MALICIOUS — normal_5f890cd6357d8.pdf
MALICIOUS — normal_5f890cd6357d8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a38131a97d295e2479dac26329743eaa3d7a8087f478d395583e130dd02f4245 - SHA-1:
6cdffecb8878b969221c992310b40abc658de319 - MD5:
3f8bf7c5855761484a9eaf3465d4bbec - ssdeep:
768:LgGzpD2pYBQugdguP93kilKx/tCoNjuLSE8cIQgIQPQOv:0GF6pXIZtCoNjuPkzv - TLSH:
T19C316DF350A7DD4CBA8EEF037FAA295D608AD74DA0229750454C672DC5BC6BD7E00860 - Submitted as: normal_5f890cd6357d8.pdf
- File type: pdf · Size: 40175 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=hi-yield+spreader+sticker+instructions, https://site-1043660.mozfiles.com/files/1043660/18713264066.pdf, https://site-1036746.mozfiles.com/files/1036746/33804305401.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=hi-yield+spreader+sticker+instructions
- https://site-1043660.mozfiles.com/files/1043660/18713264066.pdf
- https://site-1036746.mozfiles.com/files/1036746/33804305401.pdf
- https://site-1036987.mozfiles.com/files/1036987/ruzirukitorovuzixodotetuj.pdf
- https://site-1042768.mozfiles.com/files/1042768/90008461501.pdf
- https://site-1043414.mozfiles.com/files/1043414/juzikiwixerapamuninub.pdf
- https://zeginuvo.weebly.com/uploads/1/3/0/7/130775519/natuxen.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf
- https://jowodetuleguzu.weebly.com/uploads/1/3/1/8/131856173/7524634.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/4995129.pdf
- https://tegugozitofo.weebly.com/uploads/1/3/0/8/130874592/065fd.pdf
- https://site-1042452.mozfiles.com/files/1042452/mazamuwafuwevujomekasepox.pdf
- https://site-1039259.mozfiles.com/files/1039259/29502789420.pdf
- https://site-1039210.mozfiles.com/files/1039210/pogejevigafarori.pdf
- https://site-1036907.mozfiles.com/files/1036907/nibavurixugijejenanivax.pdf
- https://cdn-cms.f-static.net/uploads/4368972/normal_5f87d4d50e178.pdf
- https://cdn-cms.f-static.net/uploads/4369763/normal_5f88c7fd34611.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f87004de08f3.pdf
- https://uploads.strikinglycdn.com/files/29be7cbd-5690-4944-a15e-1446d309ec7d/88333510128.pdf
- https://uploads.strikinglycdn.com/files/722e04f9-4402-4651-a997-b5647ec8f265/52998663072.pdf
- https://uploads.strikinglycdn.com/files/5d96bbab-fa35-4b22-a239-674936746e73/jomaxexirelakar.pdf
- https://uploads.strikinglycdn.com/files/d0e3bc36-09fe-4803-a394-bf11b0ada0aa/58548948995.pdf
- https://uploads.strikinglycdn.com/files/14242729-6af8-4654-bd0e-a62909975819/mokajujujeribiboso.pdf
- https://cdn-cms.f-static.net/uploads/4368477/normal_5f890a7693ed8.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f87072455f7d.pdf
Embedded domains
- gettraff.ru
- site-1043660.mozfiles.com
- site-1036746.mozfiles.com
- site-1036987.mozfiles.com
- site-1042768.mozfiles.com
- site-1043414.mozfiles.com
- zeginuvo.weebly.com
- genigudepa.weebly.com
- jowodetuleguzu.weebly.com
- gusumadanu.weebly.com
- tegugozitofo.weebly.com
- site-1042452.mozfiles.com
- site-1039259.mozfiles.com
- site-1039210.mozfiles.com
- site-1036907.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report