MALICIOUS — 2551819.pdf
MALICIOUS — 2551819.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1dfb814218cbf5e197a206de2176db07bdbcc3a3c30ec57595ad9e98e488da7f - SHA-1:
883f4c8049816ff978cd5b11db1c1abd6840b5e7 - MD5:
481f4e05a50e0830bab762df09f3413e - ssdeep:
768:3gGzpDppgXMUizW+rTBV7hLNdac9bAhdGwYzPHWbzHt1LF5p2gfp5E:QGF9pmMJxddb+QfTHW55pRfp5E - TLSH:
T1BB318DF764DBED8D7A866B03ACAB2096548AD38961379760488C273CD0BC77E7E00951 - Submitted as: 2551819.pdf
- File type: pdf · Size: 41374 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=fragment%20sentence%20worksheet, https://uploads.strikinglycdn.com/files/3c16464a-b94e-41d2-a703-42c4179bcea4/40494554294.pdf, https://uploads.strikinglycdn.com/files/af8699f2-e275-4b7d-a41d-de5b68a4759b/18017688114.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=fragment%20sentence%20worksheet
- https://uploads.strikinglycdn.com/files/3c16464a-b94e-41d2-a703-42c4179bcea4/40494554294.pdf
- https://uploads.strikinglycdn.com/files/af8699f2-e275-4b7d-a41d-de5b68a4759b/18017688114.pdf
- https://uploads.strikinglycdn.com/files/836f0d89-061e-4ff2-b81e-74ddfcb2944e/34418999245.pdf
- https://uploads.strikinglycdn.com/files/97b844c3-df06-4677-823f-7d2f6b0d597a/munafad.pdf
- https://uploads.strikinglycdn.com/files/a2f23603-f9c1-4a83-a1e8-ce1437a29704/pawasenez.pdf
- https://uploads.strikinglycdn.com/files/dab393e4-5a5c-4723-8491-cc41c1291175/xizugutexu.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/3274198.pdf
- https://kasukironumasex.weebly.com/uploads/1/3/1/4/131454791/cd9280f0550b.pdf
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/9633892.pdf
- https://finiluxexolije.weebly.com/uploads/1/3/1/8/131856594/2431298.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f878ad44f85d.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f8712f1bed66.pdf
- https://cdn-cms.f-static.net/uploads/4368759/normal_5f8783f707cd3.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f872a0774989.pdf
- https://uploads.strikinglycdn.com/files/5a44b413-f6a5-4a4b-ab31-b66aa3e6c771/kujurubebukaremug.pdf
- https://uploads.strikinglycdn.com/files/0717546c-e0a5-4450-aada-96213248fe7d/solubonufopazitijod.pdf
- https://uploads.strikinglycdn.com/files/efab2cb1-5810-4da7-99da-01f56955fbf5/tapexuxajotetutidez.pdf
- https://uploads.strikinglycdn.com/files/e4a9bf20-56c9-4c89-b5be-e45f0d3ca74d/minejoxozifebawuv.pdf
- https://uploads.strikinglycdn.com/files/deeea970-e3b8-41d6-beab-c6d6462ece37/34025157711.pdf
- https://cdn.shopify.com/s/files/1/0479/3237/5207/files/40781709263.pdf
- https://cdn.shopify.com/s/files/1/0476/4460/6630/files/the_sims_3_ambitions_android_download.pdf
- https://cdn.shopify.com/s/files/1/0435/7485/3793/files/91359942459.pdf
- https://cdn.shopify.com/s/files/1/0484/7406/3002/files/twd_road_to_survival_hacked_apk.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- genigudepa.weebly.com
- vozunutav.weebly.com
- kasukironumasex.weebly.com
- fekudumubaf.weebly.com
- finiluxexolije.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report