MALICIOUS — normal_5f885f4226d64.pdf
MALICIOUS — normal_5f885f4226d64.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6328122c7a0d8ea50b545449952cf3609268200c9e3b0274b0ab51eb79873ebd - SHA-1:
2b565a840686b4631a3442c521d10c8939205c3e - MD5:
96482e43418774fa4a86fb9e5a9373e9 - ssdeep:
768:e4gGzpDgpsUYfnv1aZUg8ySId1lgEkcclYgiVSvn++kY:eVGFkpYMfWIaE9clRiMn+5Y - TLSH:
T198308EF754DBED4CAA879B83ADE62559218A838D7236876015DC336CC4BC2BD7F00960 - Submitted as: normal_5f885f4226d64.pdf
- File type: pdf · Size: 38890 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/8c3f11ed.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=graad+4+wiskunde+oefeninge+pdf, https://rozolabo.weebly.com/uploads/1/3/0/8/130814594/xutixi_sozamoxi_savuzatu.pdf, https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/8c3f11ed.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=graad+4+wiskunde+oefeninge+pdf
- https://rozolabo.weebly.com/uploads/1/3/0/8/130814594/xutixi_sozamoxi_savuzatu.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/8c3f11ed.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/5acab582ad41.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/lukuxaluk.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/sokilijaw.pdf
- https://site-1038503.mozfiles.com/files/1038503/resoraninuba.pdf
- https://site-1042510.mozfiles.com/files/1042510/70479409094.pdf
- https://site-1041405.mozfiles.com/files/1041405/zipawisaseleb.pdf
- https://uploads.strikinglycdn.com/files/f9db13b3-bbd0-471a-9896-c6d20142df64/gujexexo.pdf
- https://uploads.strikinglycdn.com/files/1c7f0905-4d5d-4ee2-aaa3-0b2535f57e29/61226998803.pdf
- https://uploads.strikinglycdn.com/files/67bc64ed-7f16-42d2-91e8-e04b9c42ba61/49425507613.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/xelikanotuzifaja.pdf
- https://bajusumuke.weebly.com/uploads/1/3/2/7/132741128/ac1ec53d6.pdf
- https://lixaworone.weebly.com/uploads/1/3/1/8/131871871/wakubaxux.pdf
- https://uploads.strikinglycdn.com/files/f3d213e5-c27f-4540-a93a-6394b72ef7c2/60899369373.pdf
- https://uploads.strikinglycdn.com/files/7d126015-e6e3-4d4a-be98-ace3540cb12b/40801195921.pdf
- https://uploads.strikinglycdn.com/files/189f4efd-11e6-40da-a507-f8fd5df24611/82515430619.pdf
- https://uploads.strikinglycdn.com/files/6e63545a-f730-47cf-b4fa-f320eae1e1a3/rudulejorikexolubelinis.pdf
- https://cdn.shopify.com/s/files/1/0484/0371/0104/files/vugezurawuk.pdf
- https://cdn.shopify.com/s/files/1/0437/5596/2522/files/a_guide_to_the_business_analysis_body_of_knowledge_v3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- rozolabo.weebly.com
- jatorogerujew.weebly.com
- keniwuki.weebly.com
- bedizegoresupa.weebly.com
- site-1038503.mozfiles.com
- site-1042510.mozfiles.com
- site-1041405.mozfiles.com
- uploads.strikinglycdn.com
- fijojonibiw.weebly.com
- bajusumuke.weebly.com
- lixaworone.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report