MALICIOUS — normal_5f87129fa3655.pdf
MALICIOUS — normal_5f87129fa3655.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f942b69c5d65835dac458fce7e3b957f3dd33035d39f4b802345eee6b7858489 - SHA-1:
edfe3526b97b13d3a8452e02e30105e34f6b972a - MD5:
3fb7d7697c37dbf5c9b0dbc086f4aa20 - ssdeep:
768:magGzpDEp/i3YUvzEJ+FN3ejLeMVdNpmG+s2+c61cNWg8QpMB9Xzs+:EGFwpq3nvhX6LmrHNWgh8js+ - TLSH:
T11A328FF350A7ED4C7A8B9B079DF60199544AC7496032E6A0448C7B2CD4BCEFE7E21A11 - Submitted as: normal_5f87129fa3655.pdf
- File type: pdf · Size: 44670 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/64614d97-c7ce-4fca-8227-58016ae273c1/suguliwenefokole.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/123?keyword=download+rockstar+ringtone+for+android, https://uploads.strikinglycdn.com/files/fed3b1b6-fa11-49f4-8f94-e9f7e77bc51f/9620816876.pdf, https://uploads.strikinglycdn.com/files/64614d97-c7ce-4fca-8227-58016ae273c1/suguliwenefokole.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=download+rockstar+ringtone+for+android
- https://uploads.strikinglycdn.com/files/fed3b1b6-fa11-49f4-8f94-e9f7e77bc51f/9620816876.pdf
- https://uploads.strikinglycdn.com/files/64614d97-c7ce-4fca-8227-58016ae273c1/suguliwenefokole.pdf
- https://uploads.strikinglycdn.com/files/acaf77f9-d851-4750-8a39-669ac2938b4d/63684555946.pdf
- https://uploads.strikinglycdn.com/files/5e44dc2d-5f28-40b9-9227-ace06833494e/61115784944.pdf
- https://uploads.strikinglycdn.com/files/43189879-1746-41a6-b6be-c18b49f616ee/21365915059.pdf
- https://cdn.shopify.com/s/files/1/0438/4056/9509/files/clinical_emergency_medicine.pdf
- https://uploads.strikinglycdn.com/files/8bec640f-1a90-4364-9b90-7ba95c0b22a6/katutupoxiwos.pdf
- https://uploads.strikinglycdn.com/files/6500e778-f356-4a6c-b42b-3799f21a6bc2/saxogugawozekakanepevumaf.pdf
- https://uploads.strikinglycdn.com/files/0a34eb89-793a-4582-8f60-989600e0c78d/winunasedizumidegasakuf.pdf
- https://cdn.shopify.com/s/files/1/0488/0098/9349/files/xupipijepawigiluvuzuzaxev.pdf
- https://cdn.shopify.com/s/files/1/0486/4671/7608/files/47839182642.pdf
- https://cdn.shopify.com/s/files/1/0431/8543/8883/files/app_wifi_scanner_android.pdf
- https://site-1038429.mozfiles.com/files/1038429/12382989529.pdf
- https://site-1044113.mozfiles.com/files/1044113/zibozizezoda.pdf
- https://site-1048226.mozfiles.com/files/1048226/98162709342.pdf
- https://site-1039740.mozfiles.com/files/1039740/tuvapapodulu.pdf
- https://site-1039294.mozfiles.com/files/1039294/gejerobisafotolagamiwowo.pdf
- https://uploads.strikinglycdn.com/files/35a90589-ecfb-4199-ad27-0460abe76fbe/sokuwigedapo.pdf
- https://uploads.strikinglycdn.com/files/9005551d-25a6-49e5-b1f9-1f57ea377a20/sozilazelilitijuliwo.pdf
- https://uploads.strikinglycdn.com/files/8ce86512-440a-454c-8b0e-d94161155cd3/35203672678.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1038429.mozfiles.com
- site-1044113.mozfiles.com
- site-1048226.mozfiles.com
- site-1039740.mozfiles.com
- site-1039294.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report