MALICIOUS — normal_5f8f8e3eb5863.pdf
MALICIOUS — normal_5f8f8e3eb5863.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
56f6a7e7e3f6441ec0ea3a14aabcb67cbddb1892f15f64c5c91f01baf85d4cb4 - SHA-1:
7a965ec5b5ea3b17929aec01b9f1a694ab98ccc7 - MD5:
c53c229b640a9b97799fe0afffdac133 - ssdeep:
1536:HGFPpMqHSCkR8cXE7ZCPCDXkBg5hBc/hoWU/6EYboIyjSx:mFPpMGRtcU1eCDvBco//6EYNyg - TLSH:
T12137BFF30497DE4CB7C69703EEB611AA2289C789B136A76015C9BA6CD0FC5BD3E00561 - Submitted as: normal_5f8f8e3eb5863.pdf
- File type: pdf · Size: 75909 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/bupemigimamuvap.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.com/123?keyword=mpls+configuration+commands+pdf, https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/bibesekukemugedovofa.pdf, https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/bupemigimamuvap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=mpls+configuration+commands+pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/bibesekukemugedovofa.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/bupemigimamuvap.pdf
- https://wipomozexabezi.weebly.com/uploads/1/3/0/7/130776841/bufagutaxu.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/murufotusinofuw.pdf
- https://wuvirinofibugiz.weebly.com/uploads/1/3/1/0/131070402/986ca1.pdf
- https://uploads.strikinglycdn.com/files/7dbb6a35-b194-4b71-bebb-1255f8c112b1/favufanavuzepeb.pdf
- https://uploads.strikinglycdn.com/files/64b61f16-b868-4385-b469-556902be7bc8/16638534972.pdf
- https://uploads.strikinglycdn.com/files/71b4da0a-3573-4515-8f01-645a87f1b85c/nadanaruw.pdf
- https://cdn.shopify.com/s/files/1/0483/7428/4446/files/51081511160.pdf
- https://cdn.shopify.com/s/files/1/0484/3097/3080/files/suxelerusuwujijovedusub.pdf
- https://cdn.shopify.com/s/files/1/0491/9364/8294/files/kansas_city_massacre_1975.pdf
- https://uploads.strikinglycdn.com/files/7bb6017d-d1b4-4382-91d1-896fd4b7c536/10415253326.pdf
- https://uploads.strikinglycdn.com/files/725ca07d-bb08-4f1a-b301-5798e4d78f7e/jononobojebezikimimi.pdf
- https://uploads.strikinglycdn.com/files/2222962e-6474-48e9-92e0-1a8cc17d6bbf/38218294709.pdf
- https://uploads.strikinglycdn.com/files/eda8a311-794d-4508-b4a5-c2fae6116b30/tigizavamuxojirexibesun.pdf
- https://uploads.strikinglycdn.com/files/925c0474-a3bc-4dbf-b2c9-5a27c26652ec/44010446966.pdf
- https://uploads.strikinglycdn.com/files/9cc8c550-423f-4e6c-8758-27895af46e23/suzowa.pdf
- https://laxuruvu.weebly.com/uploads/1/3/1/4/131482832/jirejuxez.pdf
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/buveg-fugiluza-dojitonugaj-goweg.pdf
- https://xalipifizipig.weebly.com/uploads/1/3/1/3/131379045/pomukeji.pdf
- https://jowodetuleguzu.weebly.com/uploads/1/3/1/8/131856173/12a5685dc.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.com
- jemiwuwavaza.weebly.com
- fijojonibiw.weebly.com
- wipomozexabezi.weebly.com
- saxibodusazo.weebly.com
- wuvirinofibugiz.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- laxuruvu.weebly.com
- bizumoku.weebly.com
- xalipifizipig.weebly.com
- jowodetuleguzu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report