MALICIOUS — normal_5f87daddda2f4.pdf
MALICIOUS — normal_5f87daddda2f4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c8c5055eaaeb24581e3a70412d909fccccdff33a10dd0d8c68da67081de3a051 - SHA-1:
b70e7321c01dba9816442dbfc55aa84dac06e42f - MD5:
23075189416d05bae85ee8596c1f3175 - ssdeep:
1536:HGF6pq1qBh6tzoQA4JIfvuhvmR0iVOsWhbZnO5bg:mF6ph6tzopWIfvuvmRNVORJOu - TLSH:
T188348DF350A7ED8CB98BAF07A9E71059614AD7887032D7A00588775CD47C7FC6E10A61 - Submitted as: normal_5f87daddda2f4.pdf
- File type: pdf · Size: 57490 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7360136.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=camera+360+lite+mod+apk, https://uploads.strikinglycdn.com/files/7d771b46-be07-41aa-a6c2-a97a10fa483d/peker.pdf, https://uploads.strikinglycdn.com/files/7dd79b45-642c-404c-a83a-163453ddb7ca/jopulijepudazoz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=camera+360+lite+mod+apk
- https://uploads.strikinglycdn.com/files/7d771b46-be07-41aa-a6c2-a97a10fa483d/peker.pdf
- https://uploads.strikinglycdn.com/files/7dd79b45-642c-404c-a83a-163453ddb7ca/jopulijepudazoz.pdf
- https://uploads.strikinglycdn.com/files/d990a320-b168-41d4-8976-f24abb7f0689/96058697884.pdf
- https://uploads.strikinglycdn.com/files/64a43729-4f4d-41d0-9670-d5ed0a6123b9/54171066953.pdf
- https://uploads.strikinglycdn.com/files/c4be103d-e126-4136-a66c-c656e3b8d42d/selexuboraluxawo.pdf
- https://uploads.strikinglycdn.com/files/a6ad231d-7faa-406a-ae05-b776ed77ce16/35884459435.pdf
- https://uploads.strikinglycdn.com/files/1e24f8b4-eb52-41b1-be34-255fbb28d83a/46483593916.pdf
- https://uploads.strikinglycdn.com/files/b955e012-f7d5-42e5-afef-19479e0f132a/vizakigamenoxulu.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7360136.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/sodotipa.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/zarifunu_nawila.pdf
- https://mokitigek.weebly.com/uploads/1/3/1/6/131606839/xiwegej.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/gevoderovepiru.pdf
- https://cdn-cms.f-static.net/uploads/4367914/normal_5f87a04897389.pdf
- https://cdn-cms.f-static.net/uploads/4368750/normal_5f87addaf2400.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f87cc9f73357.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f874c2bd4bc2.pdf
- https://site-1039731.mozfiles.com/files/1039731/matonafubuzujokukulo.pdf
- https://site-1042591.mozfiles.com/files/1042591/fudisuweb.pdf
- https://site-1043759.mozfiles.com/files/1043759/economic_order_quantity_eoq.pdf
- https://site-1048476.mozfiles.com/files/1048476/potuzojagixekigugoxel.pdf
- https://site-1036713.mozfiles.com/files/1036713/wuzivijaw.pdf
- https://site-1036972.mozfiles.com/files/1036972/89275436381.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- genigudepa.weebly.com
- jaserasozupog.weebly.com
- vimiwegom.weebly.com
- mokitigek.weebly.com
- jawasolasazilem.weebly.com
- cdn-cms.f-static.net
- site-1039731.mozfiles.com
- site-1042591.mozfiles.com
- site-1043759.mozfiles.com
- site-1048476.mozfiles.com
- site-1036713.mozfiles.com
- site-1036972.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report