MALICIOUS — normal_5f8c5b1f423f1.pdf
MALICIOUS — normal_5f8c5b1f423f1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2f95db25b122f982e0e32adaf5ceed484eeac692fb44dc6ef3759749b3145f9d - SHA-1:
e0d07c2019086ae6df64468acb610149b2d395b8 - MD5:
c73358060cb19f2686144fd2e21a1ca8 - ssdeep:
768:XgGzpDKe0YQ3bOAqYSHfRf2Vov7S6uz9jizB1xr20epCTogwiq2OqG5942:wGFGegVoTS6mQzPxa0ec7VROqG5942 - TLSH:
T1DD339DF31093EC4C3ACBAF436DAB1499615AD3896122979098C9BB6CC47C6FC3F00A55 - Submitted as: normal_5f8c5b1f423f1.pdf
- File type: pdf · Size: 50524 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.cc/123?keyword=tupperware+catalogue+november+2020+pdf, https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf, https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/0238ed3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=tupperware+catalogue+november+2020+pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/0238ed3.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/dagowokujifemonul.pdf
- https://vabeliguteziji.weebly.com/uploads/1/3/1/3/131379360/fedodanotiko_kesokozerekiwuv_gozobaruz.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/18ad995.pdf
- https://cdn-cms.f-static.net/uploads/4366401/normal_5f8727a1cdf53.pdf
- https://cdn-cms.f-static.net/uploads/4374703/normal_5f8b7a9538800.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f87330c696ce.pdf
- https://cdn-cms.f-static.net/uploads/4370080/normal_5f8b495427e3f.pdf
- https://cdn-cms.f-static.net/uploads/4368975/normal_5f8ac17e55eea.pdf
- https://cdn-cms.f-static.net/uploads/4366660/normal_5f877f0f2dcce.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f86fa4a99ab8.pdf
- https://cdn-cms.f-static.net/uploads/4366654/normal_5f8a63fed28b6.pdf
- https://cdn-cms.f-static.net/uploads/4378599/normal_5f8bf81f065d3.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f871508e9b7c.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f8776d43fef2.pdf
- https://uploads.strikinglycdn.com/files/4052f128-f3e2-44d0-ad71-0577836fc1ee/malapovoba.pdf
- https://uploads.strikinglycdn.com/files/069e46ee-ad5c-48f9-b944-ce90cf60b8a0/xavesowupavuwakiwosiwi.pdf
- https://uploads.strikinglycdn.com/files/574597a9-d3de-4e2b-b1ac-621442427e8b/3570347594.pdf
- https://uploads.strikinglycdn.com/files/0cf73bc2-4957-40e6-a523-b2bfb4b39e43/budufekafe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ttraff.cc
- dutitujazekap.weebly.com
- xawuwotogot.weebly.com
- jamuseramomuf.weebly.com
- vabeliguteziji.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report