MALICIOUS — normal_5f9036e734f2d.pdf
MALICIOUS — normal_5f9036e734f2d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9dc49d5e8000c258a4bc39a2284390481e7e9856764d85269afc6def218fea21 - SHA-1:
fc7f450ff799e56524b33b6721b3df5d592cc76f - MD5:
d24c590197f3b5d7e8e89876c02a0034 - ssdeep:
1536:tGFTppoUUCU765x0opFjgwXjHAmoExH19/Wagssmb5qq9d:wFTpZF0LopBjjHAmo4V9/O2oK - TLSH:
T1FC38D0F38193EECCB95F5B079AAB11AC5485964D602B97E0048CB33CC87C5EEAF50621 - Submitted as: normal_5f9036e734f2d.pdf
- File type: pdf · Size: 80954 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/f55bf4143a.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.cc/123?keyword=download+need+for+speed+mod+apk%252Bdata, https://cdn-cms.f-static.net/uploads/4371808/normal_5f8cb979ab42d.pdf, https://cdn-cms.f-static.net/uploads/4369784/normal_5f8d5413adfa0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=download+need+for+speed+mod+apk%252Bdata
- https://s3.amazonaws.com/zuxadol/94825564203.pdf
- https://s3.amazonaws.com/zuxadol/2517029575.pdf
- https://s3.amazonaws.com/gupuso/52383035930.pdf
- https://s3.amazonaws.com/henghuili-files2/potosibu.pdf
- https://s3.amazonaws.com/zetare/18936710835.pdf
- https://s3.amazonaws.com/tetazino/niwimaviza.pdf
- https://s3.amazonaws.com/tetazino/carnot_cycle_efficiency_derivation.pdf
- https://s3.amazonaws.com/wilugugo/24108892959.pdf
- https://s3.amazonaws.com/zetare/56960907538.pdf
- https://cdn-cms.f-static.net/uploads/4371808/normal_5f8cb979ab42d.pdf
- https://cdn-cms.f-static.net/uploads/4369784/normal_5f8d5413adfa0.pdf
- https://cdn-cms.f-static.net/uploads/4375541/normal_5f8c755bb481e.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/f55bf4143a.pdf
- https://bebamewikirebu.weebly.com/uploads/1/3/0/8/130874540/texumebelegavu-bajus-bosifowovoxij-wewawijonalik.pdf
- https://sisodiwitamusoz.weebly.com/uploads/1/3/2/6/132681746/127b244a1.pdf
- https://porelananov.weebly.com/uploads/1/3/0/7/130775759/potize.pdf
- https://uploads.strikinglycdn.com/files/d2530538-a349-45c3-84bc-3807e3e51634/wojipuluj.pdf
- https://uploads.strikinglycdn.com/files/3479553c-222b-40cc-8c4d-ad219a134c13/89854207515.pdf
- https://uploads.strikinglycdn.com/files/0e740c9f-9099-4881-98dc-93841c488aea/14505041513.pdf
- https://uploads.strikinglycdn.com/files/9c296446-8e7f-4edd-80a3-fdcdcfc723da/86938364124.pdf
- https://uploads.strikinglycdn.com/files/9d3ebd0c-b95f-482e-8c8e-c40dda56ee64/gibukarafekuxo.pdf
- https://uploads.strikinglycdn.com/files/4fd212bc-1840-4f27-b161-fe360b912d16/fefigi.pdf
- https://uploads.strikinglycdn.com/files/e9ba0a12-6d52-46cc-bff7-59f3410ec8a8/85668239194.pdf
- https://uploads.strikinglycdn.com/files/9b2b8e0f-4c1a-4b85-a12f-ace0bb729a79/kojajupiwevuxod.pdf
Embedded domains
- ttraff.cc
- s3.amazonaws.com
- cdn-cms.f-static.net
- riwisasivituw.weebly.com
- bebamewikirebu.weebly.com
- sisodiwitamusoz.weebly.com
- porelananov.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report