MALICIOUS — normal_5f8a041fd88e4.pdf
MALICIOUS — normal_5f8a041fd88e4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2c46da8bab7ce517b07f731777661ed7246645125d198075a8f56e3a3b30e798 - SHA-1:
852771229d3b13bfb64cc33d5e6e1127e6f4c9cf - MD5:
1a85cbb924b9f618327f445dfdbdb696 - ssdeep:
768:/ygGzpDOpQTLYJ+PC5ZPaOiLpfcqQj8Cqd+JMquKJX8PEu5t2wAUS8slMEOZVg+K:3GFapQHLpRQj8CvpKPcwAN3pO04RsWI - TLSH:
T10B32AEF34097ED4C7A469B03ADBA256A518AD74C7267E7A0489C332CC47C5BDBF109A0 - Submitted as: normal_5f8a041fd88e4.pdf
- File type: pdf · Size: 44902 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/vuvimow.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.ru/123?keyword=come+installare+whatsapp+web+su+android, https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/vuvimow.pdf, https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/6615122.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=come+installare+whatsapp+web+su+android
- https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/vuvimow.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/6615122.pdf
- https://suludizivot.weebly.com/uploads/1/3/1/3/131383823/91242.pdf
- https://buximinolid.weebly.com/uploads/1/3/1/3/131381316/18e0ed4bb75e5.pdf
- https://ziperivowupidu.weebly.com/uploads/1/3/1/3/131381589/temijege_korexodix.pdf
- https://uploads.strikinglycdn.com/files/96a5c473-588d-4c54-955e-1479674d3758/96909426621.pdf
- https://cdn.shopify.com/s/files/1/0501/6810/3077/files/mk470_tile_saw_specs.pdf
- https://cdn.shopify.com/s/files/1/0429/5580/0739/files/48927520037.pdf
- https://cdn.shopify.com/s/files/1/0497/1560/9761/files/to_kill_a_mockingbird_play_tickets_london.pdf
- https://cdn.shopify.com/s/files/1/0441/3099/2280/files/keginubikena.pdf
- https://uploads.strikinglycdn.com/files/7584bd7f-dfd6-4500-a6b9-06b843bf4cb7/pulerakuvemo.pdf
- https://uploads.strikinglycdn.com/files/1f1579a6-4a57-4895-89e2-7bd89b105b7a/9073088093.pdf
- https://uploads.strikinglycdn.com/files/df509e2d-34f1-4704-b451-0f1941367b9c/jisewojowisik.pdf
- https://uploads.strikinglycdn.com/files/c5b5f646-6b30-42e4-9bce-b8bfaafcfd3a/gurap.pdf
- https://uploads.strikinglycdn.com/files/4ae0600f-c02f-41d3-978c-1f152d6a1758/jazug.pdf
- https://uploads.strikinglycdn.com/files/7e992d41-8a3f-4c8c-9291-37cf6471d0b8/muxozivevajej.pdf
- https://uploads.strikinglycdn.com/files/a504a89b-e0f6-43e6-8bf7-60a64f7e71b6/50528520778.pdf
- https://cdn.shopify.com/s/files/1/0482/3331/6514/files/como_convertir_archivos_a_fotos.pdf
- https://cdn.shopify.com/s/files/1/0438/3437/6352/files/cape_fear_river_adventures.pdf
- https://cdn.shopify.com/s/files/1/0440/8098/8310/files/ytx20l-bs_battery_cross_reference.pdf
- https://cdn.shopify.com/s/files/1/0485/2062/6331/files/tiger_woods_mother_and_father.pdf
- https://cdn.shopify.com/s/files/1/0479/6556/9180/files/xewuvolumiripozasofa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.ru
- kupugaxome.weebly.com
- jawowigo.weebly.com
- suludizivot.weebly.com
- buximinolid.weebly.com
- ziperivowupidu.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report