MALICIOUS — normal_5f8dc2c94271e.pdf
MALICIOUS — normal_5f8dc2c94271e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
aadf9377c2da121e6a6a22434474643ab2929aac0dcd09ffb210c0e756fa569e - SHA-1:
0b62b74d230efa722f6103e0083f4d6a8387efbd - MD5:
7520be9235974af3864b8de97d02cff6 - ssdeep:
1536:fGFMeRT+on81cMS42IR1gNQOIy3mbVj/cIGstYm:OFMeIo81bDPgQrbeIGsb - TLSH:
T14536BFF710D7EC8D7A4BA707D9BA20696446C38CA5369BA041D8732DC47C6FD6E00B61 - Submitted as: normal_5f8dc2c94271e.pdf
- File type: pdf · Size: 67154 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://mamexobupelo.weebly.com/uploads/1/3/1/3/131383482/2ea9bf5911bb1bb.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.me/123?keyword=budgeting+for+students+pdf, https://rudofodirofebas.weebly.com/uploads/1/3/0/7/130739781/lutawinebajizi.pdf, https://winomumamo.weebly.com/uploads/1/3/1/0/131070375/xepolosagigu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=budgeting+for+students+pdf
- https://rudofodirofebas.weebly.com/uploads/1/3/0/7/130739781/lutawinebajizi.pdf
- https://winomumamo.weebly.com/uploads/1/3/1/0/131070375/xepolosagigu.pdf
- https://mamexobupelo.weebly.com/uploads/1/3/1/3/131383482/2ea9bf5911bb1bb.pdf
- https://vodiwisilob.weebly.com/uploads/1/3/2/6/132681054/dosedaxejovadun-zafede.pdf
- https://kesevaze.weebly.com/uploads/1/3/1/3/131383297/2841377.pdf
- https://jorimedazaget.weebly.com/uploads/1/3/0/7/130738946/jawizu.pdf
- https://nulixedupalaz.weebly.com/uploads/1/3/0/7/130739510/7249761.pdf
- https://uploads.strikinglycdn.com/files/2ae913f6-30d0-4699-a50b-dc5e7fc5489a/framed_perspective_vol_2.pdf
- https://uploads.strikinglycdn.com/files/e5f79f0f-1b6f-4a42-9611-a01fd4ad34ed/31044829807.pdf
- https://uploads.strikinglycdn.com/files/a4c41c76-e195-45ef-beca-8f39bddbb6a8/8556103712.pdf
- https://uploads.strikinglycdn.com/files/af5f64a5-86a7-4fab-b7d2-8de774e9fcea/47071287444.pdf
- https://uploads.strikinglycdn.com/files/0b2fed43-3634-4caa-b59f-af22774fa8b5/syntactic_structures_in_english.pdf
- https://uploads.strikinglycdn.com/files/cf2a8d6a-ef86-46ab-8cf3-70edd4067ba5/97821510372.pdf
- https://uploads.strikinglycdn.com/files/2ea4e365-39fa-4292-9564-a60b1c848cdc/situkisu.pdf
- https://uploads.strikinglycdn.com/files/610d908e-6e41-44bd-b4e3-81842aa26823/dikukumamuxapuxonepu.pdf
- https://riragojefo.weebly.com/uploads/1/3/1/8/131857115/7282037.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tifuxasorelav-sunagutigu-gikisifexixabot.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/6377259.pdf
- https://cdn.shopify.com/s/files/1/0433/7090/5750/files/58510112951.pdf
- https://cdn.shopify.com/s/files/1/0504/7428/7269/files/zogukavag.pdf
- https://cdn.shopify.com/s/files/1/0492/2150/1094/files/realidades_2_4b_practice_workbook_answers.pdf
- https://cdn.shopify.com/s/files/1/0432/0319/9138/files/gogigisoladavatafanitu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.me
- rudofodirofebas.weebly.com
- winomumamo.weebly.com
- mamexobupelo.weebly.com
- vodiwisilob.weebly.com
- kesevaze.weebly.com
- jorimedazaget.weebly.com
- nulixedupalaz.weebly.com
- uploads.strikinglycdn.com
- riragojefo.weebly.com
- genigudepa.weebly.com
- saxibodusazo.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report