MALICIOUS — normal_5fa79d4abbf9c.pdf
MALICIOUS — normal_5fa79d4abbf9c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c90b89ec05537d2f2f28702b471475ef884cf56473c16441934f851ed07bd728 - SHA-1:
2cee580a180fbd8119c5eb174c8c1f04ce33db14 - MD5:
74df07e6cb70cf2f62b15f77ca54db68 - ssdeep:
768:DgGzpDdxuF3FdHbyec9qz/tOfp/qehtqXrK+A3qOBDJpWXsPWV28:8GFZwk9cs4XrYXpWXsPW08 - TLSH:
T13B31AFF350A7ED4C2A86AB03A9B510995246D78E6132CBA015CCB7BCC57C6BC7E40E71 - Submitted as: normal_5fa79d4abbf9c.pdf
- File type: pdf · Size: 42671 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafficel.ru/123?keyword=the+thane+of+cawdor+is+executed+for+being+a, https://fewevivib.weebly.com/uploads/1/3/0/8/130813821/5653360.pdf, https://ruregeriwak.weebly.com/uploads/1/3/4/6/134666462/zitexutujifu_vowap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/123?keyword=the+thane+of+cawdor+is+executed+for+being+a
- https://fewevivib.weebly.com/uploads/1/3/0/8/130813821/5653360.pdf
- https://ruregeriwak.weebly.com/uploads/1/3/4/6/134666462/zitexutujifu_vowap.pdf
- https://tejubodefi.weebly.com/uploads/1/3/4/3/134351051/xamopovape.pdf
- https://uploads.strikinglycdn.com/files/e55c823c-ea2c-4446-a367-433ce7f1348b/de_estrella_de_las_botas_metra_surik.pdf
- https://uploads.strikinglycdn.com/files/2b0248d1-d22b-42f5-afb4-41025d6666ee/ratufimimedesuwetes.pdf
- https://s3.amazonaws.com/jazuravazaguz/types_of_inventory_vouchers_in_tally_erp_9.pdf
- https://suvejuxib.weebly.com/uploads/1/3/4/3/134380783/6235826.pdf
- https://uploads.strikinglycdn.com/files/2eabc079-1467-4e37-a62a-733b7d991b82/dental_instrument_names_and_functions.pdf
- https://uploads.strikinglycdn.com/files/b05df22b-e648-4629-885d-28a9c06e3419/16254772046.pdf
- https://s3.amazonaws.com/leguvefu/astm_a53_free_download.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- fewevivib.weebly.com
- ruregeriwak.weebly.com
- tejubodefi.weebly.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- suvejuxib.weebly.com
- jawasolasazilem.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report