MALICIOUS — normal_5f92ed3de7c55.pdf
MALICIOUS — normal_5f92ed3de7c55.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f07df334fd0b917907cd4fa08e2ffb5996fb66970a9972288eb4c23939a936f8 - SHA-1:
a4ebf64c00c664b49c3667fa6c4ca5a1c17b4c9d - MD5:
decc76e52c08b5a5ab53ee2ba7cceab7 - ssdeep:
1536:yGFvvRmBOuvBHn8b0/Nnhq+Hq/OuQkAahgl8:rFvv8OuvBHnK0/3qWqGuQFahp - TLSH:
T1E836AEF340A7ED8C7E8BAB136EF71059948AC78D6132E7A05498776CC5BC2AC3E10951 - Submitted as: normal_5f92ed3de7c55.pdf
- File type: pdf · Size: 64383 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/ff5aa.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.com/123?keyword=penjelasan+uu+perkawinan+pdf, https://rikisuluwujufa.weebly.com/uploads/1/3/1/4/131452938/3799729.pdf, https://birebojutadavom.weebly.com/uploads/1/3/4/3/134342015/2265976.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=penjelasan+uu+perkawinan+pdf
- https://rikisuluwujufa.weebly.com/uploads/1/3/1/4/131452938/3799729.pdf
- https://birebojutadavom.weebly.com/uploads/1/3/4/3/134342015/2265976.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/ff5aa.pdf
- https://jemajodelevo.weebly.com/uploads/1/3/4/3/134394711/molefowadezuli.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/bosilo_ginasesif.pdf
- https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/09809c.pdf
- https://rijizego.weebly.com/uploads/1/3/0/7/130776487/masedagepi.pdf
- https://fidegobopoj.weebly.com/uploads/1/3/2/8/132815019/ranelamegoxogaxigur.pdf
- https://uploads.strikinglycdn.com/files/49e08daf-6b70-4bcd-8bf5-91619f52f3bd/84069996680.pdf
- https://uploads.strikinglycdn.com/files/8cc4a4ae-b1ad-4259-9660-a33b8ca1316b/botil.pdf
- https://uploads.strikinglycdn.com/files/28ba79e7-5f35-48aa-9cf5-ed0925f6bbce/viwoxazagefupem.pdf
- https://s3.amazonaws.com/fibesezati/sugapibizemigodifo.pdf
- https://s3.amazonaws.com/kavitokolezub/wibimadodax.pdf
- https://s3.amazonaws.com/zuguvoxoki/64709892045.pdf
- https://uploads.strikinglycdn.com/files/6ae1db7f-ceb4-46db-a87b-7e442e8784fd/63960703271.pdf
- https://uploads.strikinglycdn.com/files/ea4fcd31-f4d4-446b-9ec0-1feedb9776f9/bizesu.pdf
- https://uploads.strikinglycdn.com/files/0288f8cd-9650-4178-846b-3e49dd607944/ejercicios_packet_tracer_resueltos.pdf
- https://uploads.strikinglycdn.com/files/1ab013c9-f558-44ce-b8d8-2888c2e75c32/4255698887.pdf
- https://uploads.strikinglycdn.com/files/d1f70476-80ae-49e5-b204-6d7d108d4be6/40841275459.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/lixavej_rivutavipulox_vunezikavad_lirumonoguwako.pdf
- https://rajaxamakato.weebly.com/uploads/1/3/2/3/132302926/zonifipifene_bofopifebodupar_semafaxoxovesuw_zafudidajol.pdf
- https://nikoxutaju.weebly.com/uploads/1/3/1/3/131378952/dazemobadititit.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/5396483.pdf
- https://kixatefibav.weebly.com/uploads/1/3/0/7/130776592/matujop.pdf
Embedded domains
- ttraff.com
- rikisuluwujufa.weebly.com
- birebojutadavom.weebly.com
- nogafuku.weebly.com
- jemajodelevo.weebly.com
- mogilifus.weebly.com
- kupugaxome.weebly.com
- rijizego.weebly.com
- fidegobopoj.weebly.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- jakedekokobara.weebly.com
- rajaxamakato.weebly.com
- nikoxutaju.weebly.com
- jufaxexave.weebly.com
- kixatefibav.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report