MALICIOUS — 6222937.pdf
MALICIOUS — 6222937.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
306c088b1b6234a0498bc08f44af79ae834053fc9aade155ba373d95fc1e7b53 - SHA-1:
85b0cc96603688c048ca6de7ebfb598efcdb0745 - MD5:
fea5ceec13040b3604973f0102481066 - ssdeep:
1536:HGF8pwzfPyxWH1yoSFQ5vB6L+Vwl3AroLdjz4vFSI:mF8piPynoYWZq+Vwl3AroZ4X - TLSH:
T1E7348DF30143DD4D7B87EB8369AB299CA04A974D7172AB604498366CC97C37DBF40960 - Submitted as: 6222937.pdf
- File type: pdf · Size: 57291 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=carrello%20elevatore%20manuale%20elettrico, https://cdn.shopify.com/s/files/1/0268/8391/5962/files/android_mobile_anti_virus_download.pdf, https://cdn.shopify.com/s/files/1/0428/9737/5388/files/vetalanotule.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=carrello%20elevatore%20manuale%20elettrico
- https://cdn.shopify.com/s/files/1/0268/8391/5962/files/android_mobile_anti_virus_download.pdf
- https://cdn.shopify.com/s/files/1/0428/9737/5388/files/vetalanotule.pdf
- https://cdn.shopify.com/s/files/1/0486/2545/1173/files/92017005754.pdf
- https://cdn.shopify.com/s/files/1/0485/1770/9986/files/famivijagode.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf
- https://welavofewefose.weebly.com/uploads/1/3/0/8/130813025/jaloxi.pdf
- https://cdn.shopify.com/s/files/1/0464/3084/7128/files/14976762126.pdf
- https://cdn.shopify.com/s/files/1/0503/1411/7293/files/coffee_grinder_manual_uk.pdf
- https://cdn.shopify.com/s/files/1/0495/7208/5926/files/driving_simulator_2020_mod_apk_unlimited_money.pdf
- https://cdn.shopify.com/s/files/1/0478/8905/5910/files/lessons_from_madame_chic_free_download.pdf
- https://uploads.strikinglycdn.com/files/126a7455-f8e2-421d-8727-1f2a6a79c2f4/jimi_hendrix_electric_ladyland_torre.pdf
- https://uploads.strikinglycdn.com/files/cc4f1211-201f-41cd-a24f-7cedf15d155f/gagoxubigizaxevaf.pdf
- https://s3.amazonaws.com/lokijuronig/bos_taurus_razas.pdf
- https://s3.amazonaws.com/tadovu/hernias_de_pared_abdominal_2019.pdf
- https://s3.amazonaws.com/paxivogedewilu/56481403173.pdf
- https://s3.amazonaws.com/wilugugo/73151423666.pdf
- https://s3.amazonaws.com/memul/business_communication_full_notes.pdf
- https://uploads.strikinglycdn.com/files/7e016bf9-cc83-401c-90c7-4feb6bb7fa43/93304872565.pdf
- https://uploads.strikinglycdn.com/files/e26b97cb-feda-4856-aa35-49c31fa4225a/6998593624.pdf
- https://uploads.strikinglycdn.com/files/140e27cd-9ff1-4902-bfc3-dc47f1718dd4/15411396322.pdf
- https://uploads.strikinglycdn.com/files/84737998-957e-4b29-97f3-f61b7872eff8/clep_exams_study_guides_free.pdf
- https://uploads.strikinglycdn.com/files/fe9a22e0-4ff3-4442-89df-50eb37666e3a/97319688803.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- jawasolasazilem.weebly.com
- welavofewefose.weebly.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report