MALICIOUS — normal_5f88304ec3d47.pdf
MALICIOUS — normal_5f88304ec3d47.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
45f2af555f73cc02ae362cdf3534632b6e2cc4ec3d584c429be7a698b9926558 - SHA-1:
bb627718b0f4940ee37a28d24ec08c514ca4aa4b - MD5:
d1a86277a08464fbb2c296098b73f749 - ssdeep:
768:FgGzpDhpj6ng/k5IrSxTl4R3LpewGb427IlokkRWXN2R9PYxgmfKUkKVW2VdTHfq:WGFVpeRspeh5E44sXQgmfk2jFE - TLSH:
T19234BFF3509BEC4C7ACBAF17BDB71264504ACB48A136A7A055C93A2DC4BC4BD6F50821 - Submitted as: normal_5f88304ec3d47.pdf
- File type: pdf · Size: 53215 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/46de12a6-788d-40ed-93b8-f7c99aef167d/lipewoguw.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=double+cross+book+pdf, https://uploads.strikinglycdn.com/files/0eb59e66-6064-4401-ae17-7f3ab515e662/bajuzedopa.pdf, https://uploads.strikinglycdn.com/files/46de12a6-788d-40ed-93b8-f7c99aef167d/lipewoguw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=double+cross+book+pdf
- https://uploads.strikinglycdn.com/files/0eb59e66-6064-4401-ae17-7f3ab515e662/bajuzedopa.pdf
- https://uploads.strikinglycdn.com/files/46de12a6-788d-40ed-93b8-f7c99aef167d/lipewoguw.pdf
- https://uploads.strikinglycdn.com/files/18511f9b-f487-4df7-931a-bbb192b36bb7/38997885708.pdf
- https://uploads.strikinglycdn.com/files/95df29e2-f135-4586-b0d7-dbd29d9dac9b/32957113866.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f87f754b5746.pdf
- https://cdn-cms.f-static.net/uploads/4369150/normal_5f87c59b9472e.pdf
- https://cdn-cms.f-static.net/uploads/4366633/normal_5f873343d70f0.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f8752f77fc8c.pdf
- https://cdn-cms.f-static.net/uploads/4367951/normal_5f8754e992ef2.pdf
- https://cdn-cms.f-static.net/uploads/4367278/normal_5f8828fe649f9.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f87ae6709ada.pdf
- https://uploads.strikinglycdn.com/files/18f127c2-d9d3-458a-b7bd-4cc5df13e94a/xovizudutim.pdf
- https://uploads.strikinglycdn.com/files/2dc04998-fdc1-4598-8b04-9581d290281f/42145705925.pdf
- https://bibeliki.weebly.com/uploads/1/3/0/7/130738572/paxuvudonarisa-kewaviludoseja-mowolifofubem-noxuv.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/rotizizalipi-xulejowo-wegevok-xutijub.pdf
- https://site-1043292.mozfiles.com/files/1043292/roramalor.pdf
- https://site-1037009.mozfiles.com/files/1037009/69831948193.pdf
- https://site-1040322.mozfiles.com/files/1040322/mafupadalujenijolo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- bibeliki.weebly.com
- fijojonibiw.weebly.com
- site-1043292.mozfiles.com
- site-1037009.mozfiles.com
- site-1040322.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report