MALICIOUS — normal_5f87bdfde3a1d.pdf
MALICIOUS — normal_5f87bdfde3a1d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ba5138379c1dec40b80f0c9a9699d2ed3aa1ac39fc62ca5c48b6d9bc428b7aee - SHA-1:
408d51ca9197a2a5feac9da24ed26225c06164c3 - MD5:
c8c457470e40411b46d4e8c0d8efe14f - ssdeep:
1536:CGFYps9xQaxNUxhhpg18lA4bgfetIM4UvEpmWgZYxNIwP:7FYpcn2h3g8y4EfeuuvEpJys - TLSH:
T1FD348EF30093ED8C7A8BAF476DAB15A8645ED7886127D7A004C82B6CC4BC6FD3E10651 - Submitted as: normal_5f87bdfde3a1d.pdf
- File type: pdf · Size: 55765 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://cdn-cms.f-static.net/uploads/4365635/normal_5f8757cda9d9e.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=dittersdorf+sinfonia+concertante+pdf, https://cdn-cms.f-static.net/uploads/4365584/normal_5f870822b33b9.pdf, https://cdn-cms.f-static.net/uploads/4367283/normal_5f874b54b84d2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=dittersdorf+sinfonia+concertante+pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f870822b33b9.pdf
- https://cdn-cms.f-static.net/uploads/4367283/normal_5f874b54b84d2.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f878b78ef244.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f8757cda9d9e.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f86fc2bef46f.pdf
- https://uploads.strikinglycdn.com/files/5176fbe5-82b0-4245-b674-97db94e53236/8164195603.pdf
- https://uploads.strikinglycdn.com/files/61a8b192-077c-4c36-a075-1ae4a99521d8/27970135721.pdf
- https://uploads.strikinglycdn.com/files/e4dec124-13cd-4970-bac2-f6b076a8cda1/zikuginaladepezikukaso.pdf
- https://uploads.strikinglycdn.com/files/1233f13f-5f7e-4e15-a686-c8069b9cc7cd/56089957234.pdf
- https://uploads.strikinglycdn.com/files/94702384-8b38-4d7d-a710-fe19b0896a62/sagekelavifunomaw.pdf
- https://cdn.shopify.com/s/files/1/0268/8004/9338/files/jabawejejebug.pdf
- https://cdn.shopify.com/s/files/1/0484/9929/4369/files/originals_book_summary.pdf
- https://cdn.shopify.com/s/files/1/0502/2570/9211/files/face_recognition_applications.pdf
- https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/manibaz.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/rarikavabemis_nadavutidur_nutalelodate.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/3ae9a2fcd2.pdf
- https://lefedatit.weebly.com/uploads/1/3/0/7/130776734/natemufive.pdf
- https://uploads.strikinglycdn.com/files/67cb2053-e357-432f-8a16-22ac636bd60f/67548546138.pdf
- https://uploads.strikinglycdn.com/files/55b61605-2eaf-46b4-9030-e7e8d339cf2c/69027751565.pdf
- https://uploads.strikinglycdn.com/files/5c7949c3-35ee-473c-8135-d714ec00d694/tagosodozeraku.pdf
- https://uploads.strikinglycdn.com/files/dbc2d120-b1ce-4802-87ad-b7337f96f49f/42337670919.pdf
- https://uploads.strikinglycdn.com/files/ae67afb5-e318-42c4-a5d7-e72fe678f571/41237781473.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f87a75ae83d2.pdf
- https://cdn-cms.f-static.net/uploads/4366645/normal_5f875c0295ee6.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- ninukiwipovesot.weebly.com
- sibakixode.weebly.com
- nanorobudilason.weebly.com
- lefedatit.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report