MALICIOUS — normal_5f8ebe3d64e5b.pdf
MALICIOUS — normal_5f8ebe3d64e5b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d37af5ebd99cd7e3176e182fd3f67885b96d5a57cc4889a427e94fb7a6e9b8ff - SHA-1:
14214fd2f82d3f13d6fcb33f868b61e959ff2258 - MD5:
a39bb7133e96ff61b44286fb06d3712e - ssdeep:
768:igGzpDgpFB8+ysZhgzjyWHTe7nANIMdB22F8L0nHfwE/9+4VTnJs7DQFKdFZ+S/9:/GF8pFu+Epn/wE/9+uTJsIXwylA - TLSH:
T145328DF71097ED4D7B8B9B53AEAA2519108DC34DA132D720858C672DD4BCABE7F10850 - Submitted as: normal_5f8ebe3d64e5b.pdf
- File type: pdf · Size: 45133 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gidixelasulam.weebly.com/uploads/1/3/0/7/130739099/0d5d637.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.cc/123?keyword=mothercare+journey+washing+instructions, https://gidixelasulam.weebly.com/uploads/1/3/0/7/130739099/0d5d637.pdf, https://rajaxamakato.weebly.com/uploads/1/3/2/3/132302926/kixefi_xonobokabo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=mothercare+journey+washing+instructions
- https://gidixelasulam.weebly.com/uploads/1/3/0/7/130739099/0d5d637.pdf
- https://rajaxamakato.weebly.com/uploads/1/3/2/3/132302926/kixefi_xonobokabo.pdf
- https://femitinekabel.weebly.com/uploads/1/3/1/4/131437683/0e7eeda.pdf
- https://uploads.strikinglycdn.com/files/a341b82c-bc6a-47ed-a6ee-4772ff5fb559/60687924505.pdf
- https://uploads.strikinglycdn.com/files/8d5539be-83f9-4ab1-b6cf-7b7173c957f9/93314445351.pdf
- https://uploads.strikinglycdn.com/files/d69cc9a6-facf-4dcd-816d-db6ba9472122/73386211112.pdf
- https://uploads.strikinglycdn.com/files/492c9193-53b2-4f07-bea8-d5c7500f6e81/67291754354.pdf
- https://uploads.strikinglycdn.com/files/f566305f-ff6c-4abe-aedd-30fa53f78e36/33449727555.pdf
- https://uploads.strikinglycdn.com/files/1e024c1c-80a7-4f99-b884-1ea2d59f9567/25399161299.pdf
- https://uploads.strikinglycdn.com/files/0c374287-7e24-45ee-8cc3-caba26da4671/38672741541.pdf
- https://uploads.strikinglycdn.com/files/d1a52721-4d97-45a9-962b-16298a75f590/34817772985.pdf
- https://uploads.strikinglycdn.com/files/f62fe9d0-12ab-49fd-9496-21a130305d33/85502582059.pdf
- https://uploads.strikinglycdn.com/files/534221c3-e3ca-4190-a84d-2f20eba56785/rukibirosadir.pdf
- https://cdn.shopify.com/s/files/1/0502/1155/3473/files/75000767439.pdf
- https://cdn.shopify.com/s/files/1/0500/4751/6835/files/wakupaxowud.pdf
- https://cdn.shopify.com/s/files/1/0483/7847/8743/files/austin_healey_3000_for_sale_usa.pdf
- https://cdn.shopify.com/s/files/1/0477/3029/4940/files/73717903108.pdf
- https://cdn.shopify.com/s/files/1/0266/7675/6669/files/aircraft_structures_for_engineering_students_solution_manual.pdf
- https://cdn.shopify.com/s/files/1/0433/3459/8809/files/12021845933.pdf
- https://cdn.shopify.com/s/files/1/0437/8797/6864/files/banjo_kazooie_jinjonator.pdf
- https://cdn.shopify.com/s/files/1/0498/3413/1655/files/26248881087.pdf
- https://cdn.shopify.com/s/files/1/0439/1731/2152/files/question_words_test.pdf
- https://cdn.shopify.com/s/files/1/0268/8394/8740/files/7291295345.pdf
- https://cdn-cms.f-static.net/uploads/4376127/normal_5f8be69fd74a1.pdf
Embedded domains
- ttraff.cc
- gidixelasulam.weebly.com
- rajaxamakato.weebly.com
- femitinekabel.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report