MALICIOUS — normal_5f8a99a9b8f6d.pdf
MALICIOUS — normal_5f8a99a9b8f6d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a9312775250fb1b05eb40c15a50ebf7487a2f35e09ca6172834d36967a921acb - SHA-1:
5c78204df0ad75769373fb54338f60e11a6573e9 - MD5:
8c675bb1120dbe652714a867b704839a - ssdeep:
1536:rGFZedpaX5CzyLX2K2ShhbY699fl+jH9BlPAC8pj:KFZedAVaSf0T9I55 - TLSH:
T1B737CFF31497DECC7A4BAF4368AB15A8444AC788312697A05C8C776CC5BC2BD7F24852 - Submitted as: normal_5f8a99a9b8f6d.pdf
- File type: pdf · Size: 70153 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://nikoxutaju.weebly.com/uploads/1/3/1/3/131378952/keguparomemarage.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=neuron+structure+and+function+psychology+pdf, https://uploads.strikinglycdn.com/files/1ce188e9-7c6c-4cbc-9179-a73f779f1922/zukafepupotevaxisolej.pdf, https://uploads.strikinglycdn.com/files/0ea50af7-51d7-4067-a78b-9c0bfa794a5c/zarevesadexafek.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=neuron+structure+and+function+psychology+pdf
- https://uploads.strikinglycdn.com/files/1ce188e9-7c6c-4cbc-9179-a73f779f1922/zukafepupotevaxisolej.pdf
- https://uploads.strikinglycdn.com/files/0ea50af7-51d7-4067-a78b-9c0bfa794a5c/zarevesadexafek.pdf
- https://uploads.strikinglycdn.com/files/ab8fbc52-fb22-4702-abd3-fd80fd076e52/18607144502.pdf
- https://uploads.strikinglycdn.com/files/005d6cd9-5205-435d-be97-52ebbe8f26fd/fixujelunapufi.pdf
- https://uploads.strikinglycdn.com/files/0a68fbe1-5848-487a-8b9a-bf4af9fc5c48/padizojatinefixo.pdf
- https://uploads.strikinglycdn.com/files/3573ee74-f29b-41f7-ab0d-deeec62d7b03/rarudinupixukesi.pdf
- https://uploads.strikinglycdn.com/files/5791996a-f701-4f39-8f65-32f4768e3f02/baldur_s_gate_enhanced_edition_manual.pdf
- https://nikoxutaju.weebly.com/uploads/1/3/1/3/131378952/keguparomemarage.pdf
- https://mogijoduvide.weebly.com/uploads/1/3/0/8/130814471/8b92a0d095201ba.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/kizerapu.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/5650151.pdf
- https://jarapitoxedomel.weebly.com/uploads/1/3/1/4/131437170/4517271.pdf
- https://uploads.strikinglycdn.com/files/6707fd44-8fd3-4c04-aca5-7f3865795177/rilubunasiwif.pdf
- https://uploads.strikinglycdn.com/files/9545ed5e-ae18-41e9-aac4-44cdefbb9892/pilutu.pdf
- https://uploads.strikinglycdn.com/files/d5bea296-1dcf-4146-b753-10fc1464a3fa/x_force_autodesk_2016.pdf
- https://cdn-cms.f-static.net/uploads/4378604/normal_5f8a1b6b274ca.pdf
- https://cdn-cms.f-static.net/uploads/4367286/normal_5f875584579df.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- nikoxutaju.weebly.com
- mogijoduvide.weebly.com
- fijojonibiw.weebly.com
- jatorogerujew.weebly.com
- jarapitoxedomel.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report