MALICIOUS — normal_5f882d784e22b.pdf
MALICIOUS — normal_5f882d784e22b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f2d2fbe8a648df2afe8884e5939e1fb5ff289c724fdc7fdb134fc5fe316dd847 - SHA-1:
21b3af67f330e746149ce172998e8f25bacbea3f - MD5:
243687f7b2a351564464333afd3fb528 - ssdeep:
768:QgGzpDLprVh5RHc7Qu1fn9aH0VcXvNhyZ2IIfQ/4PyeTPMuXX2M2z0ZX0b:9GFPpZ0VGyZcE4aBuXX2M+0ZX0b - TLSH:
T1F3327DF310A3DC8C39879F436D6A25A96189D78C61329764548C3B2DC4BC7BE3E60961 - Submitted as: normal_5f882d784e22b.pdf
- File type: pdf · Size: 45068 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/4c1794a6a4b7.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=camera+v5+lite+pro+apk, https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/4c1794a6a4b7.pdf, https://molisemopum.weebly.com/uploads/1/3/1/4/131437834/memuwom-jegajavupikunaw-sawola.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=camera+v5+lite+pro+apk
- https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/4c1794a6a4b7.pdf
- https://molisemopum.weebly.com/uploads/1/3/1/4/131437834/memuwom-jegajavupikunaw-sawola.pdf
- https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/zuxupabupi.pdf
- https://uploads.strikinglycdn.com/files/a92e8446-f31a-41e8-8a5d-131e8bcef4c9/71439907337.pdf
- https://uploads.strikinglycdn.com/files/a8060025-c601-4f9f-86ee-38cbc2043e8a/29311773787.pdf
- https://uploads.strikinglycdn.com/files/4ad87743-a11d-4eae-8be4-1f23ac10c07b/48283844828.pdf
- https://uploads.strikinglycdn.com/files/cf1c1aa0-ec22-4808-9dc8-e5ee61013589/1773075127.pdf
- https://uploads.strikinglycdn.com/files/d8a34785-ce11-4e87-93e3-d48a326bd18f/67595308817.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f8717eb03495.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f87068315723.pdf
- https://cdn-cms.f-static.net/uploads/4368735/normal_5f87a405ae05b.pdf
- https://cdn-cms.f-static.net/uploads/4367311/normal_5f87710e31f1f.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f870aa45bb53.pdf
- https://uploads.strikinglycdn.com/files/377c56a1-de2e-4b39-bf6c-5c8cadca7321/33520680135.pdf
- https://uploads.strikinglycdn.com/files/038aa7a5-02f7-4532-a956-ecfe07f3750d/xujepiz.pdf
- https://uploads.strikinglycdn.com/files/5cfe2b23-a2d8-4589-bb4b-f4740d9cee20/fidixudedinewanizanigex.pdf
- https://site-1039444.mozfiles.com/files/1039444/gesefukomeropepes.pdf
- https://site-1043910.mozfiles.com/files/1043910/58701816435.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f873ef0dcfcb.pdf
- https://cdn-cms.f-static.net/uploads/4365552/normal_5f872ff33ee87.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- seririgikum.weebly.com
- molisemopum.weebly.com
- wonigebegi.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1039444.mozfiles.com
- site-1043910.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report