MALICIOUS — normal_5f880259148ba.pdf
MALICIOUS — normal_5f880259148ba.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c2242918bd2603ac90a0bfea42fbaa6e6c3887e9202237d0523dd0efaa4c4081 - SHA-1:
1d1d85a8e9a6275990352dd7b2732a055a4fb308 - MD5:
85d3b2953a190977781723f38f037a47 - ssdeep:
1536:1GFOpjLo02T1Zd6pYfxF7teX9b1BTqH24qlCc:IFOpnsT1CAeh9v - TLSH:
T1D934AFF75077DD8CB64AAF47ADE221965499C788A133D76044883B6CC4BC7FE2E00A51 - Submitted as: normal_5f880259148ba.pdf
- File type: pdf · Size: 55223 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/1d44b872.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=kia+optima+hybrid+2020+owners+manual, https://uploads.strikinglycdn.com/files/d2b2a1c1-a313-47c6-86dc-f46df90582d6/70830303787.pdf, https://uploads.strikinglycdn.com/files/7917a291-5bb3-460f-a66e-9dad77f483ed/28036435928.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=kia+optima+hybrid+2020+owners+manual
- https://uploads.strikinglycdn.com/files/d2b2a1c1-a313-47c6-86dc-f46df90582d6/70830303787.pdf
- https://uploads.strikinglycdn.com/files/7917a291-5bb3-460f-a66e-9dad77f483ed/28036435928.pdf
- https://uploads.strikinglycdn.com/files/f6840a33-59da-4398-923e-04dbe83f3b23/81553249852.pdf
- https://uploads.strikinglycdn.com/files/5c2b526f-de49-4b51-95e2-c3ed6394ff0e/milovawagipo.pdf
- https://uploads.strikinglycdn.com/files/d33c5f1b-8af8-443a-9791-89225be98660/44072784184.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/1d44b872.pdf
- https://vezorobabuwej.weebly.com/uploads/1/3/0/9/130969079/tevob.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/xududev-ledavodu-jatulivarolaxe-bixebenal.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/mikukinib.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/mezevoxinokimuwamibu.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/lulodegoner.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/630dc3.pdf
- https://uploads.strikinglycdn.com/files/694bd283-f9f5-4b5c-aef3-ea7061852dbe/39028435344.pdf
- https://uploads.strikinglycdn.com/files/142fcce1-f1ad-41f1-ac06-05195134749d/60935526488.pdf
- https://site-1038429.mozfiles.com/files/1038429/66561329917.pdf
- https://site-1036824.mozfiles.com/files/1036824/ruliwizuketarivi.pdf
- https://site-1038830.mozfiles.com/files/1038830/josijofaridonu.pdf
- https://site-1048488.mozfiles.com/files/1048488/nebifagevinoxodu.pdf
- https://site-1039889.mozfiles.com/files/1039889/bidukopaxefila.pdf
- https://cdn.shopify.com/s/files/1/0492/3739/3564/files/nalezuwilofalivo.pdf
- https://cdn.shopify.com/s/files/1/0435/8412/7135/files/1967617426.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- jakedekokobara.weebly.com
- vezorobabuwej.weebly.com
- keniwuki.weebly.com
- xojerajap.weebly.com
- bedizegoresupa.weebly.com
- rakamukomegu.weebly.com
- site-1038429.mozfiles.com
- site-1036824.mozfiles.com
- site-1038830.mozfiles.com
- site-1048488.mozfiles.com
- site-1039889.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report