MALICIOUS — normal_5f8cb98578586.pdf
MALICIOUS — normal_5f8cb98578586.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6d82c71ba4509877ade4554c1ca00804fb42e50cbcef4238486e74333599f1a8 - SHA-1:
3093b4f2486a14cc80359a55acd831a9a27a195c - MD5:
9bd8315094245657ec8efb799612b0f9 - ssdeep:
768:cgGzpDZpEzJn5BcZIqbBMPeE0fCx3HYKR/gbkX1f2kV0Zb+esYYxdmLWBQyR+9RG:5GFdptHfCpagX1flV0Zb+esqe4yT - TLSH:
T157337CF360A7ED4CBA878F037DEE28AD9049D7499132A7605598B72DC07C36E7E00A10 - Submitted as: normal_5f8cb98578586.pdf
- File type: pdf · Size: 50329 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/jasamejug-jenutuzudemeluf.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.ru/123?keyword=adblock+apk+download+free, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/jasamejug-jenutuzudemeluf.pdf, https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/2551819.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=adblock+apk+download+free
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/jasamejug-jenutuzudemeluf.pdf
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/2551819.pdf
- https://ziripovopibew.weebly.com/uploads/1/3/0/8/130874468/vujibawefil-vozomodifate-sajobesiwi-bezaxexizomon.pdf
- https://rabugotekinevod.weebly.com/uploads/1/3/1/8/131871666/8571159.pdf
- https://buliduxefexefux.weebly.com/uploads/1/3/1/6/131636978/pabegolasati.pdf
- https://uploads.strikinglycdn.com/files/892ba25e-639a-4b92-b0a5-40b0e40c7345/39664461807.pdf
- https://uploads.strikinglycdn.com/files/1795b7e6-cf2f-47cf-ab24-317814f8ad03/59236884642.pdf
- https://uploads.strikinglycdn.com/files/6ef2c872-ae95-4c9f-8ad8-230de60fe987/bugejisufajasopodu.pdf
- https://uploads.strikinglycdn.com/files/fc71d997-d3c5-4b49-b466-a397db44ee9e/20023586947.pdf
- https://uploads.strikinglycdn.com/files/96263fb3-f695-4506-950a-556cdb7ab644/72814196461.pdf
- https://cdn-cms.f-static.net/uploads/4367283/normal_5f876321c92ed.pdf
- https://cdn-cms.f-static.net/uploads/4366632/normal_5f872f4c5d17b.pdf
- https://cdn-cms.f-static.net/uploads/4369643/normal_5f8aa024423ce.pdf
- https://cdn-cms.f-static.net/uploads/4371023/normal_5f88a0a33fe6f.pdf
- https://cdn.shopify.com/s/files/1/0431/8009/7702/files/rekivasupamuxepotol.pdf
- https://cdn.shopify.com/s/files/1/0501/5925/5717/files/ranetinebirilipibabuzalik.pdf
- https://cdn.shopify.com/s/files/1/0429/9807/1450/files/componentes_del_espacio_supracrestal.pdf
- https://cdn.shopify.com/s/files/1/0496/0364/1507/files/8470826651.pdf
- https://cdn.shopify.com/s/files/1/0494/1185/0407/files/mounting_solutions_plus_miami_fl_33157.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/luximidizeniwa.pdf
- https://takijotirodone.weebly.com/uploads/1/3/1/6/131637658/sukoxajapemofu.pdf
- https://gonoloxezejuje.weebly.com/uploads/1/3/1/4/131410007/2aeaed4.pdf
- https://topodomero.weebly.com/uploads/1/3/2/6/132696018/94079.pdf
- https://wesujugureju.weebly.com/uploads/1/3/0/8/130874517/1607846.pdf
Embedded domains
- ttraff.ru
- jakedekokobara.weebly.com
- pavowojavujide.weebly.com
- ziripovopibew.weebly.com
- rabugotekinevod.weebly.com
- buliduxefexefux.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- wepugimi.weebly.com
- takijotirodone.weebly.com
- gonoloxezejuje.weebly.com
- topodomero.weebly.com
- wesujugureju.weebly.com
- mujunoba.weebly.com
- tevirilozarenov.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report