MALICIOUS — normal_5f870a04da2cf.pdf
MALICIOUS — normal_5f870a04da2cf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
13d5313b2a54b02daca4eb1c2c8ba6cf2d58202e4e801868ee7a3510430f2fcb - SHA-1:
2eaa5e1b72f7800414791d34ed99907127373d57 - MD5:
e0c09463ce72ccb2f3f6e6634eae2579 - ssdeep:
768:3gGzpDYph4xfvrWi4NLOaRWzhjfi6VFtx4x0xRpz0GH4SGuQ+Db68bRbRI:QGFMphnRWVjfbXh9z3H4/uQ+imI - TLSH:
T13C317CF740EBED4C7E87AB039DB72569158EC30971369760549C772C88BC6BDAE408A0 - Submitted as: normal_5f870a04da2cf.pdf
- File type: pdf · Size: 40635 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xizaxamuxive.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=solutions+a2+student%2527s+book+pdf, https://uploads.strikinglycdn.com/files/c49b8420-175b-4084-896c-132fef774940/46443152359.pdf, https://uploads.strikinglycdn.com/files/62e50d6b-e975-4286-8212-fc0eb42c9f30/fofafofofuri.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=solutions+a2+student%2527s+book+pdf
- https://uploads.strikinglycdn.com/files/c49b8420-175b-4084-896c-132fef774940/46443152359.pdf
- https://uploads.strikinglycdn.com/files/62e50d6b-e975-4286-8212-fc0eb42c9f30/fofafofofuri.pdf
- https://uploads.strikinglycdn.com/files/32a14d30-2c3e-47a4-bb08-7133ecfe2267/fimef.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xizaxamuxive.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7304884.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/wovexofek.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/a63fb.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f86f98f44d33.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f86f783f14ee.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_5f87070170a48.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f86f60df3aca.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f870993d2570.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f870988e204b.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f8708dee87aa.pdf
- https://uploads.strikinglycdn.com/files/1296af03-e648-4de8-9eee-cba5963254c9/vunexabivunev.pdf
- https://uploads.strikinglycdn.com/files/238a4480-5dad-402b-87b8-3d603fa65c4c/vavaxerimativesuduniwiwid.pdf
- https://uploads.strikinglycdn.com/files/ff887d68-6fea-4787-9e38-4767b748c64e/lenovufujos.pdf
- https://uploads.strikinglycdn.com/files/2aa31553-fc71-40be-9668-56834ad7a665/45736174904.pdf
- https://uploads.strikinglycdn.com/files/c7a48f08-38dc-4393-b948-29794649ed0f/litazebi.pdf
- https://uploads.strikinglycdn.com/files/88195a3d-7d9d-4a72-a6fe-0c2224c5da19/zimuxuvugexitenanulej.pdf
- https://uploads.strikinglycdn.com/files/050edf9c-7112-4ab6-a128-10845924c50e/49390619758.pdf
- https://uploads.strikinglycdn.com/files/1fd30309-e2c4-4af6-aced-fc5e8a99668b/kukemasetokezukel.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- dutitujazekap.weebly.com
- genigudepa.weebly.com
- jawasolasazilem.weebly.com
- jatorogerujew.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report