MALICIOUS — normal_5f875afbe9dd4.pdf
MALICIOUS — normal_5f875afbe9dd4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c69f01d72327a9b464ab5b3e6ebdf18c266d0c421d146921eeac47164e34a601 - SHA-1:
b0581a3060a51c8429f931de62aa9ebf574616f4 - MD5:
387f4e4092ac1baa08123ac6ff649a51 - ssdeep:
768:wNgGzpDzeaEDBOX0FKGRqlidBBJlY68xxHaxcHRjOmQOHZ5:wuGFPeaXkXYvHtHpO5w5 - TLSH:
T1D6317CF750A7DD8C3AC7EB136EBA2458A48EDB486132D7A00488776CC47C2BD7E50960 - Submitted as: normal_5f875afbe9dd4.pdf
- File type: pdf · Size: 40970 bytes
- Verdict: malicious (71/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/2e1a6c4b-be45-46e9-8cbe-8c682c58d67a/85881729051.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=natural+selection+and+selective+breeding+worksheet, https://cdn-cms.f-static.net/uploads/4366325/normal_5f8722c98d8c8.pdf, https://cdn-cms.f-static.net/uploads/4367631/normal_5f87584915cd6.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=natural+selection+and+selective+breeding+worksheet
- https://cdn-cms.f-static.net/uploads/4366325/normal_5f8722c98d8c8.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f87584915cd6.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f872bf7caf9d.pdf
- https://uploads.strikinglycdn.com/files/2e1a6c4b-be45-46e9-8cbe-8c682c58d67a/85881729051.pdf
- https://uploads.strikinglycdn.com/files/a1252435-b897-475d-8396-b81cf003a030/jaririgate.pdf
- https://uploads.strikinglycdn.com/files/d2710971-2ba2-4c73-817f-85a371ff843a/28437210236.pdf
- https://uploads.strikinglycdn.com/files/0906ea77-ac80-4f4d-bec4-11632c2c4159/vadogukexuga.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f8710c21be4e.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f86f418c6c17.pdf
- https://site-1038311.mozfiles.com/files/1038311/93749853632.pdf
- https://site-1043477.mozfiles.com/files/1043477/gidorowakunovilokiwir.pdf
- https://uploads.strikinglycdn.com/files/1eac3d79-c5db-4eed-acb3-55a1f84c3eb9/nojejerav.pdf
- https://uploads.strikinglycdn.com/files/b4e9cbcf-52dc-4b2c-a1aa-47edb177bd23/24954759366.pdf
- https://uploads.strikinglycdn.com/files/18fd5fca-5156-4bea-9305-f11cfcdec8b1/xalapamukowone.pdf
- https://uploads.strikinglycdn.com/files/a6b5a3af-9ea5-4b7d-acee-89126ae382e3/vimoxufo.pdf
- https://uploads.strikinglycdn.com/files/63be2421-673d-4cb7-ad6f-535a776e39fd/loral.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8709fb687ed.pdf
- https://cdn-cms.f-static.net/uploads/4367621/normal_5f874909b6cac.pdf
- https://cdn-cms.f-static.net/uploads/4365553/normal_5f872ea6024af.pdf
- https://cdn-cms.f-static.net/uploads/4366343/normal_5f873c3580233.pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f870554b2223.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038311.mozfiles.com
- site-1043477.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report