MALICIOUS — 7544631.pdf
MALICIOUS — 7544631.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0f1466233a01634434c923125483caacb2b9b197923c8a5f618fdaeaa050ef1d - SHA-1:
09d0e139e9de0dec680da2ac932666bdd4082acd - MD5:
92b758d7e7817ce50a637c30fe70b5f6 - ssdeep:
768:6gGzpD8eha1bPtIWV5APPakcL+XH/kDV1ZWCyodnUhMVgoc7viHdO1sT6zuV0b:nGFweVgQsDV1ZWCy6UhMV0M47z9b - TLSH:
T1C4338DF300ABED8C7987A703A9B7145925CEC78C6226975048987B6DD8BC6BC7F10960 - Submitted as: 7544631.pdf
- File type: pdf · Size: 47805 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://cdn-cms.f-static.net/uploads/4366344/normal_5f870e3e0497d.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=para%20que%20serve%20sertex, https://cdn-cms.f-static.net/uploads/4366045/normal_5f87059074348.pdf, https://cdn-cms.f-static.net/uploads/4366344/normal_5f870e3e0497d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=para%20que%20serve%20sertex
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f87059074348.pdf
- https://cdn-cms.f-static.net/uploads/4366344/normal_5f870e3e0497d.pdf
- https://cdn-cms.f-static.net/uploads/4366401/normal_5f8732658ac8e.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f87158657072.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f870f3bc053d.pdf
- https://cdn.shopify.com/s/files/1/0433/1051/4334/files/used_stage_lighting_ebay.pdf
- https://cdn.shopify.com/s/files/1/0478/2702/6079/files/what_is_cpct_in_maths_in_hindi.pdf
- https://cdn.shopify.com/s/files/1/0437/5209/5898/files/8233910948.pdf
- https://cdn.shopify.com/s/files/1/0433/9544/8988/files/types_of_reaction_worksheet_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0483/4902/0311/files/bill_of_rights_scenarios_worksheet.pdf
- https://giwakatunu.weebly.com/uploads/1/3/1/4/131437107/woxesegela.pdf
- https://kenilajapa.weebly.com/uploads/1/3/1/0/131069910/5809899.pdf
- https://site-1038717.mozfiles.com/files/1038717/23788115067.pdf
- https://site-1043704.mozfiles.com/files/1043704/10666712316.pdf
- https://site-1042196.mozfiles.com/files/1042196/mobepudanozefegi.pdf
- https://site-1043842.mozfiles.com/files/1043842/75254252177.pdf
- https://uploads.strikinglycdn.com/files/21e0ee56-4f54-4f9f-95b3-f93e9616c900/28100154028.pdf
- https://uploads.strikinglycdn.com/files/2a2c9bdd-ca8d-488d-8ef2-c38115232f55/66043939056.pdf
- https://uploads.strikinglycdn.com/files/45847ea8-3984-43ac-9f9b-c5ee96a9c0f9/36724819275.pdf
- https://uploads.strikinglycdn.com/files/7de641c6-06b4-4003-8afc-784b7e578edd/6636213975.pdf
- https://uploads.strikinglycdn.com/files/87e69630-2a7f-400f-8742-9bcd34280979/12214139411.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f8716d2b910e.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f86fee14df2a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- giwakatunu.weebly.com
- kenilajapa.weebly.com
- site-1038717.mozfiles.com
- site-1043704.mozfiles.com
- site-1042196.mozfiles.com
- site-1043842.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report