MALICIOUS — 2712298.pdf
MALICIOUS — 2712298.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
25f3b4873896b707df2a68d70a2987d962d5d8b3a76849b8c44eb8736414ace3 - SHA-1:
30dabe7dc2c288cac1c6e1719bb19cbf3a830817 - MD5:
6d0dbfdd01e87fff46a293a87079406d - ssdeep:
1536:hGFMpXfLzkyB1pzCBZmqKs8H2ie/RNSah9aeaK3:EFMpPLzkktCfm7sq2ie5J - TLSH:
T1AC34AFF300ABED4C7A4BAB539DA7116A9589E7CD21369760408D6B2CC8FC6FC7E10911 - Submitted as: 2712298.pdf
- File type: pdf · Size: 57217 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://wuwenivavubujer.weebly.com/uploads/1/3/1/4/131437756/5331339.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=adobe%20photoshop%20free%20%20trial%20version, https://uploads.strikinglycdn.com/files/cdb2ca8a-14af-4da7-b764-52db1139e6c5/kugisobatunapi.pdf, https://uploads.strikinglycdn.com/files/ee92b1e3-98a5-400a-a819-60777f205858/gukag.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=adobe%20photoshop%20free%20%20trial%20version
- https://uploads.strikinglycdn.com/files/cdb2ca8a-14af-4da7-b764-52db1139e6c5/kugisobatunapi.pdf
- https://uploads.strikinglycdn.com/files/ee92b1e3-98a5-400a-a819-60777f205858/gukag.pdf
- https://uploads.strikinglycdn.com/files/be67fee4-fab7-4507-85be-a396e24aa524/xiramatalawoxemuxodaku.pdf
- https://uploads.strikinglycdn.com/files/8fa428fe-187b-483b-9591-dbdd845f6250/31211970767.pdf
- https://zugufavowi.weebly.com/uploads/1/3/0/8/130874222/4900efd31424701.pdf
- https://wuwenivavubujer.weebly.com/uploads/1/3/1/4/131437756/5331339.pdf
- https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/6071270.pdf
- https://tuxitusonodedin.weebly.com/uploads/1/3/0/8/130873989/cdc651cee5a51.pdf
- https://uploads.strikinglycdn.com/files/157dbd1b-d4e5-46c2-a649-53cc414c823f/jibirim.pdf
- https://uploads.strikinglycdn.com/files/d480f455-1a48-4900-a644-cda679da3dfd/bezuwep.pdf
- https://cdn-cms.f-static.net/uploads/4380700/normal_5f8d9d6187237.pdf
- https://cdn-cms.f-static.net/uploads/4369307/normal_5f8911d7f3fbf.pdf
- https://cdn.shopify.com/s/files/1/0496/7294/5821/files/27543865979.pdf
- https://cdn.shopify.com/s/files/1/0441/0654/7352/files/career_of_evil_indonesia_download.pdf
- https://cdn.shopify.com/s/files/1/0492/6429/6092/files/garden_hose_shut_off_valve_walmart.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f893b2ea501c.pdf
- https://cdn-cms.f-static.net/uploads/4370560/normal_5f89d91e18c40.pdf
- https://cdn-cms.f-static.net/uploads/4369522/normal_5f8b9bb5ce156.pdf
- https://cdn-cms.f-static.net/uploads/4374175/normal_5f8aba3decab5.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- zugufavowi.weebly.com
- wuwenivavubujer.weebly.com
- gazesomudari.weebly.com
- tuxitusonodedin.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report