MALICIOUS — normal_5f88a788d4f83.pdf
MALICIOUS — normal_5f88a788d4f83.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bee0aa2ed8a98d10aa209afeb330d9b3205bd2086ba4db007949ba921506d206 - SHA-1:
2fd0da2f939676a1d864e6e91258dd062ff4e5ba - MD5:
4980d510b1e85348c2f583d4922a1255 - ssdeep:
1536:pGFVeGwQY1Yka2eiJBc/5vOk+bo3j4H1MVv5C68QP8m:8FVeqUJy8Ojs1MVQNO - TLSH:
T182348DF710DBDD4C7A879B439DBB2555648AC38C723A97A04888766CC4BC6AE7F50C20 - Submitted as: normal_5f88a788d4f83.pdf
- File type: pdf · Size: 55523 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tavumake.weebly.com/uploads/1/3/2/7/132740551/lopinudifegopotukas.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=dpp+4+inhibitors+mechanism+of+action+pdf, https://cdn-cms.f-static.net/uploads/4368496/normal_5f8863721cbfd.pdf, https://cdn-cms.f-static.net/uploads/4367313/normal_5f87e09351a9e.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=dpp+4+inhibitors+mechanism+of+action+pdf
- https://cdn-cms.f-static.net/uploads/4368496/normal_5f8863721cbfd.pdf
- https://cdn-cms.f-static.net/uploads/4367313/normal_5f87e09351a9e.pdf
- https://cdn-cms.f-static.net/uploads/4367959/normal_5f87dcbdad201.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f870da3d44b8.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f87a4955bac7.pdf
- https://fupexorugukemig.weebly.com/uploads/1/3/0/8/130814763/pogoriki_poxus.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/lopinudifegopotukas.pdf
- https://bibeliki.weebly.com/uploads/1/3/0/7/130738572/c167e7091.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/rinozeleb.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/nukexifepejisox.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/9b6e7aadaa78.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/rinedufiwaditarip.pdf
- https://site-1038952.mozfiles.com/files/1038952/zitodosim.pdf
- https://site-1036958.mozfiles.com/files/1036958/toromopit.pdf
- https://site-1040871.mozfiles.com/files/1040871/93974902439.pdf
- https://site-1041295.mozfiles.com/files/1041295/43824156821.pdf
- https://uploads.strikinglycdn.com/files/13bcbf45-f027-4680-a3c4-02144b565cdb/walupenusafijidotodizi.pdf
- https://uploads.strikinglycdn.com/files/e7d3eff8-cd12-436a-a591-26e483f38e98/damaponumijolujuliwolo.pdf
- https://uploads.strikinglycdn.com/files/51df11e4-00d3-47c7-ae38-bbde51f8d253/91123240624.pdf
- https://uploads.strikinglycdn.com/files/8035d6d7-98e0-49b7-93a5-d314d88facb9/vipavoz.pdf
- https://uploads.strikinglycdn.com/files/f66f6718-6a9c-4b53-b2a3-25f0dfe682fc/zofokimukuk.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/nesubine.pdf
- https://pezopipowom.weebly.com/uploads/1/3/1/4/131406060/5525451.pdf
- https://lefedatit.weebly.com/uploads/1/3/0/7/130776734/riwigenamajone_mevot_nusuv_xapig.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- fupexorugukemig.weebly.com
- tavumake.weebly.com
- bibeliki.weebly.com
- rakamukomegu.weebly.com
- dimaxafazeza.weebly.com
- mojivimimujovo.weebly.com
- site-1038952.mozfiles.com
- site-1036958.mozfiles.com
- site-1040871.mozfiles.com
- site-1041295.mozfiles.com
- uploads.strikinglycdn.com
- gimejexoxixaza.weebly.com
- pezopipowom.weebly.com
- lefedatit.weebly.com
- k.pw
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report