MALICIOUS — normal_5f875629cb4b6.pdf
MALICIOUS — normal_5f875629cb4b6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
da7a8f37b79a067e4b2b9d8b481f540dbddd3d70baa67cde442bcee42a6fd5c1 - SHA-1:
5377eb3753832a3ccbe517d3683c7c26729018b1 - MD5:
5a049b1009cad0a753bb9fa1e0e90701 - ssdeep:
768:cgGzpDBprWjCvBlCcx/SruK0T7MZ1lqVmH2l3wN0pGtkwgu54VmIqgZfvanMX6M8:5GFVpr+nq62l3i0ctkwgu5vu3anMX6M8 - TLSH:
T14F328CF710D7ED8C3A8B9B13ACAB29A55489C7496137DB90444CBB2CD4BC67DAF10860 - Submitted as: normal_5f875629cb4b6.pdf
- File type: pdf · Size: 45161 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/987b21c6b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=green+smoothie+revolution+pdf, https://uploads.strikinglycdn.com/files/cb8d2f24-cd3e-4927-b6d5-5ae0dde53be7/gurojonitavunewor.pdf, https://uploads.strikinglycdn.com/files/fe33eeec-c2ab-4783-98fe-4ae359fa2029/56466922033.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=green+smoothie+revolution+pdf
- https://uploads.strikinglycdn.com/files/cb8d2f24-cd3e-4927-b6d5-5ae0dde53be7/gurojonitavunewor.pdf
- https://uploads.strikinglycdn.com/files/fe33eeec-c2ab-4783-98fe-4ae359fa2029/56466922033.pdf
- https://uploads.strikinglycdn.com/files/de11fc6b-11ec-49d1-aeeb-1694b03dd2ea/nuwebatororotete.pdf
- https://zuwumepegowivos.weebly.com/uploads/1/3/1/0/131069935/vetuwexirara.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/987b21c6b.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/a7b88.pdf
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/9293837.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/ee3d484850ba95e.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f86f8249ad86.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f86f647a422d.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f874b0d05c80.pdf
- https://cdn.shopify.com/s/files/1/0500/3336/1045/files/edgar_morin_el_metodo_5.pdf
- https://cdn.shopify.com/s/files/1/0499/3413/9546/files/bigo_live_hack_diamond_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0435/7488/6563/files/wemuwiporele.pdf
- https://cdn.shopify.com/s/files/1/0497/3890/7809/files/84488842910.pdf
- https://cdn-cms.f-static.net/uploads/4366627/normal_5f872899342b8.pdf
- https://cdn-cms.f-static.net/uploads/4365553/normal_5f8707334c4fe.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f87100b94ebb.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f870ec1ba015.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f86faf173f8f.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bewoti.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dbbd04.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/bizerokiva.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/lemebakagur.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- zuwumepegowivos.weebly.com
- gimejexoxixaza.weebly.com
- gevafitasib.weebly.com
- vekejuritikoj.weebly.com
- babikovinemixe.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- vuxozajuje.weebly.com
- bedizegoresupa.weebly.com
- wepugimi.weebly.com
- boguvetasitob.weebly.com
- juragubiv.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report