MALICIOUS — normal_5f87a94210027.pdf
MALICIOUS — normal_5f87a94210027.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
edc4b7ae3051a61f2c77acc2c171de0f280ec67bc4fbcfb9687a7c2bfaec3879 - SHA-1:
62141f021645f17215b157bf8a5317a1c11cf6dc - MD5:
fef7b36b69b9bcdfd511bd43b90a013b - ssdeep:
768:AgGzpDBp+qzmnOv6XJARxZZdNy0k4MjXW5c3/5+6FLaP0m0Jb64T8YZHjwg32SD7:NGF1p/zNyzjXNR9s30Jb64f5GU7 - TLSH:
T11A338EF3509BEC8C7A8F9F03ADEB11AD914AD78970329790849C772CD17C9AD6E00961 - Submitted as: normal_5f87a94210027.pdf
- File type: pdf · Size: 49090 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/gedetu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=arduino+mega+sensor+shield+v2.0+manual, https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/gedetu.pdf, https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/3212089.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=arduino+mega+sensor+shield+v2.0+manual
- https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/gedetu.pdf
- https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/3212089.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/vunud.pdf
- https://cdn.shopify.com/s/files/1/0495/9843/1381/files/how_i_met_your_mother_lily_tattoo.pdf
- https://cdn.shopify.com/s/files/1/0435/0446/8134/files/angel_and_devil_costumes_for_adults.pdf
- https://cdn.shopify.com/s/files/1/0433/9151/6839/files/f2p_ranged_pure_guide.pdf
- https://cdn.shopify.com/s/files/1/0437/6530/1400/files/vudaxosexeda.pdf
- https://cdn.shopify.com/s/files/1/0504/6684/8933/files/zecharia_sitchin_libros_gratis.pdf
- https://site-1038837.mozfiles.com/files/1038837/sesunuzifo.pdf
- https://site-1037202.mozfiles.com/files/1037202/jofubunivadug.pdf
- https://site-1036894.mozfiles.com/files/1036894/xowajawuwuvilizosinirag.pdf
- https://site-1040213.mozfiles.com/files/1040213/27802481925.pdf
- https://site-1038558.mozfiles.com/files/1038558/39289483776.pdf
- https://cdn.shopify.com/s/files/1/0482/8486/0578/files/bactec_fx_user_manual.pdf
- https://cdn.shopify.com/s/files/1/0502/9593/1045/files/ana_mara_polvorosa_edad.pdf
- https://cdn.shopify.com/s/files/1/0434/3290/2806/files/suraf.pdf
- https://cdn.shopify.com/s/files/1/0500/1153/7568/files/gordons_wine_bar_london_tripadvisor.pdf
- https://cdn.shopify.com/s/files/1/0436/9979/8166/files/midland_hh54_manual.pdf
- https://uploads.strikinglycdn.com/files/660a1915-8556-4060-a5d0-9ac0b4a412ee/6217519136.pdf
- https://uploads.strikinglycdn.com/files/68a10027-5eee-4cf7-ae33-7ada8b9f043f/xemugujakozug.pdf
- https://uploads.strikinglycdn.com/files/2f1b46f4-d9d8-4170-b49b-92fb2eb25db9/mitazisojanewe.pdf
- https://uploads.strikinglycdn.com/files/7d9a479b-558e-4620-9f0c-4d466510c4f5/79350801476.pdf
- https://uploads.strikinglycdn.com/files/fdd84cb3-0bf9-4677-bde8-56c1d8db320b/winududerazisununowude.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- viwuwobigoku.weebly.com
- gazesomudari.weebly.com
- vuxozajuje.weebly.com
- cdn.shopify.com
- site-1038837.mozfiles.com
- site-1037202.mozfiles.com
- site-1036894.mozfiles.com
- site-1040213.mozfiles.com
- site-1038558.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report