MALICIOUS — normal_5f993b6c3f255.pdf
MALICIOUS — normal_5f993b6c3f255.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4b764163916ab76d9fe04e130715810250a4f5845e2a43d5fa2ae0e426626602 - SHA-1:
d67815d946ff047f1def468a1daf7fb821aec263 - MD5:
cfb3601e02b1e6bebed68fe188623da1 - ssdeep:
768:WgGzpDcpySCziB+5j5EmH/EJDDBSMv/mNchgCF25Dq5r99fOc:DGFQpyP+I5jAS2/q8gCF2pq5mc - TLSH:
T1A9317DF750E7EC4C368EAF13ADA71159A14AD748613697A0488C773CC4BCAFE2E00A51 - Submitted as: normal_5f993b6c3f255.pdf
- File type: pdf · Size: 40406 bytes
- Verdict: malicious (71/100)
Detections (2 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://lowizozexide.weebly.com/uploads/1/3/0/7/130776176/juwol.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=tuck+everlasting+test+answers, https://nujidigazinuwag.weebly.com/uploads/1/3/4/3/134318548/ditetadexukesi.pdf, https://fukobararusi.weebly.com/uploads/1/3/4/4/134404541/caa9823e308d9c0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=tuck+everlasting+test+answers
- https://nujidigazinuwag.weebly.com/uploads/1/3/4/3/134318548/ditetadexukesi.pdf
- https://fukobararusi.weebly.com/uploads/1/3/4/4/134404541/caa9823e308d9c0.pdf
- https://lotagixowila.weebly.com/uploads/1/3/1/1/131164100/sapozokuwad.pdf
- https://wuvirinofibugiz.weebly.com/uploads/1/3/1/0/131070402/fijuxiwu.pdf
- https://uploads.strikinglycdn.com/files/a08f4aaf-6cd6-4fa3-9c27-8435d1c42be2/varianza_de_una_variable_aleatoria_e.pdf
- https://uploads.strikinglycdn.com/files/58dce84b-18e0-4de4-9ca9-4017490c59ea/14799885529.pdf
- https://uploads.strikinglycdn.com/files/d220b00a-e33f-41a8-8937-86c49dc67a98/sozaduri.pdf
- https://lowizozexide.weebly.com/uploads/1/3/0/7/130776176/juwol.pdf
- https://lusekovipe.weebly.com/uploads/1/3/4/2/134234723/7913219.pdf
- https://zozilevijuni.weebly.com/uploads/1/3/1/3/131383476/75649d18fa.pdf
- https://pelixenebedevo.weebly.com/uploads/1/3/4/3/134338689/1883880.pdf
- https://juregirezixo.weebly.com/uploads/1/3/4/4/134401856/5819919.pdf
- https://uploads.strikinglycdn.com/files/863547e8-456c-415c-b469-9fc5636bdf5c/81161202796.pdf
- https://uploads.strikinglycdn.com/files/8332d0f6-7712-4eb3-a109-21c2b875dc98/vipajofepewur.pdf
- https://uploads.strikinglycdn.com/files/62d2ab0a-b26a-42cd-9686-c58c63f210a2/mexarip.pdf
- https://uploads.strikinglycdn.com/files/b3846a8e-e10c-4bf5-9571-f633e195119a/koxaruxujag.pdf
- https://uploads.strikinglycdn.com/files/b1e41d16-1376-4bb0-91a9-a4be70028074/duvejegigiwirifepak.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f8c27625dfec.pdf
- https://cdn-cms.f-static.net/uploads/4367665/normal_5f87b10796b35.pdf
- https://cdn-cms.f-static.net/uploads/4386618/normal_5f8d397f0f4a3.pdf
- https://cdn-cms.f-static.net/uploads/4386606/normal_5f8e973c0fcf4.pdf
- https://cdn-cms.f-static.net/uploads/4368485/normal_5f87fcf24dd81.pdf
- https://cdn-cms.f-static.net/uploads/4376120/normal_5f94de14c3f75.pdf
- https://cdn-cms.f-static.net/uploads/4375698/normal_5f8a15b573519.pdf
Embedded domains
- cctraff.ru
- nujidigazinuwag.weebly.com
- fukobararusi.weebly.com
- lotagixowila.weebly.com
- wuvirinofibugiz.weebly.com
- uploads.strikinglycdn.com
- lowizozexide.weebly.com
- lusekovipe.weebly.com
- zozilevijuni.weebly.com
- pelixenebedevo.weebly.com
- juregirezixo.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report