MALICIOUS — normal_5f8717b8db622.pdf
MALICIOUS — normal_5f8717b8db622.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e9a966dfd6e3d7ff1d841d3c428544b29ca3ccfc5bbc4ef06097201fef5959fb - SHA-1:
df7bc28a9c622131eaddf253e0a818c55d1b21c7 - MD5:
384f397a399888fdce6b1de690f9183a - ssdeep:
1536:oGF2pnhNHyNCsAYVYa3ea16dq0JI0icx:FF2pjHyNJqa3ea16dh60z - TLSH:
T16F339FF314E7ED4C7ACBAB03ADAA2A556049D788912697A044CC372DC0BC77E7F10960 - Submitted as: normal_5f8717b8db622.pdf
- File type: pdf · Size: 49628 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/fa4b1fa0-ebce-4109-9344-2d3d67e95441/32049049025.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=torque+value+chart+pdf, https://uploads.strikinglycdn.com/files/97247fb3-adc0-4d87-8dd9-6593b65d7b2b/69187012680.pdf, https://uploads.strikinglycdn.com/files/412f0dad-b035-4ec6-aded-6f56fc634eaf/guweraxezijalisab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=torque+value+chart+pdf
- https://uploads.strikinglycdn.com/files/97247fb3-adc0-4d87-8dd9-6593b65d7b2b/69187012680.pdf
- https://uploads.strikinglycdn.com/files/412f0dad-b035-4ec6-aded-6f56fc634eaf/guweraxezijalisab.pdf
- https://uploads.strikinglycdn.com/files/cd642896-ed29-4d2b-8a22-390f700d3fa5/58562571205.pdf
- https://uploads.strikinglycdn.com/files/fa4b1fa0-ebce-4109-9344-2d3d67e95441/32049049025.pdf
- https://uploads.strikinglycdn.com/files/6fdddd9c-4e05-4023-8f37-0fbf25191308/divekekamot.pdf
- https://uploads.strikinglycdn.com/files/5aa1fd99-e394-44ce-a744-87cb5fc06b0a/puvibinedujebas.pdf
- https://uploads.strikinglycdn.com/files/b3c9114f-aa4b-4e45-97ed-9fdc450fe657/mufobemanogomos.pdf
- https://uploads.strikinglycdn.com/files/c1698723-2ef2-4f5b-8589-647e0ee53464/berejozesakimiz.pdf
- https://uploads.strikinglycdn.com/files/dc5f3d42-66de-4a99-a19b-12fadc5e0c21/fakobemuluzodapen.pdf
- https://cdn.shopify.com/s/files/1/0478/0054/9535/files/32925288974.pdf
- https://cdn.shopify.com/s/files/1/0438/4528/8093/files/sodium_lauroyl_isethionate_cancer.pdf
- https://site-1038431.mozfiles.com/files/1038431/fozivebusepulutewolobada.pdf
- https://site-1040006.mozfiles.com/files/1040006/3201685033.pdf
- https://site-1039649.mozfiles.com/files/1039649/pejet.pdf
- https://site-1040767.mozfiles.com/files/1040767/wuvezibulurururun.pdf
- https://site-1042549.mozfiles.com/files/1042549/34984157932.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/duwivif.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/pejajofedaxevaw_kozadesupuke.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/winepogor.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f87082c4579e.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f8708feae79a.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f87032d7b851.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f87007b1f1d8.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1038431.mozfiles.com
- site-1040006.mozfiles.com
- site-1039649.mozfiles.com
- site-1040767.mozfiles.com
- site-1042549.mozfiles.com
- genigudepa.weebly.com
- guwomenod.weebly.com
- zoxuzuxebexot.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report