MALICIOUS — normal_5f88074ae70d1.pdf
MALICIOUS — normal_5f88074ae70d1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e6ca7912e39ba927ab5441ed879c5181d6561ea6b2e37d73bec1c7b92295d8a7 - SHA-1:
1915c161ac41ecda0b4b208c88721a40d702df60 - MD5:
281bba959a2d0b4396e7bc43fc362115 - ssdeep:
768:RgGzpDYeY1XBJlCwVAL33wCH2790mbfQxjiw4xidkkO6dU:iGFceNwbBsjiw4xLkO6dU - TLSH:
T1E5317CF31097DE8C7A879B036DAA2515248AC78C6132D7A0588C773CD4BCABDBE50D21 - Submitted as: normal_5f88074ae70d1.pdf
- File type: pdf · Size: 41515 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/makotu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=la+cimbali+m27+re+manual+pdf, https://cdn.shopify.com/s/files/1/0487/7261/2262/files/44014060347.pdf, https://cdn.shopify.com/s/files/1/0478/2610/8575/files/mayville_high_school_mi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=la+cimbali+m27+re+manual+pdf
- https://cdn.shopify.com/s/files/1/0487/7261/2262/files/44014060347.pdf
- https://cdn.shopify.com/s/files/1/0478/2610/8575/files/mayville_high_school_mi.pdf
- https://cdn.shopify.com/s/files/1/0438/7074/8827/files/61576145371.pdf
- https://cdn.shopify.com/s/files/1/0433/4977/0395/files/marshall_plan_cartoon.pdf
- https://cdn.shopify.com/s/files/1/0501/1911/4952/files/tapekejebaju.pdf
- https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/makotu.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/pigix.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/roruj-fegedevovelere-zexomojikazi-rewubujelem.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/nojilu.pdf
- https://cdn.shopify.com/s/files/1/0479/2968/8231/files/bupowewipolixowadutusoza.pdf
- https://cdn.shopify.com/s/files/1/0435/6653/0721/files/83295458694.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/7c2eb3c.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/jidimut.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/kezupukono.pdf
- https://vefoxetewezelir.weebly.com/uploads/1/3/1/4/131483279/rixini.pdf
- https://uploads.strikinglycdn.com/files/45cc8555-3657-418e-9ccb-dfb78e98f924/6122595864.pdf
- https://uploads.strikinglycdn.com/files/9e990785-ea30-48c8-8734-768e7bbd7eaa/12678034817.pdf
- https://uploads.strikinglycdn.com/files/b1bfbf06-8afa-44b9-961e-62439121c58a/9249415313.pdf
- https://uploads.strikinglycdn.com/files/2d7bd776-c1c8-48c4-a1c7-ed4c77b84727/lunaripupumusol.pdf
- https://uploads.strikinglycdn.com/files/5dbb4f78-7856-491f-9daf-1ef41c8d6057/35543246605.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- gemaxudemaxepeb.weebly.com
- jiwepurojal.weebly.com
- guwomenod.weebly.com
- megadezatesaram.weebly.com
- viweposedijul.weebly.com
- bedizegoresupa.weebly.com
- vefoxetewezelir.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report