MALICIOUS — normal_5f87b9b3362c9.pdf
MALICIOUS — normal_5f87b9b3362c9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
07bc571bb4555e847c0e76dea15dbde122d55d68afe19ba4b96873c212bc611a - SHA-1:
b029c85a08acc47d2e234861dca2a1d94c5eb3d3 - MD5:
c266db1bfce3363ff955eb04f51dbdea - ssdeep:
768:BxJgGzpDde3fRF31ebWbRkF9gPBCKCpZ2Bv8jggEFJfOzzwuyKw5yRHwdG:2GFJeVebARkFoKc8/EFAzs75yFwdG - TLSH:
T16A338DF300A7DD8C7A87AB035ABE1919918BD74D2132A7A44498B77DC4BC67C7F50A20 - Submitted as: normal_5f87b9b3362c9.pdf
- File type: pdf · Size: 51830 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/jasamejug-jenutuzudemeluf.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=cast+from+android+to+pc+windows+10, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/jasamejug-jenutuzudemeluf.pdf, https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/74ae5439bbe84.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=cast+from+android+to+pc+windows+10
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/jasamejug-jenutuzudemeluf.pdf
- https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/74ae5439bbe84.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/e276efd25922.pdf
- https://cdn-cms.f-static.net/uploads/4366633/normal_5f877e9ebc628.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f87a6c4a4f3a.pdf
- https://site-1039207.mozfiles.com/files/1039207/87604769009.pdf
- https://site-1038634.mozfiles.com/files/1038634/70323384111.pdf
- https://site-1040399.mozfiles.com/files/1040399/netij.pdf
- https://site-1037228.mozfiles.com/files/1037228/66772721362.pdf
- https://uploads.strikinglycdn.com/files/659b33a7-dff6-4d18-ba02-1cc6ffee7bb0/34631271822.pdf
- https://uploads.strikinglycdn.com/files/dcb53a7c-f0fb-47f7-991a-65bab12e27d9/zibigenigipekak.pdf
- https://uploads.strikinglycdn.com/files/8854c9c9-4a74-489f-94b4-5826b4b8448f/44322323648.pdf
- https://uploads.strikinglycdn.com/files/f7bb4921-6151-4082-bfcc-9ec08d9d37e4/ravilu.pdf
- https://uploads.strikinglycdn.com/files/9228256f-da0c-416d-ae70-7a70d566a28c/50011178234.pdf
- https://uploads.strikinglycdn.com/files/f6782303-b2d0-4f0c-bd29-e69a71e85fa5/luwuladuxesujumaxekome.pdf
- https://uploads.strikinglycdn.com/files/97c6cccd-357c-4c54-ba12-3561381e9e2e/somunexugip.pdf
- https://uploads.strikinglycdn.com/files/a78b3ea9-dd69-4b8c-a71b-22753ed77c52/77800036608.pdf
- https://uploads.strikinglycdn.com/files/9696a169-0d12-4248-abf3-cca9fea16e3c/68129715855.pdf
- https://uploads.strikinglycdn.com/files/79443278-7749-4c74-bd00-22a3977b7e75/45769079475.pdf
- https://uploads.strikinglycdn.com/files/6da87a77-4107-440e-b81a-5ff218d12cca/jizewigoxafevukuvinisi.pdf
- https://uploads.strikinglycdn.com/files/0a2cce97-25f5-4957-8543-2a7531b1e24c/lowab.pdf
- https://uploads.strikinglycdn.com/files/d7ee98ba-2113-4cb0-a46e-19b239858ec0/kubopuvutuvevedulamug.pdf
- https://uploads.strikinglycdn.com/files/d2c17ce1-f304-4bb2-beb4-01537b5945a4/40026843111.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- jakedekokobara.weebly.com
- ninukiwipovesot.weebly.com
- lipowuripipu.weebly.com
- cdn-cms.f-static.net
- site-1039207.mozfiles.com
- site-1038634.mozfiles.com
- site-1040399.mozfiles.com
- site-1037228.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report