MALICIOUS — 9930655.pdf
MALICIOUS — 9930655.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0a04f71ae48b26e250016cba5bfbef0d63861a8ea001e98a5cd428d2352b394e - SHA-1:
d1760cee1fd227500247ca69cd38c238c943e985 - MD5:
f6aabc866361a77fb754d2b3163787c8 - ssdeep:
768:JgGzpDcpNgksjnA56D5B4BhRh0lPf9GpO3h2vuZ/2sWTI2Owjb62lgtx:qGFYpNhsDFGg34uZ/feI2Hjbzlgtx - TLSH:
T136317DF35093EE8DBE4B9B03A9FA1049658AC78C5137E794449C372CD5BC6AD6F20860 - Submitted as: 9930655.pdf
- File type: pdf · Size: 40171 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/ead64c6e.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=dragon%20ball%20super%20broly%20torrent%20download, https://cdn.shopify.com/s/files/1/0431/9802/1793/files/warframe_hidden_messages_quest.pdf, https://cdn.shopify.com/s/files/1/0434/0029/8648/files/higo_no_kami_pocket_knife.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=dragon%20ball%20super%20broly%20torrent%20download
- https://cdn.shopify.com/s/files/1/0431/9802/1793/files/warframe_hidden_messages_quest.pdf
- https://cdn.shopify.com/s/files/1/0434/0029/8648/files/higo_no_kami_pocket_knife.pdf
- https://cdn.shopify.com/s/files/1/0266/7580/6402/files/how_much_pint_in_a_quart.pdf
- https://cdn.shopify.com/s/files/1/0433/8538/9212/files/valtryek_v5_qr_code_video.pdf
- https://cdn-cms.f-static.net/uploads/4368504/normal_5f878df339b77.pdf
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f877d1689c26.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/ead64c6e.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/ff06dfdf.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/zekalujenopavib.pdf
- https://site-1039762.mozfiles.com/files/1039762/nukevenoxunelofiguxajuv.pdf
- https://site-1039649.mozfiles.com/files/1039649/madubarudirepaf.pdf
- https://site-1048244.mozfiles.com/files/1048244/babibomekuwikovi.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f872e7b21dec.pdf
- https://cdn-cms.f-static.net/uploads/4366632/normal_5f876ef8a9f9e.pdf
- https://cdn-cms.f-static.net/uploads/4366956/normal_5f877c7e86942.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f870defa78af.pdf
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f877bb8804f8.pdf
- https://uploads.strikinglycdn.com/files/1ea5abbc-40a1-446e-8a72-e551a6b112c9/roperivitutigaxetomutexu.pdf
- https://uploads.strikinglycdn.com/files/e7bceb85-0037-4473-b9f5-d6b9e3c3c4c3/256568503.pdf
- https://uploads.strikinglycdn.com/files/c77d1c10-6ca3-4a2b-8076-1f9a590c0fd2/74875199808.pdf
- https://uploads.strikinglycdn.com/files/2c12d7b7-9463-46ed-993f-4ef2af4c7c9d/92115872506.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- jawowigo.weebly.com
- genigudepa.weebly.com
- vozunutav.weebly.com
- site-1039762.mozfiles.com
- site-1039649.mozfiles.com
- site-1048244.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report