MALICIOUS — 94438755814.pdf
MALICIOUS — 94438755814.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
61567b894773a18bdf138c000d2bffa138cb417b6591c97edbd56ed20b6b5af6 - SHA-1:
a3adb318f40edab5ca5234ab2bf84d13a3205988 - MD5:
bf86f71eee8d7ea60b776e5a720d2c6a - ssdeep:
768:QRgGzpDzp/siWnqTjdFIqmcH9mdNUQEHcl6WnQP8Uuu6yF8:QiGFHpU6VlgNUfHcEKQB2yF8 - TLSH:
T17C328EF310A7FC8C7E8EAB039EBB1159A089C64C613697A018C8771ED47CABD6F10951 - Submitted as: 94438755814.pdf
- File type: pdf · Size: 47406 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://dufevirefat.weebly.com/uploads/1/3/1/4/131438490/6d3a8560c5af7.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=playtex+straw+sippy+cup+replacement+parts, https://uploads.strikinglycdn.com/files/a312c49a-7089-4424-b574-df61859ea67f/65040642854.pdf, https://uploads.strikinglycdn.com/files/09961672-48a1-497c-a695-ce5759019ed2/mekifefudemutositinumaxis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=playtex+straw+sippy+cup+replacement+parts
- https://uploads.strikinglycdn.com/files/a312c49a-7089-4424-b574-df61859ea67f/65040642854.pdf
- https://uploads.strikinglycdn.com/files/09961672-48a1-497c-a695-ce5759019ed2/mekifefudemutositinumaxis.pdf
- https://uploads.strikinglycdn.com/files/a3a00e01-56a3-48ca-a2ae-ac114f371794/93628775775.pdf
- https://uploads.strikinglycdn.com/files/d09692a0-ac25-4b20-b3ea-4eedb482e75a/fulukifasezugib.pdf
- https://uploads.strikinglycdn.com/files/0fca4e76-bc38-4327-9723-2a41a0bc2530/wetifasumuwusu.pdf
- https://dufevirefat.weebly.com/uploads/1/3/1/4/131438490/6d3a8560c5af7.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/1181add08fecfe.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/lekov.pdf
- https://pezopipowom.weebly.com/uploads/1/3/1/4/131406060/xejuteboj-warur-xodobuzititux.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/7c2eb3c.pdf
- https://uploads.strikinglycdn.com/files/5d0bf842-d044-417a-af77-697cc445a372/nunazibiwol.pdf
- https://uploads.strikinglycdn.com/files/4d1748c2-039b-4624-b228-f45438fcfbf1/xevaziv.pdf
- https://uploads.strikinglycdn.com/files/be0c44c6-8d6c-4294-8e2e-95b4ff0012a0/65246740516.pdf
- https://uploads.strikinglycdn.com/files/ac2563e2-d318-445e-8ba2-99f95c4141b1/13330378629.pdf
- https://uploads.strikinglycdn.com/files/30b33e6e-6055-40da-94cb-7bfb0e8ad613/25740620032.pdf
- https://uploads.strikinglycdn.com/files/870c3f82-13e9-4885-b16c-f16073de149d/divolojawiwakidesubilive.pdf
- https://uploads.strikinglycdn.com/files/79d2420a-e896-42e4-be5b-1c854d711ba7/fegibelelevowiwajizo.pdf
- https://uploads.strikinglycdn.com/files/03438888-e25d-46ab-ab20-211e7f15b23f/24434544557.pdf
- https://uploads.strikinglycdn.com/files/79b99de2-001e-4c9f-8de4-522211747962/detuvowo.pdf
- https://uploads.strikinglycdn.com/files/2e13d020-f8c8-4cfd-a5cf-7cd02508cf6b/exercice_thales_pythagore_brevet.pdf
- https://uploads.strikinglycdn.com/files/ad56389e-f020-4a60-b840-5993a6f4c741/secretos_para_dibujar_rostros_realistas.pdf
- https://uploads.strikinglycdn.com/files/7787a6df-2376-4fbf-bb07-94ce39b51ae1/48023308322.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- dufevirefat.weebly.com
- vozunutav.weebly.com
- rabifupokuwu.weebly.com
- pezopipowom.weebly.com
- viweposedijul.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report