MALICIOUS — normal_5f8a3fa63c65c.pdf
MALICIOUS — normal_5f8a3fa63c65c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d2ef5eae44cb09c8535de3550924071a79e2d52f883834eaaf62d6ffc591a1ce - SHA-1:
2f084270264088443cc7f3d032aafc10244b5c7e - MD5:
cc2dc8163b70255e50b8e00339a78ba6 - ssdeep:
768:xgGzpD8pf7gKjAle4PjmRHez8F1jZVPiKtXT4YTcKqlM/Cpxr+JAq0z4PbLtC:CGFIplZZtj4sD8M/wxr+/0z4PdC - TLSH:
T1F7318DF3509BDD4D3A839B937CA7126AA489C38CA1379790198C772CD6BC6BD6F10910 - Submitted as: normal_5f8a3fa63c65c.pdf
- File type: pdf · Size: 42487 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tibiwurab.weebly.com/uploads/1/3/2/6/132695994/29ca61ee3bb.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=libro+dieta+del+metabolismo+acelerado+pdf+online, https://jenafowumavadas.weebly.com/uploads/1/3/1/4/131437472/wuxomewutefu-leferul-jojimon-veliseg.pdf, https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/5babc5cf9fef701.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=libro+dieta+del+metabolismo+acelerado+pdf+online
- https://jenafowumavadas.weebly.com/uploads/1/3/1/4/131437472/wuxomewutefu-leferul-jojimon-veliseg.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/5babc5cf9fef701.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/lozazokoxusa.pdf
- https://tibiwurab.weebly.com/uploads/1/3/2/6/132695994/29ca61ee3bb.pdf
- https://cdn.shopify.com/s/files/1/0440/2269/4046/files/xisuzinoxanoxuzozibugi.pdf
- https://cdn-cms.f-static.net/uploads/4374199/normal_5f89d353b3a42.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f86fa69a3699.pdf
- https://cdn-cms.f-static.net/uploads/4373522/normal_5f8a262401607.pdf
- https://cdn-cms.f-static.net/uploads/4373768/normal_5f8a1c08bcd89.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f892e1da8d94.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f8717d44cd10.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f86fbd91b5ce.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f889599c2ae6.pdf
- https://cdn-cms.f-static.net/uploads/4374976/normal_5f89338438c99.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f8750979df0f.pdf
- https://cdn-cms.f-static.net/uploads/4370307/normal_5f8a3f910892a.pdf
- https://cdn.shopify.com/s/files/1/0501/8697/7441/files/luzun.pdf
- https://cdn.shopify.com/s/files/1/0479/0062/3014/files/conversations_with_god_book_2_free.pdf
- https://cdn.shopify.com/s/files/1/0266/8232/7221/files/erasing_hell_francis_chan.pdf
- https://cdn.shopify.com/s/files/1/0445/7735/8024/files/el_cayado_del_pastor_1er_trimestre.pdf
- https://cdn.shopify.com/s/files/1/0428/8462/8633/files/marosowikavu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- jenafowumavadas.weebly.com
- dapujevubo.weebly.com
- vozunutav.weebly.com
- tibiwurab.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report