MALICIOUS — normal_5f8715c2db4d8.pdf
MALICIOUS — normal_5f8715c2db4d8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1c7ba793fc278972af75467fd6c09c2e426cafe04edf42530ec2507c77817233 - SHA-1:
920930711efea776a4536705f2c2d2ff9fe05c76 - MD5:
f080137646986932cd920114ac4ba1d5 - ssdeep:
1536:uGF/pXY4ZnjrIfph0CQ57UblWuYSSNFoeqQd:XF/ptophLQ57UbXYSSvoeb - TLSH:
T14C339EF3449BED4C7A829B076ABB2969648AD7483133D7A05488772CC4BC67DAF00D70 - Submitted as: normal_5f8715c2db4d8.pdf
- File type: pdf · Size: 50464 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/9232432.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=thermogravimetric+analysis+nptel+pdf, https://uploads.strikinglycdn.com/files/61af9243-b479-474a-ac85-5dc61d595dee/kimafiwerolero.pdf, https://uploads.strikinglycdn.com/files/9ac95a3d-991d-4124-9538-871b9c6c1763/13757782537.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=thermogravimetric+analysis+nptel+pdf
- https://uploads.strikinglycdn.com/files/61af9243-b479-474a-ac85-5dc61d595dee/kimafiwerolero.pdf
- https://uploads.strikinglycdn.com/files/9ac95a3d-991d-4124-9538-871b9c6c1763/13757782537.pdf
- https://uploads.strikinglycdn.com/files/3cce9f67-8da0-475b-bf9c-af994c64875d/72232902279.pdf
- https://uploads.strikinglycdn.com/files/1a811cc1-67b8-40d0-b201-45dff908e2b4/gebanalotetiviras.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f8703ddbaaf3.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/9232432.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/roriturosiw.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f870d801b7df.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f8704ba7ffb7.pdf
- https://cdn-cms.f-static.net/uploads/4365636/normal_5f86f4cca4cb4.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f86f55811991.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f87136c660c6.pdf
- https://uploads.strikinglycdn.com/files/c1907ecc-cbf7-4c69-8598-eb6bd1daad89/xadosikiwuxuvi.pdf
- https://uploads.strikinglycdn.com/files/1cecd9ac-449b-4948-8b04-50f0cc5f6573/27965711718.pdf
- https://uploads.strikinglycdn.com/files/fd78765a-29da-49c3-88f5-672d438a819b/vokatonedagisojupetag.pdf
- https://uploads.strikinglycdn.com/files/b81a94fa-ed12-479d-b9f5-48e43d86f320/pexifiledesapulererebigap.pdf
- https://uploads.strikinglycdn.com/files/ce5db714-8fdc-4541-9489-fc8905029769/48162510270.pdf
- https://site-1036826.mozfiles.com/files/1036826/terimalemo.pdf
- https://site-1039807.mozfiles.com/files/1039807/97383196573.pdf
- https://site-1036828.mozfiles.com/files/1036828/81242322066.pdf
- https://site-1036894.mozfiles.com/files/1036894/lenojuvegajavawimelijo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- jawasolasazilem.weebly.com
- gimejexoxixaza.weebly.com
- site-1036826.mozfiles.com
- site-1039807.mozfiles.com
- site-1036828.mozfiles.com
- site-1036894.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report