MALICIOUS — normal_5f87650c9406c.pdf
MALICIOUS — normal_5f87650c9406c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e63c7ee83b3a1cd2913b8de0c44c0ff6c0333c90ff50f53027e4dc3c5ede7d86 - SHA-1:
569a784a4f3ae54b58ccb68627541a2d906249b2 - MD5:
de8c63aa5e6ba40b0828399c0d7a5131 - ssdeep:
768:PgGzpDjpNMWT7NR3sZ89Nh1NEozo7vxv0bDbRRJcUj:4GF/ptNh1NEOolc7RRJcUj - TLSH:
T1D5306BF35097ED4C7A4F6F039EAA115E618AD3CDA133975044882B2CD0BCAFD2E40A65 - Submitted as: normal_5f87650c9406c.pdf
- File type: pdf · Size: 37276 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://lixaworone.weebly.com/uploads/1/3/1/8/131871871/sopakasumut.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=loris+malaguzzi+libros+pdf, https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/6e5c8a73.pdf, https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=loris+malaguzzi+libros+pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/6e5c8a73.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf
- https://lixaworone.weebly.com/uploads/1/3/1/8/131871871/sopakasumut.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/wovexofek.pdf
- https://vibebivenef.weebly.com/uploads/1/3/1/4/131412032/23dcc5ae3a6204.pdf
- https://uploads.strikinglycdn.com/files/495a08da-bba0-4b25-93b2-6f0921d05167/ziwamugomon.pdf
- https://uploads.strikinglycdn.com/files/7bd42b75-e7a3-4dcf-9cca-e14817ec9498/10184721419.pdf
- https://site-1044026.mozfiles.com/files/1044026/69713924966.pdf
- https://site-1037889.mozfiles.com/files/1037889/setuvakepikizow.pdf
- https://site-1036781.mozfiles.com/files/1036781/fubujigufokemugib.pdf
- https://site-1039393.mozfiles.com/files/1039393/50194901578.pdf
- https://site-1038337.mozfiles.com/files/1038337/zolewiwugusadefiza.pdf
- https://cdn.shopify.com/s/files/1/0266/8966/7243/files/qualified_dividends_and_capital_gain_tax_worksheet_2019.pdf
- https://cdn.shopify.com/s/files/1/0497/4936/0793/files/sectionalism_map_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0484/7357/1482/files/74586087293.pdf
- https://cdn.shopify.com/s/files/1/0435/0679/4651/files/fikixibiluwenijolafotu.pdf
- https://cdn.shopify.com/s/files/1/0497/5368/6180/files/diablo_2_android_2020.pdf
- https://uploads.strikinglycdn.com/files/b649c5f2-2ab4-4f0a-97fa-507b31515456/jotusoxesaketitenarol.pdf
- https://uploads.strikinglycdn.com/files/6f953530-1249-4d2d-99ca-ffb1b1d4af5c/zezedaragelesomatojudanom.pdf
- https://site-1038530.mozfiles.com/files/1038530/87679840623.pdf
- https://site-1036977.mozfiles.com/files/1036977/gevomevefabaz.pdf
- https://site-1040363.mozfiles.com/files/1040363/rowawibimarevezowe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- jufaxexave.weebly.com
- zoxuzuxebexot.weebly.com
- lixaworone.weebly.com
- jawasolasazilem.weebly.com
- vibebivenef.weebly.com
- uploads.strikinglycdn.com
- site-1044026.mozfiles.com
- site-1037889.mozfiles.com
- site-1036781.mozfiles.com
- site-1039393.mozfiles.com
- site-1038337.mozfiles.com
- cdn.shopify.com
- site-1038530.mozfiles.com
- site-1036977.mozfiles.com
- site-1040363.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report