MALICIOUS — normal_5f872d43ef121.pdf
MALICIOUS — normal_5f872d43ef121.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5d71918b66925f065f59f33bc8aab4e2c314d9577ad06a91fc954683ac63004d - SHA-1:
85fe43c993ffb862d9f5e4c07c23fe1d71ce3a1e - MD5:
fd7cf3899413df43cd2038584c156459 - ssdeep:
768:YgGzpDxpgwj0nUSMTCOCwIPcRPStmaBmQX5iQG2OkbqsQ1hPh0AA:1GFVp+PcxOx+QGYaH0AA - TLSH:
T12E327CF310A7DD4CBE8AAB435DAB0565508EC34D6236A79081CC772CD4BC9BE7E11960 - Submitted as: normal_5f872d43ef121.pdf
- File type: pdf · Size: 43358 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/jatelu-zukolugaw.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=converting+pdf+to+word+foxit, https://site-1048449.mozfiles.com/files/1048449/lukojitugavikazafezikis.pdf, https://site-1039797.mozfiles.com/files/1039797/7901417285.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=converting+pdf+to+word+foxit
- https://site-1048449.mozfiles.com/files/1048449/lukojitugavikazafezikis.pdf
- https://site-1039797.mozfiles.com/files/1039797/7901417285.pdf
- https://site-1042510.mozfiles.com/files/1042510/vekibugubebeliv.pdf
- https://site-1044029.mozfiles.com/files/1044029/vizevutewugoxejox.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/d16d0b.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/jatelu-zukolugaw.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/69c6fb656594.pdf
- https://uploads.strikinglycdn.com/files/a901cea6-4860-471e-ab59-f8f34197d505/35562787.pdf
- https://uploads.strikinglycdn.com/files/40b2506e-c6ed-417f-aaca-a023c3c573db/lalemedosuzajaviriku.pdf
- https://uploads.strikinglycdn.com/files/7cdc2dde-9c70-4e8f-af88-2ef6fccad56f/muzibologew.pdf
- https://uploads.strikinglycdn.com/files/ad6bfcb1-c422-49b5-9dfe-31a30c7751cd/93140226770.pdf
- https://cdn-cms.f-static.net/uploads/4366620/normal_5f872ba898db4.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f872b59bdc77.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f8726c35a7a5.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f87101572337.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f86f8737db67.pdf
- https://uploads.strikinglycdn.com/files/67772e36-d8d4-4cf5-a3e9-040d490d0a40/83311288717.pdf
- https://uploads.strikinglycdn.com/files/fa2a8ef4-8b99-4546-a7a7-ece7f7366821/10075406941.pdf
- https://uploads.strikinglycdn.com/files/f3b5faf4-de7b-40ec-b495-b484abf07e29/fuzetomi.pdf
- https://uploads.strikinglycdn.com/files/1c7884aa-30ff-4469-ae5b-31c0b4cb3a45/4214193545.pdf
- https://uploads.strikinglycdn.com/files/d4b623f3-ddc0-4c43-bdb3-b2b0b7d055d1/28889964148.pdf
- https://uploads.strikinglycdn.com/files/48a28c38-49cc-4427-bcec-2b3c954ae469/tifitojukigesedexoromuxik.pdf
- https://uploads.strikinglycdn.com/files/e42c2be9-d82d-4851-9396-9af3fcc644a4/veviliral.pdf
- https://uploads.strikinglycdn.com/files/10303ccb-3723-48dd-810a-b4a6962eb2e5/6881108730.pdf
Embedded domains
- gettraff.ru
- site-1048449.mozfiles.com
- site-1039797.mozfiles.com
- site-1042510.mozfiles.com
- site-1044029.mozfiles.com
- jufaxexave.weebly.com
- vuxozajuje.weebly.com
- jaserasozupog.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report