MALICIOUS — normal_5f8767ed89986.pdf
MALICIOUS — normal_5f8767ed89986.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
760b92aae265e61aa6e364ab88efe12f9a0cb5c18b32316eb689fa8acd90ab5d - SHA-1:
d351ed2e1245a40e4f169d835849d415888ef4dd - MD5:
9a6088e471375802851e4f6606d1f198 - ssdeep:
768:6gGzpDhpgt75j44YxV6IkKUPkHqdg+bqgrKtuH+GcYDZMAmjxg8m0cgrvX:nGFFpdPkBMEbhGtuHxMAg3rvX - TLSH:
T1CA33ADF300A7ED8C7E875B03ADAB116A518AC789A232D760588C773D95BC1ED7E10861 - Submitted as: normal_5f8767ed89986.pdf
- File type: pdf · Size: 48535 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=worx+chainsaw+user+manual, https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/fadedamiwijokati.pdf, https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/93049f265a0000.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=worx+chainsaw+user+manual
- https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/fadedamiwijokati.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/93049f265a0000.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/6015640.pdf
- https://cdn.shopify.com/s/files/1/0434/7029/1096/files/6339922457.pdf
- https://cdn.shopify.com/s/files/1/0432/5752/8478/files/76068754855.pdf
- https://cdn.shopify.com/s/files/1/0492/8031/9645/files/brevard_clerk_of_courts_beca.pdf
- https://cdn.shopify.com/s/files/1/0433/9702/1854/files/omegle_not_working_camera.pdf
- https://cdn.shopify.com/s/files/1/0477/5562/4604/files/menoje.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3731638.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/8e42bfb8d1b0f.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/e27909d0be.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f86f85fbbce5.pdf
- https://cdn-cms.f-static.net/uploads/4367903/normal_5f8767d719c55.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f8744fd800fb.pdf
- https://vozutadisifik.weebly.com/uploads/1/3/1/4/131483249/1e7e9f5fd.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/8948163.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/duzebajonufepunurudu.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/tigosorivibisakoxu.pdf
- https://site-1042927.mozfiles.com/files/1042927/9815447334.pdf
- https://site-1039156.mozfiles.com/files/1039156/segojesewe.pdf
- https://site-1038541.mozfiles.com/files/1038541/583824480.pdf
- https://site-1043216.mozfiles.com/files/1043216/27896306864.pdf
- https://site-1044243.mozfiles.com/files/1044243/90447328980.pdf
Embedded domains
- cctraff.ru
- mojenosude.weebly.com
- zoxuzuxebexot.weebly.com
- vopevejefed.weebly.com
- cdn.shopify.com
- jakedekokobara.weebly.com
- gimejexoxixaza.weebly.com
- bedizegoresupa.weebly.com
- gevafitasib.weebly.com
- cdn-cms.f-static.net
- vozutadisifik.weebly.com
- sibakixode.weebly.com
- fuparududewon.weebly.com
- jemiwuwavaza.weebly.com
- site-1042927.mozfiles.com
- site-1039156.mozfiles.com
- site-1038541.mozfiles.com
- site-1043216.mozfiles.com
- site-1044243.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report