MALICIOUS — normal_5ff143056757c.pdf
MALICIOUS — normal_5ff143056757c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
ff2275c2a52f79d8f1b3b69b56c8ee3b442bbd78efc78d8d1c5cb54db6243b6b - SHA-1:
31c5fb0ccccddc5823421d4afc19f31b85132579 - MD5:
380ef8c998fe20046ecb469790f2e5fd - ssdeep:
1536:62gJMkl1lkU9ZLgtZQjhcNMOB1w+GbeLBn9gGdu22OD:iJPXHLgtZYOrB12berlHB - TLSH:
T1F136D0F320E7ECCCA68A6F136AA64498708AD2892536D75004887B7CD87C2BD7D54F51 - Submitted as: normal_5ff143056757c.pdf
- File type: pdf · Size: 68174 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!380EF8C998FE
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://traffking.ru/123?utm_term=auction+direct+service+department+victor+ny, https://uploads.strikinglycdn.com/files/4d9498b5-073f-4bcb-8113-d1e5a0e4df13/quality_function_deployment.pdf, https://uploads.strikinglycdn.com/files/d11f9c10-fb9b-421c-936d-5d0a711bdf6b/pakobineguregewuja.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/123?utm_term=auction+direct+service+department+victor+ny
- https://uploads.strikinglycdn.com/files/4d9498b5-073f-4bcb-8113-d1e5a0e4df13/quality_function_deployment.pdf
- https://uploads.strikinglycdn.com/files/d11f9c10-fb9b-421c-936d-5d0a711bdf6b/pakobineguregewuja.pdf
- https://uploads.strikinglycdn.com/files/4bf23ae1-d935-4441-af79-e7bb5501754a/dalaruworedawawutigumolup.pdf
- https://uploads.strikinglycdn.com/files/7d933831-76f2-441b-a9e5-ceefaf765de3/28517049740.pdf
- https://uploads.strikinglycdn.com/files/f6dd6d3e-e486-4d90-96e5-a96ad36233c2/reallit_army_acronym.pdf
- https://s3.amazonaws.com/baxegezivumi/72040593453.pdf
- https://s3.amazonaws.com/satulibaren/mugapazazemopevi.pdf
- https://s3.amazonaws.com/guwutivupudutu/steel_rx_reviews.pdf
- https://uploads.strikinglycdn.com/files/75709405-8a07-4bdc-b276-996f1ccd2f25/34448151020.pdf
- https://uploads.strikinglycdn.com/files/4644fdb5-123e-4096-9bcd-fa49664e0ba6/galaxy_3d_wallpaper_720x1280.pdf
- https://uploads.strikinglycdn.com/files/46eeb0a8-46fa-4435-8a60-f464c065d98e/stick_cricket_super_league_cheats.pdf
- https://s3.amazonaws.com/wetevali/clinical_guidelines_for_metastatic_prostate_cancer.pdf
- https://s3.amazonaws.com/tobobowu/jupajivekux.pdf
- https://uploads.strikinglycdn.com/files/2470b238-7907-4441-b331-26fcab30c5c4/norwalk_rec_center_pool.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report