MALICIOUS — normal_5f870da335115.pdf
MALICIOUS — normal_5f870da335115.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f3ca35e0fc9cd115100df3cfe6e9393429c6f56c71909fb2fbb7d227f9419e72 - SHA-1:
681c80f4fbb34a1bc821e429a9d97c1f39db5c8e - MD5:
4f1e04623b818d2bc77c8c0c2537964a - ssdeep:
768:mgGzpDceCnRFxzVQC1Bo9v+g3dro0lHYPXvRAfovOzXEyognlkRlX45qj:zGFweORrCSF4c0l4BJeXPlkXX45qj - TLSH:
T1D235AFF320E7DC4C7AC7AB07ADEA2115528ADB483032A7684588772CC5BC77E3D60A51 - Submitted as: normal_5f870da335115.pdf
- File type: pdf · Size: 59529 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/sefaritonos-nukivafeka-retisebop-regaxumex.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=cromatografia+de+gases+y+gases+masas+pdf, https://uploads.strikinglycdn.com/files/5b91817e-edc3-4d0f-b188-d83fc5dae0bf/23935011282.pdf, https://uploads.strikinglycdn.com/files/bac53db0-fc0e-4a9a-84f7-e01b1eb30213/nekebalisidizezavokujanel.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=cromatografia+de+gases+y+gases+masas+pdf
- https://uploads.strikinglycdn.com/files/5b91817e-edc3-4d0f-b188-d83fc5dae0bf/23935011282.pdf
- https://uploads.strikinglycdn.com/files/bac53db0-fc0e-4a9a-84f7-e01b1eb30213/nekebalisidizezavokujanel.pdf
- https://uploads.strikinglycdn.com/files/03ea2d16-7853-49fe-bfcd-fc9b4fac6bc1/musopisidufivokorigajas.pdf
- https://uploads.strikinglycdn.com/files/5ba89bd3-8d30-4745-a8c2-681c43fd14d8/tujutikonosovuwodo.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/sefaritonos-nukivafeka-retisebop-regaxumex.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/busixakowun_zefisuni.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/dekefomivupe-kovak-talajonipa-fedebiraroz.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/nukunuraki.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/vunud.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/lanadez.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zuvefusu_tewojawowebav.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/4867245.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/a8401ec7a9859.pdf
- https://site-1037000.mozfiles.com/files/1037000/3821838808.pdf
- https://site-1044024.mozfiles.com/files/1044024/folagilomigopovef.pdf
- https://site-1039437.mozfiles.com/files/1039437/papikupusasena.pdf
- https://site-1036902.mozfiles.com/files/1036902/7789031911.pdf
- https://site-1044472.mozfiles.com/files/1044472/vovodawuzulijurozurex.pdf
- https://uploads.strikinglycdn.com/files/552983ae-507e-467f-9003-54138e9f9c8b/wafapulebedosidifufok.pdf
- https://uploads.strikinglycdn.com/files/6e9a1e3e-ed0a-4aa7-92af-f77cc84c5c71/kirodaxes.pdf
- https://uploads.strikinglycdn.com/files/5297925d-8474-4560-894a-8ef717aef1c1/31893669728.pdf
- https://uploads.strikinglycdn.com/files/e61ada05-06a4-462f-b606-295d0bdea624/xegezeduwawit.pdf
- https://uploads.strikinglycdn.com/files/d39a14d9-c97e-4a90-a720-c2993a67e865/dexiwidakanimev.pdf
- https://uploads.strikinglycdn.com/files/f5275106-ab9d-45ef-bc00-a6a6e74a1ce3/wadul.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- jawasolasazilem.weebly.com
- jakedekokobara.weebly.com
- zoxuzuxebexot.weebly.com
- guwomenod.weebly.com
- vuxozajuje.weebly.com
- gimejexoxixaza.weebly.com
- fijojonibiw.weebly.com
- site-1037000.mozfiles.com
- site-1044024.mozfiles.com
- site-1039437.mozfiles.com
- site-1036902.mozfiles.com
- site-1044472.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report