
- https://s3.amazonaws.com/xalexojaxipud/the_egyptian_museum_cairo_official_catalogue.pdf
- https://fekugutupufug.weebly.com/uploads/1/3/4/8/134876907/d1ba6.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- nusutena.weebly.com
- uploads.strikinglycdn.com
- vozunutav.weebly.com
- s3.amazonaws.com
- rabifupokuwu.weebly.com
- pasezarovatif.weebly.com
- cdn.sqhk.co
- fekugutupufug.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report