MALICIOUS — normal_5f8af4772ac72.pdf
MALICIOUS — normal_5f8af4772ac72.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ebb134debdee04971c3255d358a8bbb6e43e3cb5f0e497897e9b7afceaa3a64c - SHA-1:
0c232ab8757adc3fd204f62c9848fe1ff851d547 - MD5:
18b3665d15fa5284e9bdb147a3a08157 - ssdeep:
1536:cGFFp2XcDZAwwR4nj94E2+SREezPuWWOpZZubGa:5FFpTRbR4tPvWOnM7 - TLSH:
T16536BFF3A097FC8C7A4B6B476EA7116A614AD7C82036A750548C772DD4BC6BE3E00B41 - Submitted as: normal_5f8af4772ac72.pdf
- File type: pdf · Size: 63861 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/regamafizesoxidiwed.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=android+manifest+intent+data, https://cdn.shopify.com/s/files/1/0434/7900/7384/files/the_higher_learning_in_america.pdf, https://cdn.shopify.com/s/files/1/0494/1280/0679/files/85648227425.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=android+manifest+intent+data
- https://cdn.shopify.com/s/files/1/0434/7900/7384/files/the_higher_learning_in_america.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/phone_number_unknown_in_android_status.pdf
- https://cdn.shopify.com/s/files/1/0494/1280/0679/files/85648227425.pdf
- https://cdn.shopify.com/s/files/1/0495/4593/7048/files/map_of_georgetown_university_hospital.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/9cf4a4513dfa5.pdf
- https://kidunaxu.weebly.com/uploads/1/3/1/4/131437100/a2820.pdf
- https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/regamafizesoxidiwed.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/4333548.pdf
- https://funiwulew.weebly.com/uploads/1/3/2/8/132814073/7973492.pdf
- https://uploads.strikinglycdn.com/files/b450ca55-6711-45c0-b32a-031632356900/sapebal.pdf
- https://uploads.strikinglycdn.com/files/f2b65309-14f6-427d-a5ac-48deca5d1516/pedivevogevadajibajekoxel.pdf
- https://uploads.strikinglycdn.com/files/4e3ee5b2-bfa5-4926-aa93-f32251eaf728/gawebe.pdf
- https://nurekagenarufab.weebly.com/uploads/1/3/1/6/131636906/134175.pdf
- https://mufalugibesenu.weebly.com/uploads/1/3/1/4/131453255/da254ab8415.pdf
- https://buxivadoga.weebly.com/uploads/1/3/0/7/130740323/7911124.pdf
- https://cdn.shopify.com/s/files/1/0429/8155/6375/files/hp_virtual_connect_flex-10_cookbook.pdf
- https://cdn.shopify.com/s/files/1/0437/1261/0457/files/85256951303.pdf
- https://cdn.shopify.com/s/files/1/0494/0270/8135/files/6360284235.pdf
- https://cdn.shopify.com/s/files/1/0497/5198/2233/files/automotive_smoke_machine_rental.pdf
- https://cdn.shopify.com/s/files/1/0492/4692/9052/files/star_wars_dark_disciple_download.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/kezedivalo-bolumukejufufik.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/3e75a4e696b2f2d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- juragubiv.weebly.com
- kidunaxu.weebly.com
- nukevokisoget.weebly.com
- wepugimi.weebly.com
- funiwulew.weebly.com
- uploads.strikinglycdn.com
- nurekagenarufab.weebly.com
- mufalugibesenu.weebly.com
- buxivadoga.weebly.com
- dimaxafazeza.weebly.com
- genigudepa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report