MALICIOUS — normal_5f8b317ad9e16.pdf
MALICIOUS — normal_5f8b317ad9e16.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0a73e4a52910f673961e9b13fb1991d58b56450d853a9f76f9d45a17d200b496 - SHA-1:
08c6f07ddb2cb8a759864e7dd554168afecf2bd2 - MD5:
4d41dff8322b7b888f42a33c1e6d9f5b - ssdeep:
1536:RGFVe41aye5BC02GvAldcJsWQG9TeIDQ/rha:0FVe4Uye5B+GvAldcl0IMTI - TLSH:
T11235BFF76147EC887AC3AF0369E624A9219AD7882071A7A410CC773DC57C3BD7E50A51 - Submitted as: normal_5f8b317ad9e16.pdf
- File type: pdf · Size: 61846 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://cdn-cms.f-static.net/uploads/4366385/normal_5f876f39ed615.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=android+coordinatorlayout+toolbar+example, https://uploads.strikinglycdn.com/files/a45fa9c9-1871-4224-b9a3-8d7b49c4c5a2/3380333250.pdf, https://uploads.strikinglycdn.com/files/eebf5f5d-e10e-4aa3-a316-7ef568651a9e/8214089366.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=android+coordinatorlayout+toolbar+example
- https://uploads.strikinglycdn.com/files/a45fa9c9-1871-4224-b9a3-8d7b49c4c5a2/3380333250.pdf
- https://uploads.strikinglycdn.com/files/eebf5f5d-e10e-4aa3-a316-7ef568651a9e/8214089366.pdf
- https://uploads.strikinglycdn.com/files/c7711514-c39c-4233-819b-d7641ac1862e/17661293604.pdf
- https://uploads.strikinglycdn.com/files/83e52f32-9f6a-4b6a-898d-69fddd6a26e1/ikea_borgsjo_discontinued.pdf
- https://uploads.strikinglycdn.com/files/d1da08c4-082d-4326-9ec9-6c3e5102803c/jekajovedosurodesu.pdf
- https://wojeribexojuxu.weebly.com/uploads/1/3/1/8/131856158/e354a7809599.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/fezimexebitodugivife.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f87398d5684d.pdf
- https://cdn-cms.f-static.net/uploads/4366385/normal_5f876f39ed615.pdf
- https://cdn-cms.f-static.net/uploads/4379859/normal_5f8b04acc750e.pdf
- https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/6420032.pdf
- https://redunexodozik.weebly.com/uploads/1/3/0/8/130814050/tuwewalovirozul.pdf
- https://penulikadima.weebly.com/uploads/1/3/1/4/131482887/2734f5d9.pdf
- https://uploads.strikinglycdn.com/files/572ea540-3d63-4db6-8a7e-0abee9c4c907/jexudavetalewaxan.pdf
- https://uploads.strikinglycdn.com/files/ab10bb18-2062-436d-95ab-ab119786209b/92469424802.pdf
- https://uploads.strikinglycdn.com/files/a408d201-e6df-4c99-b065-9e94b643c60c/26691643682.pdf
- https://uploads.strikinglycdn.com/files/b8158bba-6c4a-4158-bd72-1d87061d8705/87382910750.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- wojeribexojuxu.weebly.com
- megadezatesaram.weebly.com
- cdn-cms.f-static.net
- kokubexajaluk.weebly.com
- redunexodozik.weebly.com
- penulikadima.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report