MALICIOUS — 6208632.pdf
MALICIOUS — 6208632.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6594e2c8baef55e166c3b692e9a1990c46bae4e471af48aafe77408be1f11a8c - SHA-1:
c499c78f8ee4b3b4ab3964233a5190b47067a4d5 - MD5:
3b643dc2a2047e2bb4140f40c7335bf2 - ssdeep:
1536:CGFCeTXxMSrmpPqUt33ipjYGh3RS+H7H6uPle9stmqNpklPkj2Hw:7FCeI1foPh8+Wu9e3qNp5Z - TLSH:
T11138CFF3509BCD8D7A976B236CF30564648AC7CC3222979015C97B2DC5BC6BCAE11960 - Submitted as: 6208632.pdf
- File type: pdf · Size: 79017 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/c2628d83-1e27-495f-917b-f67d7afa889d/dozafeduvupuz.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=lexus%20sc400%20manual%20transmission, https://uploads.strikinglycdn.com/files/c2628d83-1e27-495f-917b-f67d7afa889d/dozafeduvupuz.pdf, https://uploads.strikinglycdn.com/files/87a1b094-9e99-4f5a-866f-feaf2c89d7e6/21269932277.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=lexus%20sc400%20manual%20transmission
- https://uploads.strikinglycdn.com/files/c2628d83-1e27-495f-917b-f67d7afa889d/dozafeduvupuz.pdf
- https://uploads.strikinglycdn.com/files/87a1b094-9e99-4f5a-866f-feaf2c89d7e6/21269932277.pdf
- https://uploads.strikinglycdn.com/files/15a8e989-caeb-43a5-b2e2-5e8bdb5855c1/jegofovadogap.pdf
- https://uploads.strikinglycdn.com/files/1181e92d-f742-458c-86b0-f9808f82ea42/2229619089.pdf
- https://uploads.strikinglycdn.com/files/bbeeb90f-f9bb-4f1c-a584-ee4cec8595a3/kozejimadufugowotedibarek.pdf
- https://uploads.strikinglycdn.com/files/fffc6682-ec0c-4b3d-98de-b39166e83e35/vopixulovererabotobibatu.pdf
- https://site-1038429.mozfiles.com/files/1038429/zumisuzo.pdf
- https://site-1040613.mozfiles.com/files/1040613/lobuw.pdf
- https://site-1037180.mozfiles.com/files/1037180/jepiludufemuwesorenu.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f87067c72395.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f8719bbdd346.pdf
- https://cdn-cms.f-static.net/uploads/4366980/normal_5f8730892315a.pdf
- https://cdn-cms.f-static.net/uploads/4367000/normal_5f872f0fa29a3.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f8705f3e628e.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f870b8853694.pdf
- https://cdn-cms.f-static.net/uploads/4365657/normal_5f8701ede58e5.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f8711c48e1bc.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f870f268a02d.pdf
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f8726af4ffba.pdf
- https://uploads.strikinglycdn.com/files/e6e350ac-ace1-4153-ac41-8afb92717e13/92512874317.pdf
- https://uploads.strikinglycdn.com/files/a0961405-4af9-4390-8486-cf39d897dcb3/43187129592.pdf
- https://uploads.strikinglycdn.com/files/9c22810b-3159-4d13-9de0-56d1e152b722/32093812778.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1038429.mozfiles.com
- site-1040613.mozfiles.com
- site-1037180.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report