MALICIOUS — normal_5f8e19c2f2838.pdf
MALICIOUS — normal_5f8e19c2f2838.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e8078b9cd6431c051d8d408fad265c0410997e754ef89f4eaf75dbaf56a5caca - SHA-1:
3c93266ff04173b872c2ebace36e280c512fd4c1 - MD5:
6b2f520a53c034586a776942f57989ae - ssdeep:
1536:/GFQeVUWQWwXW7AIsdKcwNlQf30clPp0UV:uFQer0gAIssVNlO0ov - TLSH:
T19F349EF35097EC4C7E8A9B839DBB2659144AC74CA23B9750448CB32CD1BCAAE7F14461 - Submitted as: normal_5f8e19c2f2838.pdf
- File type: pdf · Size: 54663 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://finiluxexolije.weebly.com/uploads/1/3/1/8/131856594/6001731.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.cc/123?keyword=house+builder+games+apk, https://cdn.shopify.com/s/files/1/0501/8723/9597/files/zabubepizi.pdf, https://cdn.shopify.com/s/files/1/0439/0649/8728/files/rawifezuka.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=house+builder+games+apk
- https://cdn.shopify.com/s/files/1/0501/8723/9597/files/zabubepizi.pdf
- https://cdn.shopify.com/s/files/1/0439/0649/8728/files/rawifezuka.pdf
- https://cdn.shopify.com/s/files/1/0497/6961/1418/files/alternative_to_google_maps_api_android.pdf
- https://cdn.shopify.com/s/files/1/0430/4430/7098/files/88334949033.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/mifenadubuj-gemaz-biresilogi-xalewuzejo.pdf
- https://finiluxexolije.weebly.com/uploads/1/3/1/8/131856594/6001731.pdf
- https://zevigetadafuwun.weebly.com/uploads/1/3/0/9/130969942/d1fef4448b24de.pdf
- https://zeteparikimifol.weebly.com/uploads/1/3/1/6/131637109/mexafijavewurir.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/saloviganepepi.pdf
- https://uploads.strikinglycdn.com/files/90270432-79d1-453b-a0b0-0258b5e19911/kimber_lee_head_bobbers.pdf
- https://uploads.strikinglycdn.com/files/e99c9389-94dd-4a36-bac6-cbe78b1c6360/79564476519.pdf
- https://uploads.strikinglycdn.com/files/11bc30a3-3003-45d9-b68b-82c3a7bd2293/bixejijedalinema.pdf
- https://uploads.strikinglycdn.com/files/522b0709-b158-49e6-b2a2-487392725106/47845509642.pdf
- https://uploads.strikinglycdn.com/files/dda17eaa-4719-4a5e-8ef4-813ce93ccc84/95671243796.pdf
- https://cdn-cms.f-static.net/uploads/4369768/normal_5f87ff31d423d.pdf
- https://cdn-cms.f-static.net/uploads/4385612/normal_5f8e0a023040d.pdf
- https://cdn-cms.f-static.net/uploads/4368949/normal_5f879fbdd9b06.pdf
- https://cdn-cms.f-static.net/uploads/4368958/normal_5f8dfec3dccfa.pdf
- https://cdn.shopify.com/s/files/1/0494/3672/1319/files/desunabefanusewoxup.pdf
- https://cdn.shopify.com/s/files/1/0437/6631/7205/files/relative_atomic_mass_worksheet_answers.pdf
- https://uploads.strikinglycdn.com/files/d033394e-f107-4476-81b2-61b2edf5aab5/19172669279.pdf
- https://uploads.strikinglycdn.com/files/c4dbb12a-5cbc-4284-870d-ba6b2279d92d/74662301723.pdf
- https://uploads.strikinglycdn.com/files/be2b860d-0360-46d1-b9c2-b314b69c2411/statistics_for_dummies.pdf
- https://uploads.strikinglycdn.com/files/5dabe9dd-a53b-473b-ad12-b6f6a18b9c85/63856586110.pdf
Embedded domains
- ttraff.cc
- cdn.shopify.com
- wepugimi.weebly.com
- finiluxexolije.weebly.com
- zevigetadafuwun.weebly.com
- zeteparikimifol.weebly.com
- natizupasa.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report