MALICIOUS — 9212933.pdf
MALICIOUS — 9212933.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
417c9ba7b507b7910f25994df302a7f0fee478cdb88135cdd5c2f2082cf515f1 - SHA-1:
f2214c758d4ec45184d3b028d5f3783ec63ea82e - MD5:
d72cfcb0e24c85eb1bcc2904ffe7ad28 - ssdeep:
768:EgGzpDPTp3F1HXqW1d+c50Ln1yFXTzqmDTcM6K3joY03JM51/H:xGFXp/HXF1rXHqmDTsYoB3JeH - TLSH:
T1AA327DF350A7DE8C3EC79B936EFB21996049D685613297608588772CC4BC6BE7F00A11 - Submitted as: 9212933.pdf
- File type: pdf · Size: 45899 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=comment%20allumer%20freebox%20sans%20t%C3%A9l%C3%A9commande, https://pepisukuwen.weebly.com/uploads/1/3/1/6/131606293/vufudotabozok_fibutek_fuwujejurutajix.pdf, https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/2839228.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=comment%20allumer%20freebox%20sans%20t%C3%A9l%C3%A9commande
- https://pepisukuwen.weebly.com/uploads/1/3/1/6/131606293/vufudotabozok_fibutek_fuwujejurutajix.pdf
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/2839228.pdf
- https://firerokuk.weebly.com/uploads/1/3/1/1/131164187/kepenu-likilaxi-wanerojitofetaw.pdf
- https://penulikadima.weebly.com/uploads/1/3/1/4/131482887/jetugapop.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf
- https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/sivovawi.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/jiwevuterijafus-mekuvezagezoj-dalefener.pdf
- https://cdn.shopify.com/s/files/1/0500/3306/6144/files/21287889396.pdf
- https://cdn.shopify.com/s/files/1/0485/2609/8594/files/female_mind_control_system.pdf
- https://cdn.shopify.com/s/files/1/0266/9605/7019/files/68609542051.pdf
- https://cdn.shopify.com/s/files/1/0434/0590/1991/files/busivamijotezojiwo.pdf
- https://cdn.shopify.com/s/files/1/0498/2453/0594/files/donut_ghost_house_secret_exit.pdf
- https://uploads.strikinglycdn.com/files/e7820a15-332c-4830-9b43-f7b64251d6d5/83754639230.pdf
- https://uploads.strikinglycdn.com/files/a2324be6-d8de-4483-b20a-bd883850e802/banglarbhumi_lr_plot_information.pdf
- https://uploads.strikinglycdn.com/files/f8a7ed3e-b397-47e5-8f4c-23f8ef911e47/46412658843.pdf
- https://mesipaku.weebly.com/uploads/1/3/1/3/131383407/funav.pdf
- https://remewizefo.weebly.com/uploads/1/3/1/8/131856163/jezowogabusot_dajuxax_peloxidinivolup_foxilabeleturak.pdf
- https://uploads.strikinglycdn.com/files/b62681e7-82d1-404b-8bc8-4110379c1ddf/26771188823.pdf
- https://uploads.strikinglycdn.com/files/f87c88e5-bc31-462d-a63d-306dfa77901f/download_dr_dre_2001.pdf
- https://uploads.strikinglycdn.com/files/cbb1d5d5-1273-4ff2-9b3b-ca699d0889e8/92414349354.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- pepisukuwen.weebly.com
- bizumoku.weebly.com
- firerokuk.weebly.com
- penulikadima.weebly.com
- jawasolasazilem.weebly.com
- mefemanodi.weebly.com
- saxibodusazo.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- mesipaku.weebly.com
- remewizefo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report