MALICIOUS — normal_5f8e75ac98f9c.pdf
MALICIOUS — normal_5f8e75ac98f9c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9ca896d3da3f431f45bf28f079eb61c408058be8bb4658b264cf3b3dcb69c032 - SHA-1:
a2cb0acbff636de01848ef84b88dbe7653f28dab - MD5:
cce62977012ad041b1335442706db816 - ssdeep:
1536:cGFdp6/M37jTKxj11rnF8SSwBcBCBL1dOuqtBZB3tfDJDTG:5Fdp3rjWxxxyRwBrVqzZB3tfdu - TLSH:
T1CB38C0F350A7ED4C7A839F17ADEA215EA18CD64C6133D3A42088BB2CC47877C2E51621 - Submitted as: normal_5f8e75ac98f9c.pdf
- File type: pdf · Size: 79435 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ligewajinaxi.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.club/123?keyword=fungal+genetics+and+biology+instructions+to+authors, https://cdn-cms.f-static.net/uploads/4382405/normal_5f8b7042aa09b.pdf, https://cdn-cms.f-static.net/uploads/4368503/normal_5f8aaa6216c87.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=fungal+genetics+and+biology+instructions+to+authors
- https://cdn-cms.f-static.net/uploads/4382405/normal_5f8b7042aa09b.pdf
- https://cdn-cms.f-static.net/uploads/4368503/normal_5f8aaa6216c87.pdf
- https://cdn-cms.f-static.net/uploads/4369802/normal_5f88b42861c1f.pdf
- https://cdn-cms.f-static.net/uploads/4383688/normal_5f8cf05ed6603.pdf
- https://cdn-cms.f-static.net/uploads/4376380/normal_5f8e5528bc942.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/nukexifepejisox.pdf
- https://lotagixowila.weebly.com/uploads/1/3/1/1/131164100/dilapunu.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ligewajinaxi.pdf
- https://mutazodot.weebly.com/uploads/1/3/0/8/130874237/sisopil.pdf
- https://uploads.strikinglycdn.com/files/14e76f14-4ffd-481d-ab12-583e85a00709/bimurijivuwuz.pdf
- https://uploads.strikinglycdn.com/files/07acde38-ffc9-46c3-9f82-ea1038e1add0/tusawatuxo.pdf
- https://cdn-cms.f-static.net/uploads/4368979/normal_5f8e4e033022f.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f88c82c4b917.pdf
- https://cdn.shopify.com/s/files/1/0439/4093/7896/files/47843276305.pdf
- https://cdn.shopify.com/s/files/1/0437/0972/6874/files/cipa_towing_mirrors_fit_chart.pdf
- https://cdn.shopify.com/s/files/1/0481/3753/5655/files/second_derivative_concavity_inflection.pdf
- https://cdn.shopify.com/s/files/1/0440/7135/4533/files/76478209180.pdf
- https://cdn-cms.f-static.net/uploads/4368249/normal_5f88ae6725a44.pdf
- https://cdn-cms.f-static.net/uploads/4371508/normal_5f8da2c7d74e8.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f87fceddf8fa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ttraff.club
- cdn-cms.f-static.net
- dimaxafazeza.weebly.com
- lotagixowila.weebly.com
- guwomenod.weebly.com
- mutazodot.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- t:\Es
- o:\hl
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report