MALICIOUS — normal_5f87cf0f1e7c3.pdf
MALICIOUS — normal_5f87cf0f1e7c3.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7bb8647045971ca943bfbc296e4719927eaf90a664f4c6e83f53a8647a2f34e6 - SHA-1:
2fa7a6efd0ae32631992d9ab81b6ae0bd26507d0 - MD5:
3f795b328cf6532ca09a61783e4e3647 - ssdeep:
1536:sGFzpn7zZ5Mmjw5ZD78YqoB8m4VzyRwBBQlDX:JFzp7zZ5NwqYDBb4VB/QF - TLSH:
T1FA339EF750E3DECC3B8B6B4359E705986149D6887132ABA05988763CD4BC6BD2F10E21 - Submitted as: normal_5f87cf0f1e7c3.pdf
- File type: pdf · Size: 49941 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gozofuma.weebly.com/uploads/1/3/0/8/130874065/penotisezivigop.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=ms+publisher+2020+tutorial+pdf+with+examples, https://gozofuma.weebly.com/uploads/1/3/0/8/130874065/penotisezivigop.pdf, https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dekegu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=ms+publisher+2020+tutorial+pdf+with+examples
- https://gozofuma.weebly.com/uploads/1/3/0/8/130874065/penotisezivigop.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dekegu.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/mezevoxinokimuwamibu.pdf
- https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/manibaz.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/8347111.pdf
- https://uploads.strikinglycdn.com/files/5898b37b-330a-4d45-8763-ea5cabe6c2dd/27811384734.pdf
- https://uploads.strikinglycdn.com/files/78df3905-961b-4f19-806c-c8b0a82ff99a/ravuma.pdf
- https://uploads.strikinglycdn.com/files/d9a6ff90-2132-4af9-ada3-790c830ed420/28985973221.pdf
- https://uploads.strikinglycdn.com/files/e73d3af9-1d01-4eca-b38f-d72e03ddf9ad/60082739813.pdf
- https://uploads.strikinglycdn.com/files/830656df-a4f8-460a-8736-1fb2a95b0d86/mugofokulavekojirub.pdf
- https://uploads.strikinglycdn.com/files/0953b79b-b6d9-434e-9ba6-7013f3a76f2a/91859258901.pdf
- https://uploads.strikinglycdn.com/files/04f7f242-c77e-4c3a-973f-3ca74959922a/90887338691.pdf
- https://uploads.strikinglycdn.com/files/8575f56b-85e3-475d-8913-ed7f78870047/zupufosovifefarunu.pdf
- https://site-1042780.mozfiles.com/files/1042780/22414931021.pdf
- https://site-1038578.mozfiles.com/files/1038578/99690809350.pdf
- https://site-1039303.mozfiles.com/files/1039303/tepogonepedaxepinaf.pdf
- https://cdn-cms.f-static.net/uploads/4366351/normal_5f870fdc1f3a7.pdf
- https://cdn-cms.f-static.net/uploads/4368500/normal_5f8785dbd2980.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f874fe68a0a0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- gozofuma.weebly.com
- bedizegoresupa.weebly.com
- xojerajap.weebly.com
- ninukiwipovesot.weebly.com
- mogilifus.weebly.com
- uploads.strikinglycdn.com
- site-1042780.mozfiles.com
- site-1038578.mozfiles.com
- site-1039303.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report