MALICIOUS — 6088572611.pdf
MALICIOUS — 6088572611.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
19bd296c6cb7ca75398dbbdcfaafb448f1b559410a4d5d99a0bf8236a97fd976 - SHA-1:
439bf2b08280d212229b5cbae1b0b5641c2c3a13 - MD5:
36e4cd900e7db66c3d5caa3a70ac4b7a - ssdeep:
1536:vGFrpZQBqoStaYAOONNk5jKAzhQhgtkm:eFrpZ6qzi9NIjKAzh0g7 - TLSH:
T18A34BFF751A7ED4C7ACA9B436CD6006A2095C78C9137E390589C3B6CD8BC2BEBE11911 - Submitted as: 6088572611.pdf
- File type: pdf · Size: 57455 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/belapigojat.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=self+improvement+books+in+urdu+pdf, https://cdn.shopify.com/s/files/1/0482/2627/1384/files/8530557910.pdf, https://cdn.shopify.com/s/files/1/0498/8161/2446/files/merasawurebobofuba.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=self+improvement+books+in+urdu+pdf
- https://cdn.shopify.com/s/files/1/0433/7808/1955/files/prophet_hacker_download.pdf
- https://cdn.shopify.com/s/files/1/0482/2627/1384/files/8530557910.pdf
- https://cdn.shopify.com/s/files/1/0498/8161/2446/files/merasawurebobofuba.pdf
- https://cdn.shopify.com/s/files/1/0431/3756/4838/files/nimep.pdf
- https://vabeliguteziji.weebly.com/uploads/1/3/1/3/131379360/busamoto.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/belapigojat.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/1388067.pdf
- https://mumixopid.weebly.com/uploads/1/3/1/8/131872042/fopumudefixaka.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/xujewonagamaxu.pdf
- https://vevejeda.weebly.com/uploads/1/3/0/7/130776099/wujumoj-womivuzile-subejivanoge-werowubara.pdf
- https://wepeweguwerixum.weebly.com/uploads/1/3/1/8/131856135/38c98cb1a698685.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/5650151.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/1a27643b41869.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/fazijopaf.pdf
- https://cdn-cms.f-static.net/uploads/4367921/normal_5f887f0230616.pdf
- https://cdn-cms.f-static.net/uploads/4367627/normal_5f883519753f0.pdf
- https://site-1043199.mozfiles.com/files/1043199/judiremeguwerisepobos.pdf
- https://site-1048488.mozfiles.com/files/1048488/fivituvodot.pdf
- https://site-1041579.mozfiles.com/files/1041579/15206679219.pdf
- https://site-1038636.mozfiles.com/files/1038636/giwafuwipopuputi.pdf
- https://site-1041932.mozfiles.com/files/1041932/exiled_kingdoms_full_version_apk.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- vabeliguteziji.weebly.com
- guwomenod.weebly.com
- pumowurunumig.weebly.com
- mumixopid.weebly.com
- zafozudakajadev.weebly.com
- vevejeda.weebly.com
- wepeweguwerixum.weebly.com
- jatorogerujew.weebly.com
- zoxuzuxebexot.weebly.com
- babikovinemixe.weebly.com
- cdn-cms.f-static.net
- site-1043199.mozfiles.com
- site-1048488.mozfiles.com
- site-1041579.mozfiles.com
- site-1038636.mozfiles.com
- site-1041932.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report