MALICIOUS — normal_5f89c2b26f27a.pdf
MALICIOUS — normal_5f89c2b26f27a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d0657b46499fa920faed14a8a8bce94dd35fde5d8c43a63afa7601b5a986a7d7 - SHA-1:
4830a16eed7fdc60324844976f33b51a60943ccf - MD5:
2a13dc53f3b902950467d115f3ef3633 - ssdeep:
1536:wGFBpM4AvyyDyohUEvOVZ0oIBx1+7xJtf1hVU+yW4772mSZ:9FBpM/yoWWOVZRITw73fXU++7c - TLSH:
T145369EF35197ED8C7A8B6B03ADA705A8614AD78C3137E660548C676CC4BCAFD7E10A10 - Submitted as: normal_5f89c2b26f27a.pdf
- File type: pdf · Size: 64732 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/1c327083-332a-4fdc-9b81-811b4d0246fc/39997703099.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.link/123?keyword=spoken+english+tamil+pdf+free+download, https://cdn.shopify.com/s/files/1/0476/7213/1750/files/bemepulukelasebinup.pdf, https://cdn.shopify.com/s/files/1/0484/8461/4299/files/fuzig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=spoken+english+tamil+pdf+free+download
- https://cdn.shopify.com/s/files/1/0476/7213/1750/files/bemepulukelasebinup.pdf
- https://cdn.shopify.com/s/files/1/0434/6734/1981/files/scurlock_elementary_school_raeford_nc.pdf
- https://cdn.shopify.com/s/files/1/0484/8461/4299/files/fuzig.pdf
- https://cdn.shopify.com/s/files/1/0440/2295/6197/files/hay_ahi_ay_rae.pdf
- https://cdn.shopify.com/s/files/1/0497/9248/3490/files/jizazovisewemupo.pdf
- https://jikolugoxolij.weebly.com/uploads/1/3/1/3/131379047/2232836.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ramugimexixepaba.pdf
- https://vozutadisifik.weebly.com/uploads/1/3/1/4/131483249/662261.pdf
- https://tumovapexawezan.weebly.com/uploads/1/3/1/3/131398362/6374287.pdf
- https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/808585.pdf
- https://uploads.strikinglycdn.com/files/99d0e1b1-2d3a-4a3b-8aae-ddea1054bbf6/dekevo.pdf
- https://uploads.strikinglycdn.com/files/c6d1a053-ed92-45b2-ab66-7f09633dcaea/32854402549.pdf
- https://uploads.strikinglycdn.com/files/1c327083-332a-4fdc-9b81-811b4d0246fc/39997703099.pdf
- https://uploads.strikinglycdn.com/files/119012f1-eacf-4ce3-823f-9ccce5000577/zimonemunena.pdf
- https://uploads.strikinglycdn.com/files/3d32193d-4e9c-4084-9447-9494800bbf73/55800101319.pdf
- https://uploads.strikinglycdn.com/files/074de080-ab48-434a-b132-fe83c5728ec9/zitewisuzaxasotinitaxulur.pdf
- https://uploads.strikinglycdn.com/files/42817d69-e75e-4758-818d-de14660d812c/77773176183.pdf
- https://uploads.strikinglycdn.com/files/c20b845e-3b39-4020-8827-67fa1daeccc1/silixoguwufakol.pdf
- https://uploads.strikinglycdn.com/files/70edc734-d8ff-46b5-8d3d-fee824513590/85318521672.pdf
- https://uploads.strikinglycdn.com/files/971a2958-4884-496e-8db9-a4beeac55b9b/sezujokelinuzujedazubosig.pdf
- https://uploads.strikinglycdn.com/files/4bb5265f-803c-469b-b573-9c37450f3add/35851864047.pdf
- https://uploads.strikinglycdn.com/files/8c19ef3c-1b56-4214-816e-eaa1314f4451/zedefemuwujov.pdf
- https://uploads.strikinglycdn.com/files/50d61783-2058-4e6b-8bfe-a4d34c99c394/ledewimorewadapexaneraxup.pdf
- https://uploads.strikinglycdn.com/files/b0c09bf2-b1be-4bac-a116-66426804c1cd/xidabaviminelimejuki.pdf
Embedded domains
- ttraff.link
- cdn.shopify.com
- jikolugoxolij.weebly.com
- guwomenod.weebly.com
- vozutadisifik.weebly.com
- tumovapexawezan.weebly.com
- vikumeniwexawud.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report