MALICIOUS — normal_5f943250e8f8b.pdf
MALICIOUS — normal_5f943250e8f8b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
64f06e3b4afc59b5dcce64de5dc56cd6d9b195b8372a65d5d97ee1142ac4320a - SHA-1:
30db4082cef9f43e0025cf0c670578884f270ab8 - MD5:
13fdb0aff627c24f74979264353af89a - ssdeep:
1536:RGFj3IJUn3ZmEE46A7ZQzNZF9ygaj29YC:0Fj3Tn3ZSBwZYl9y5j2v - TLSH:
T14D35AEF360DBED0C7A8767239DB7156895CAC288A236E79080CC772CE47C9BE6D10951 - Submitted as: normal_5f943250e8f8b.pdf
- File type: pdf · Size: 57809 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/jatelu-zukolugaw.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.club/123?keyword=ios+vs+android+development, https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/jatelu-zukolugaw.pdf, https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/serowo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=ios+vs+android+development
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/jatelu-zukolugaw.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/serowo.pdf
- https://tubenuluni.weebly.com/uploads/1/3/1/4/131437864/8191cbea7.pdf
- https://kekerisasil.weebly.com/uploads/1/3/0/7/130775365/7370477.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/vunud.pdf
- https://cdn-cms.f-static.net/uploads/4389127/normal_5f91cbe0b9f91.pdf
- https://cdn-cms.f-static.net/uploads/4389354/normal_5f941622efeeb.pdf
- https://cdn-cms.f-static.net/uploads/4389586/normal_5f8f25509fe68.pdf
- https://cdn-cms.f-static.net/uploads/4380084/normal_5f9050b89a7fe.pdf
- https://cdn-cms.f-static.net/uploads/4384325/normal_5f938fa61e329.pdf
- https://s3.amazonaws.com/dedinavesute/bupiwesazoligaje.pdf
- https://s3.amazonaws.com/mijedusovineti/wavax.pdf
- https://s3.amazonaws.com/mubefula/discuss_the_concept_of_rural_development.pdf
- https://uploads.strikinglycdn.com/files/2be26bca-0246-48c6-a759-369d9c909ade/mezituf.pdf
- https://uploads.strikinglycdn.com/files/3d83afa8-b067-4b12-982e-6d4511072cc0/detejejizu.pdf
- https://uploads.strikinglycdn.com/files/37cf0ae9-42a2-4c22-aef2-17ba4c7c0c13/97836496952.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f873cc856f56.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f8704a03313a.pdf
- https://cdn-cms.f-static.net/uploads/4393026/normal_5f8f48d727f6c.pdf
- https://cdn-cms.f-static.net/uploads/4369643/normal_5f89b45099720.pdf
- https://cdn-cms.f-static.net/uploads/4368218/normal_5f8877ed49142.pdf
- https://uploads.strikinglycdn.com/files/d396451f-d871-46ec-9802-b1334c287a41/57811290419.pdf
- https://uploads.strikinglycdn.com/files/0dbdd8d2-0e6b-4ee8-b0e0-0a0e0ec17061/2700173413.pdf
- https://uploads.strikinglycdn.com/files/41bb9434-6efc-4a10-83c8-49e74289bf02/xofemurivusanitunedefo.pdf
Embedded domains
- ttraff.club
- vuxozajuje.weebly.com
- vimiwegom.weebly.com
- tubenuluni.weebly.com
- kekerisasil.weebly.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- x.es
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report