MALICIOUS — normal_5f870be87b512.pdf
MALICIOUS — normal_5f870be87b512.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a93e3c64cd072a901abaf1ce5b1a514343ffae74c6b845ae02ade9b46d869b91 - SHA-1:
2a94d0c881020020376829e71bcebbdba983e598 - MD5:
62fc2a6b4b300b96243b49075ce31a41 - ssdeep:
6144:2zifBYAmO85sr+9UVFWkGbeS8pvt7oKv9KDvXq5:8if+Amd59UnWkGbe7vt8Kv9qvX+ - TLSH:
T13A4402F324ABDD4DBE835B53BDF61546612AD6493271E78412487B6CC8B82BD7E00B02 - Submitted as: normal_5f870be87b512.pdf
- File type: pdf · Size: 255936 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/8c3f11ed.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=android+textview+center+text+multiline, https://site-1048173.mozfiles.com/files/1048173/79519252988.pdf, https://site-1040512.mozfiles.com/files/1040512/78030025235.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=android+textview+center+text+multiline
- https://site-1048173.mozfiles.com/files/1048173/79519252988.pdf
- https://site-1040512.mozfiles.com/files/1040512/78030025235.pdf
- https://site-1036920.mozfiles.com/files/1036920/29762573137.pdf
- https://site-1040426.mozfiles.com/files/1040426/15197261709.pdf
- https://uploads.strikinglycdn.com/files/f87052dd-a6d5-4af9-b66b-cf0774fc2513/suruvivifulinu.pdf
- https://uploads.strikinglycdn.com/files/79cdfce8-8420-4021-96b4-954a60675306/jubowetulizalok.pdf
- https://uploads.strikinglycdn.com/files/108aca22-ad22-407f-9fc5-6ef3bfdd36b0/bizanup.pdf
- https://uploads.strikinglycdn.com/files/c249a4ef-1900-40f1-b5ef-afad7d4ddfcd/semizivurefusibivur.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/8c3f11ed.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/lukuxaluk.pdf
- https://uploads.strikinglycdn.com/files/7882ae20-5ae8-44b9-9a33-a709b3aa9f6c/40306980344.pdf
- https://uploads.strikinglycdn.com/files/1c523aa0-928a-4d4c-9bac-c0398a05fbdf/kumos.pdf
- https://uploads.strikinglycdn.com/files/2b2a3ac8-ffe6-4601-876d-8cc4e7af91d1/kasamavoxiwudamiviraneted.pdf
- https://cdn.shopify.com/s/files/1/0431/2766/8890/files/fabakugisaf.pdf
- https://cdn.shopify.com/s/files/1/0457/0162/8060/files/zatewi.pdf
- https://cdn.shopify.com/s/files/1/0435/3972/6487/files/all_of_me_lyrics_download.pdf
- https://cdn.shopify.com/s/files/1/0497/2760/2840/files/public_company_accounting_oversight_board.pdf
- https://cdn.shopify.com/s/files/1/0436/4432/1945/files/blank_middle_east_map_no_borders.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1048173.mozfiles.com
- site-1040512.mozfiles.com
- site-1036920.mozfiles.com
- site-1040426.mozfiles.com
- uploads.strikinglycdn.com
- jatorogerujew.weebly.com
- bedizegoresupa.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- luasoftware.com
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report