MALICIOUS — normal_5f880b004f5e1.pdf
MALICIOUS — normal_5f880b004f5e1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3d6586484b7f8f3b31ca8a85887cfd5db961460c594e7965e6a386b878971bbb - SHA-1:
72cffdbe19b50bb7d402777a23796c2f6455c66b - MD5:
d08edbce406da3281c66440026ee7ea6 - ssdeep:
768:QgGzpDCpijTkg3ujoVcdRZOEixcWqR8OUCQWlLysDFYvpd+H6rfbX7qZCQ:9GFGpijYljmuz8EdJ6vptX7qZCQ - TLSH:
T177328EF764A7DD8C7E87AB136EF62568548DD348A1339B5444C8676CC4BC2AE2F00A60 - Submitted as: normal_5f880b004f5e1.pdf
- File type: pdf · Size: 46031 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://pepotoxuxomupav.weebly.com/uploads/1/3/1/4/131483830/41417.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=this+war+of+mine+mod+apk+1.5.5, https://uploads.strikinglycdn.com/files/3c9da7cf-9a5a-4a48-8b3e-0686a0b46871/23588530483.pdf, https://uploads.strikinglycdn.com/files/869bd508-718e-43c3-ae82-e1732a816276/17255489750.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=this+war+of+mine+mod+apk+1.5.5
- https://uploads.strikinglycdn.com/files/3c9da7cf-9a5a-4a48-8b3e-0686a0b46871/23588530483.pdf
- https://uploads.strikinglycdn.com/files/869bd508-718e-43c3-ae82-e1732a816276/17255489750.pdf
- https://uploads.strikinglycdn.com/files/8ca070c6-fcb5-4e84-87d0-0fa63391b49e/90281954839.pdf
- https://pepotoxuxomupav.weebly.com/uploads/1/3/1/4/131483830/41417.pdf
- https://welofubevi.weebly.com/uploads/1/3/1/8/131856084/4084745.pdf
- https://uploads.strikinglycdn.com/files/00221cdb-ca91-4db2-8603-736fd84fb22a/vutos.pdf
- https://uploads.strikinglycdn.com/files/1f0652c0-b4e0-482a-a902-2b40a6db8521/fudov.pdf
- https://uploads.strikinglycdn.com/files/33ef12db-3edf-4601-a56b-64aca0dbef42/89458772738.pdf
- https://uploads.strikinglycdn.com/files/9e16f3cb-7e66-4bbe-95b0-db6637530677/30743372029.pdf
- https://uploads.strikinglycdn.com/files/bb2ca7a7-6771-483f-917b-0b93a5de7946/wibuzagirizatis.pdf
- https://uploads.strikinglycdn.com/files/947d5642-68eb-4f93-8d2b-a1d105a33e2a/zakujifozupolimotinif.pdf
- https://uploads.strikinglycdn.com/files/38d83940-90bd-40c6-a328-033fa7f9e560/67166963582.pdf
- https://uploads.strikinglycdn.com/files/688f69dc-eede-4921-830f-3a2e4feb32b8/71010548989.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f87cc6371338.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f870bb001107.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f87440ac8ba9.pdf
- https://cdn-cms.f-static.net/uploads/4366660/normal_5f878ae9e40cc.pdf
- https://cdn-cms.f-static.net/uploads/4367290/normal_5f879c993bbe7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- pepotoxuxomupav.weebly.com
- welofubevi.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report