MALICIOUS — normal_5f875b72673cd.pdf
MALICIOUS — normal_5f875b72673cd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c3c7cb85dd54d5a0df832b51b5ab0b5c86e522b4b01cf210e62220e94be418ab - SHA-1:
2166c884d3a177f7d4561c0ece3149219b917c34 - MD5:
23352cf3c6f2c3de0fefaed7e28f645b - ssdeep:
768:f0gGzpDGpf2FVo7lMNF0Q5OAMmOy9pe6+oNaCa0qvRSOWT58pq:pGFSpfE8AZOy9peeNaCaDop18pq - TLSH:
T1E7305CF311A7EC4C7ACA9F03AEAB115DA089D78861329760948C773CD5BC6AD7F10921 - Submitted as: normal_5f875b72673cd.pdf
- File type: pdf · Size: 38419 bytes
- Verdict: malicious (71/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=all+english+idioms+and+phrases+apk+download, https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/4045700.pdf, https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=all+english+idioms+and+phrases+apk+download
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/4045700.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/gabemomigipenaguv.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/kedoxezezaj-temolej-zunemalavorun-mutelokowomimi.pdf
- https://lixaworone.weebly.com/uploads/1/3/1/8/131871871/1475288.pdf
- https://cdn.shopify.com/s/files/1/0494/2263/1067/files/ludegodiwitajeduwukomaxi.pdf
- https://cdn.shopify.com/s/files/1/0493/7498/6399/files/1756022153.pdf
- https://cdn.shopify.com/s/files/1/0437/1231/5545/files/he_speaks_to_me_priscilla_shirer.pdf
- https://cdn.shopify.com/s/files/1/0497/5103/1961/files/12530499994.pdf
- https://uploads.strikinglycdn.com/files/9d94011a-dbd5-4c23-8eb1-8869243ceb38/42688649612.pdf
- https://uploads.strikinglycdn.com/files/da919dd4-6755-420e-b84e-2fc0ace247fb/83984335048.pdf
- https://uploads.strikinglycdn.com/files/5c7740cc-a613-4bef-b064-3e84a7f92d49/64152785676.pdf
- https://uploads.strikinglycdn.com/files/d955081a-1976-4787-9d6d-76d6c4ebc03d/84734134962.pdf
- https://site-1048253.mozfiles.com/files/1048253/vozifujezofabof.pdf
- https://site-1040558.mozfiles.com/files/1040558/gitebikigujoxekukiwe.pdf
- https://site-1038743.mozfiles.com/files/1038743/42383180711.pdf
- https://site-1039491.mozfiles.com/files/1039491/20145937882.pdf
- https://site-1041608.mozfiles.com/files/1041608/bulasegepotex.pdf
- https://site-1039573.mozfiles.com/files/1039573/somiwos.pdf
- https://site-1048275.mozfiles.com/files/1048275/14537760479.pdf
- https://site-1048529.mozfiles.com/files/1048529/jusemimugur.pdf
- https://cdn.shopify.com/s/files/1/0266/9730/2216/files/the_conference_of_the_birds_poem_cliffnotes.pdf
- https://cdn.shopify.com/s/files/1/0438/9067/1771/files/pokemon_buddy_adventure_guide.pdf
- https://cdn.shopify.com/s/files/1/0502/5801/8472/files/super_smash_bros_meme_font.pdf
Embedded domains
- cctraff.ru
- zoxuzuxebexot.weebly.com
- dutitujazekap.weebly.com
- kabudededawizo.weebly.com
- guwomenod.weebly.com
- lixaworone.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1048253.mozfiles.com
- site-1040558.mozfiles.com
- site-1038743.mozfiles.com
- site-1039491.mozfiles.com
- site-1041608.mozfiles.com
- site-1039573.mozfiles.com
- site-1048275.mozfiles.com
- site-1048529.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report