MALICIOUS — normal_5ffce1bbd833f.pdf
MALICIOUS — normal_5ffce1bbd833f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
21051bb4d585841cc52705658cec66b38d549a8ca048cf553ab1239dd96fa90e - SHA-1:
05da2efe2fc17b3c5ac7412610c389bde25f9549 - MD5:
d15fbbdd61b1c0c8638c86dc1a3c6019 - ssdeep:
1536:f36u4BBI2nQDQH9DG6xNJxDVm3LPRV/23765wV09AtXY:Px45QDA9DNH03LrM6OV09Au - TLSH:
T14937E1F31017EDCCFBC58B2329E61624A459D6DC71329B815488BB2CD8386FE2F12942 - Submitted as: normal_5ffce1bbd833f.pdf
- File type: pdf · Size: 69952 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D15FBBDD61B1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4416321/normal_5ff515208cb33.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?utm_term=annie+fisher+stem+school+hartford+ct, https://jagojepenita.weebly.com/uploads/1/3/0/7/130739472/tunilalinesib-tamuvaxepom-wapinaxoxasuki.pdf, https://kubuvapag.weebly.com/uploads/1/3/0/7/130776206/divilewilugitulurim.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?utm_term=annie+fisher+stem+school+hartford+ct
- https://jagojepenita.weebly.com/uploads/1/3/0/7/130739472/tunilalinesib-tamuvaxepom-wapinaxoxasuki.pdf
- https://kubuvapag.weebly.com/uploads/1/3/0/7/130776206/divilewilugitulurim.pdf
- https://site-1168056.mozfiles.com/files/1168056/best_outliner_clippers.pdf
- https://site-1172896.mozfiles.com/files/1172896/music_inception_piano.pdf
- https://site-1167973.mozfiles.com/files/1167973/xtreme_jet_boat_porto_preco.pdf
- https://cdn-cms.f-static.net/uploads/4457311/normal_5fdba6110fc90.pdf
- https://kijilijesudopob.weebly.com/uploads/1/3/0/7/130739968/wonexubidafemop.pdf
- https://static.s123-cdn-static.com/uploads/4416321/normal_5ff515208cb33.pdf
- https://cdn-cms.f-static.net/uploads/4409992/normal_5fe81e0daaac4.pdf
- https://cdn-cms.f-static.net/uploads/4411937/normal_5fdc2b1b84a63.pdf
- https://vepimogarib.weebly.com/uploads/1/3/4/8/134856589/bogekuju.pdf
- https://static.s123-cdn-static.com/uploads/4370762/normal_5fcbf30c59867.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- jagojepenita.weebly.com
- kubuvapag.weebly.com
- site-1168056.mozfiles.com
- site-1172896.mozfiles.com
- site-1167973.mozfiles.com
- cdn-cms.f-static.net
- kijilijesudopob.weebly.com
- static.s123-cdn-static.com
- vepimogarib.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report