MALICIOUS — normal_5f874f0c663d1.pdf
MALICIOUS — normal_5f874f0c663d1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
126d89c3515aedd13f0998c2a01914ba1f76549b51536ca2b457e13790af916c - SHA-1:
f10511d7e8be877d9dd133dc91fda07a40e71012 - MD5:
71b6d16b2f172976314c85d6a6c75fe4 - ssdeep:
768:20gGzpDzpxBaIIlG5kssq1dy5YH6OGVCtfkIcG30wnd5ZQGevPRJmZ:yGF/pr7k3q1M5+pGM/RNnmn3RJmZ - TLSH:
T11733AEF35093ED8C7B876F078DAB0498608AD38C6136966044D87B6DD87CAED7F40A60 - Submitted as: normal_5f874f0c663d1.pdf
- File type: pdf · Size: 51579 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/2bbffe28-fb52-471f-ac39-a4eaf0082285/lutamobojuz.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=english+handbook+st+andrews, https://uploads.strikinglycdn.com/files/2bbffe28-fb52-471f-ac39-a4eaf0082285/lutamobojuz.pdf, https://uploads.strikinglycdn.com/files/67d98368-ab93-46b7-8351-ac9bbeea2836/95759852376.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=english+handbook+st+andrews
- https://uploads.strikinglycdn.com/files/2bbffe28-fb52-471f-ac39-a4eaf0082285/lutamobojuz.pdf
- https://uploads.strikinglycdn.com/files/67d98368-ab93-46b7-8351-ac9bbeea2836/95759852376.pdf
- https://uploads.strikinglycdn.com/files/e4115c34-03ba-45ce-9248-41248c1d3c30/dapexafefixexota.pdf
- https://uploads.strikinglycdn.com/files/bf4923d7-c5bb-4b53-ab76-e61530205ab4/xirokorifozuwen.pdf
- https://uploads.strikinglycdn.com/files/b04b7d87-115a-467e-bb11-decdae274e56/depotumaz.pdf
- https://site-1036938.mozfiles.com/files/1036938/kovawowizixixig.pdf
- https://site-1040982.mozfiles.com/files/1040982/rarulib.pdf
- https://site-1039617.mozfiles.com/files/1039617/xilowaraguko.pdf
- https://site-1042009.mozfiles.com/files/1042009/36353427009.pdf
- https://site-1043607.mozfiles.com/files/1043607/tigofulisatapatoxa.pdf
- https://uploads.strikinglycdn.com/files/7853efed-a679-4a6d-b57a-d8bc71c9d8e5/tavuzifizatozitiba.pdf
- https://uploads.strikinglycdn.com/files/ce5c821b-abb9-4cf3-bebd-4253b2bdf373/25956520510.pdf
- https://uploads.strikinglycdn.com/files/ccff5caa-cc16-456d-b32d-0a9d0ad4ef02/dolusawuzumora.pdf
- https://uploads.strikinglycdn.com/files/8e93efd7-0308-4363-8617-cbd911bfe1ef/xutigoramasurazuwitirag.pdf
- https://site-1041934.mozfiles.com/files/1041934/46984564836.pdf
- https://site-1041381.mozfiles.com/files/1041381/52751751640.pdf
- https://site-1042199.mozfiles.com/files/1042199/zomafagafoboniwonotawilu.pdf
- https://site-1040215.mozfiles.com/files/1040215/87178189516.pdf
- https://site-1036733.mozfiles.com/files/1036733/vemufaligosa.pdf
- https://site-1038925.mozfiles.com/files/1038925/wabuvedinavek.pdf
- https://site-1042684.mozfiles.com/files/1042684/2040522875.pdf
- https://site-1041785.mozfiles.com/files/1041785/48123157993.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036938.mozfiles.com
- site-1040982.mozfiles.com
- site-1039617.mozfiles.com
- site-1042009.mozfiles.com
- site-1043607.mozfiles.com
- site-1041934.mozfiles.com
- site-1041381.mozfiles.com
- site-1042199.mozfiles.com
- site-1040215.mozfiles.com
- site-1036733.mozfiles.com
- site-1038925.mozfiles.com
- site-1042684.mozfiles.com
- site-1041785.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report