MALICIOUS — normal_5f8f2669b2376.pdf
MALICIOUS — normal_5f8f2669b2376.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fe1bfb74c0ee249c6653cf385364e41323bd679fed98e169b8463a1b53207257 - SHA-1:
cdfcf59072103a17b848ba26db25100388374f82 - MD5:
24422be1d9b5df64fd8915a97693165e - ssdeep:
768:bgGzpDJee26bqO+w+/gBrv+dMgReOyd/y9dVYweT/q8Z:kGF9ep/gBrv+mgRa/qdVYwEq8Z - TLSH:
T14C307CF35197EC8C7A87DB03A9A72059258AC78C6127E7A0948C773CC4BC6BD6E10D61 - Submitted as: normal_5f8f2669b2376.pdf
- File type: pdf · Size: 38705 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/3718456.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.cc/123?keyword=altivar+31+manuale+italiano, https://uploads.strikinglycdn.com/files/81cef864-dd7c-4f8f-a875-b68d08ba6921/mirekavavonatojunotofabix.pdf, https://uploads.strikinglycdn.com/files/2dfedd4b-a3a9-4b43-b644-5060d8549ae5/84083058509.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=altivar+31+manuale+italiano
- https://uploads.strikinglycdn.com/files/81cef864-dd7c-4f8f-a875-b68d08ba6921/mirekavavonatojunotofabix.pdf
- https://uploads.strikinglycdn.com/files/2dfedd4b-a3a9-4b43-b644-5060d8549ae5/84083058509.pdf
- https://uploads.strikinglycdn.com/files/ff95de57-6d0b-424a-a35f-838c4cdf1d1f/79111828467.pdf
- https://uploads.strikinglycdn.com/files/d3c8502f-f12b-4b70-8879-fda391d42174/lujejalubalu.pdf
- https://uploads.strikinglycdn.com/files/5b6e7dcb-8822-4685-9449-cf210117271c/jutufewalogepunanusulaku.pdf
- https://cdn.shopify.com/s/files/1/0504/6684/8933/files/android_device_rooted_or_not.pdf
- https://s3.amazonaws.com/fasanag/boxuwutedagejufanoxutok.pdf
- https://s3.amazonaws.com/henghuili-files2/lubowijele.pdf
- https://s3.amazonaws.com/wilugugo/18994031008.pdf
- https://s3.amazonaws.com/subud/84376230654.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/3718456.pdf
- https://digafixi.weebly.com/uploads/1/3/0/7/130776371/6996352.pdf
- https://turomanusogagi.weebly.com/uploads/1/3/1/4/131453559/23e19bc1eb1.pdf
- https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/14e5d20c5299f.pdf
- https://givifajilodox.weebly.com/uploads/1/3/0/8/130874655/putenipemetigu_pebukalukowos_jixoxuv_siwidedito.pdf
- https://topodomero.weebly.com/uploads/1/3/2/6/132696018/zorodubafiva.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/vibururodiz.pdf
- https://cdn.shopify.com/s/files/1/0434/5069/5841/files/81054860168.pdf
- https://cdn.shopify.com/s/files/1/0427/9464/7719/files/lululemon_marketing_strategy_2019.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ttraff.cc
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- jakedekokobara.weebly.com
- digafixi.weebly.com
- turomanusogagi.weebly.com
- kubupukadumu.weebly.com
- givifajilodox.weebly.com
- topodomero.weebly.com
- papunagaku.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report