MALICIOUS — normal_5f9010ff5dc80.pdf
MALICIOUS — normal_5f9010ff5dc80.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
21f9126516eb84fb4a415a14d2bdb23e5078a04921771d092311b295d784e70a - SHA-1:
b5f219d712e4e2dce5a97ed87b78eff26a965678 - MD5:
ae2f7376f2b1900dff82ab023e28d99a - ssdeep:
768:tgGzpDMpYX93Bk6cau1crTB5lkjtaoUGs6ZI++s7vKPgnh:OGF4p8k6q1cvBEJaoUWZI++dPgnh - TLSH:
T1CB329DF31093ED9C778E9B479FBA114D608AE788623B9660509C3A2DC47C6ED7E40660 - Submitted as: normal_5f9010ff5dc80.pdf
- File type: pdf · Size: 45445 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/93832134-dcec-4d56-ad53-65929c07611b/levinawisadedalo.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=bleach+mugen+apk+download, https://cdn.shopify.com/s/files/1/0500/7350/1884/files/american_tradition_in_literature_12th_edition.pdf, https://uploads.strikinglycdn.com/files/3e709d28-0f5d-4377-a3a4-d64bb5bf11d9/57351246937.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=bleach+mugen+apk+download
- https://s3.amazonaws.com/wonoti/tafubo.pdf
- https://s3.amazonaws.com/leguvefu/pojawide.pdf
- https://s3.amazonaws.com/wilugugo/jenatuzonizatazavadefaw.pdf
- https://s3.amazonaws.com/gupuso/gagugu.pdf
- https://s3.amazonaws.com/leguvefu/amar_chitra_katha_comics_free_download.pdf
- https://cdn.shopify.com/s/files/1/0500/7350/1884/files/american_tradition_in_literature_12th_edition.pdf
- https://s3.amazonaws.com/zirojopemup/bataille_de_verdun_rsum.pdf
- https://s3.amazonaws.com/gupuso/display_system_and_anthropometric_data.pdf
- https://uploads.strikinglycdn.com/files/3e709d28-0f5d-4377-a3a4-d64bb5bf11d9/57351246937.pdf
- https://uploads.strikinglycdn.com/files/0c9edb87-6c14-4ab1-8da4-708a96fdb17d/lubedunanirazegabu.pdf
- https://uploads.strikinglycdn.com/files/08fb9137-6005-42c8-9894-cd3cbf9937fa/27575355253.pdf
- https://uploads.strikinglycdn.com/files/51237d26-896b-4280-9fab-1ed4c488d99d/bisovixajibuxibif.pdf
- https://uploads.strikinglycdn.com/files/c379b548-8b1a-4f4a-b5e9-72fa3195105f/68492778517.pdf
- https://masogipu.weebly.com/uploads/1/3/1/6/131606875/263e5989.pdf
- https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/rexobevumalob.pdf
- https://zilavexeredora.weebly.com/uploads/1/3/0/8/130874610/selinimafimigoto.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/8742796.pdf
- https://uploads.strikinglycdn.com/files/93832134-dcec-4d56-ad53-65929c07611b/levinawisadedalo.pdf
- https://uploads.strikinglycdn.com/files/7e2d3425-6701-4b2b-970f-134d92bb12dc/kemekosurisiku.pdf
- https://uploads.strikinglycdn.com/files/d9d260a3-69c4-483b-af95-b0a89a0022ba/23513184554.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- masogipu.weebly.com
- damijuvik.weebly.com
- zilavexeredora.weebly.com
- mogilifus.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report