MALICIOUS — normal_5f890c16a0be1.pdf
MALICIOUS — normal_5f890c16a0be1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a69926bee947e511f47a69bff7b40ff51ca06a85547f2cafa290fe1bd22ba5ab - SHA-1:
a0fa8a772f86c4e5512c7d483e9053d81733304f - MD5:
9cf8da892a2b4ba3b06005c6e6edbb9e - ssdeep:
768:2gGzpDxpgR+V3Z0CMwCsuI4A6VnCAT0Bv5ePlRRBlTarlInIvq0FgAAm83:jGF9p/ZusvX6VnpPZBCl2SFgAAmm - TLSH:
T16D347CF35097ED4C768A6F47AEAB106A685AC38C6033969440D8773CC5BC6FE6E10E11 - Submitted as: normal_5f890c16a0be1.pdf
- File type: pdf · Size: 52444 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279037.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=piaggio+beverly+500+cruiser+service+manual, https://site-1036945.mozfiles.com/files/1036945/ragiwafidifevajotafu.pdf, https://site-1040668.mozfiles.com/files/1040668/67245360603.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=piaggio+beverly+500+cruiser+service+manual
- https://site-1036945.mozfiles.com/files/1036945/ragiwafidifevajotafu.pdf
- https://site-1040668.mozfiles.com/files/1040668/67245360603.pdf
- https://site-1040264.mozfiles.com/files/1040264/badolerediso.pdf
- https://site-1036689.mozfiles.com/files/1036689/10363283818.pdf
- https://site-1036724.mozfiles.com/files/1036724/fezuxatepek.pdf
- https://rolosakuzorega.weebly.com/uploads/1/3/1/3/131379035/tatugeg-nutilijilemudoj.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/mabexa.pdf
- https://xifobosakup.weebly.com/uploads/1/3/2/8/132815359/6941125.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279037.pdf
- https://lajojixuvoporor.weebly.com/uploads/1/3/0/7/130738555/vusewekamoda.pdf
- https://site-1041682.mozfiles.com/files/1041682/38736304209.pdf
- https://site-1039707.mozfiles.com/files/1039707/17043116853.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/tumomeseke-wepebipodimabid-falonezifo-vasunejebemetiv.pdf
- https://sevanilab.weebly.com/uploads/1/3/1/4/131437268/2851860.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/gidosaz.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/wepezuwodu-fivusosi.pdf
- https://uploads.strikinglycdn.com/files/c0f7d15c-31ae-4162-85fc-b9dcf06bb1f0/83276175591.pdf
- https://uploads.strikinglycdn.com/files/1a44ed9c-d1d7-41d2-abda-e96e11fad7fb/1616829406.pdf
- https://uploads.strikinglycdn.com/files/0450cf47-3b23-4df1-a2e8-39361a0466e2/lifun.pdf
- https://uploads.strikinglycdn.com/files/3b6ce51b-7f23-4326-b110-65f46c4b49d6/81598081725.pdf
- https://cdn.shopify.com/s/files/1/0503/9993/6662/files/tiditoputupope.pdf
- https://cdn.shopify.com/s/files/1/0496/5131/8935/files/fokalikovawe.pdf
- https://cdn.shopify.com/s/files/1/0268/7523/2427/files/rijabox.pdf
- https://cdn.shopify.com/s/files/1/0434/4699/3052/files/nufovutivupigurope.pdf
Embedded domains
- ggtraff.ru
- site-1036945.mozfiles.com
- site-1040668.mozfiles.com
- site-1040264.mozfiles.com
- site-1036689.mozfiles.com
- site-1036724.mozfiles.com
- rolosakuzorega.weebly.com
- megadezatesaram.weebly.com
- xifobosakup.weebly.com
- fijojonibiw.weebly.com
- lajojixuvoporor.weebly.com
- site-1041682.mozfiles.com
- site-1039707.mozfiles.com
- lipowuripipu.weebly.com
- sevanilab.weebly.com
- rabifupokuwu.weebly.com
- viweposedijul.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report